mirror of
https://github.com/openclaw/openclaw.git
synced 2026-08-04 08:01:41 +00:00
* refactor(config): consolidate media model lists * refactor(config): unify memory configuration * refactor(config): consolidate TTS ownership * refactor(config): move typing policy to agents * refactor(config): retire product-level config surfaces * refactor(config): share scoped tool policy type * chore(config): refresh generated baselines * fix(config): honor agent typing overrides * fix(config): migrate sibling config consumers * refactor(infra): keep base64url decoder private * fix(config): strip invalid legacy TTS values * chore(config): refresh rebased baseline hash * fix(doctor): route legacy messages.tts.realtime voice to talk during tts move * refactor(config): polish final layout names * refactor(config): freeze retired tuning defaults * feat(config): add fast mode default symmetry * refactor(config): key agent entries by id * docs(config): update final layout reference * test(config): cover final layout migrations * chore(config): refresh final layout baselines * fix(config): align final layout runtime readers * fix(config): align remaining readers * fix(config): stabilize final layout migrations * fix(config): finalize config projection proof * fix(config): address final layout review * docs(release): preserve historical config names * fix(config): complete keyed agent migration * fix(config): close final migration gaps * fix(config): finish full-branch review * fix(config): complete runtime secret detection * fix(config): close final review findings * fix(config): finish canonical docs and heartbeat migration * fix(config): integrate latest main after rebase * refactor(env): isolate test-only controls * refactor(env): isolate build and development controls * refactor(env): collapse process identity indirection * refactor(env): remove duplicate config and temp aliases * docs(env): define the operator-facing allowlist * ci(env): ratchet production variable count * fix(env): remove stale provider helper import * fix(env): make ratchet sorting explicit * test(env): keep test seam in dead-code audit * test(env): cover ratchet growth and boundary; document surface budgets * docs(config): document tier-eval consolidations * docs(config): clarify speech preference ownership * test(memory): align retired tuning fixtures * refactor(memory): freeze engine heuristics * refactor(config): apply tier-eval tranche * refactor(tts): move persona shaping to providers * refactor(compaction): move prompt policy to providers * test(config): align hookified prompt fixtures * chore(deadcode): classify test-only exports * chore(github): remove unused spawn helper * chore(deadcode): classify queue diagnostics * chore(deadcode): remove unused lane snapshot export * chore(plugin-sdk): ratchet consolidated surface * fix(config): integrate latest main after rebase
73 lines
2.2 KiB
TypeScript
73 lines
2.2 KiB
TypeScript
// Covers loopback logging exposure audit findings.
|
|
import { describe, expect, it } from "vitest";
|
|
import type { OpenClawConfig } from "../config/config.js";
|
|
import { withEnvAsync } from "../test-utils/env.js";
|
|
import { collectSecurityAuditFindings } from "./audit.test-support.js";
|
|
import type { SecurityAuditFinding } from "./audit.types.js";
|
|
|
|
function hasGatewayFinding(
|
|
checkId: "gateway.trusted_proxies_missing" | "gateway.loopback_no_auth",
|
|
severity: "warn" | "critical",
|
|
findings: SecurityAuditFinding[],
|
|
) {
|
|
return findings.some((finding) => finding.checkId === checkId && finding.severity === severity);
|
|
}
|
|
|
|
function hasLoggingFinding(
|
|
checkId: "logging.redact_off",
|
|
severity: "warn",
|
|
findings: SecurityAuditFinding[],
|
|
) {
|
|
return findings.some((finding) => finding.checkId === checkId && finding.severity === severity);
|
|
}
|
|
|
|
describe("security audit loopback and logging findings", () => {
|
|
it("evaluates loopback control UI and logging exposure findings", async () => {
|
|
await Promise.all([
|
|
(async () => {
|
|
const cfg: OpenClawConfig = {
|
|
gateway: {
|
|
bind: "loopback",
|
|
controlUi: { enabled: true },
|
|
},
|
|
};
|
|
expect(
|
|
hasGatewayFinding(
|
|
"gateway.trusted_proxies_missing",
|
|
"warn",
|
|
await collectSecurityAuditFindings(cfg),
|
|
),
|
|
).toBe(true);
|
|
})(),
|
|
withEnvAsync(
|
|
{
|
|
OPENCLAW_GATEWAY_TOKEN: undefined,
|
|
OPENCLAW_GATEWAY_PASSWORD: undefined,
|
|
},
|
|
async () => {
|
|
const cfg: OpenClawConfig = {
|
|
gateway: {
|
|
bind: "loopback",
|
|
controlUi: { enabled: true },
|
|
auth: {},
|
|
},
|
|
};
|
|
expect(
|
|
hasGatewayFinding(
|
|
"gateway.loopback_no_auth",
|
|
"critical",
|
|
await collectSecurityAuditFindings(cfg),
|
|
),
|
|
).toBe(true);
|
|
},
|
|
),
|
|
(async () => {
|
|
const cfg: OpenClawConfig = {};
|
|
expect(
|
|
hasLoggingFinding("logging.redact_off", "warn", await collectSecurityAuditFindings(cfg)),
|
|
).toBe(false);
|
|
})(),
|
|
]);
|
|
});
|
|
});
|