mirror of
https://github.com/openclaw/openclaw.git
synced 2026-07-28 07:21:11 +00:00
* feat(gateway): auto-approve trusted-proxy browser device pairing Adds gateway.auth.trustedProxy.deviceAutoApprove so team gateways behind an identity-aware proxy (Cloudflare Access, oauth2-proxy, Pomerium) can skip the manual `openclaw devices approve` step for new Control UI/WebChat devices. Auto-approval fires only for a new (unpaired) operator browser device on a connection that already passed trusted-proxy auth with a resolved allowUsers user. Scope upgrades on existing devices and node pairing stay manual. Granted scopes are capped to the configured set intersected with the connection's x-openclaw-scopes proxy cap, operator.admin is rejected at config validation, and the pairing-store approval rechecks new-device status under the store lock so a repair/upgrade or concurrent approval can never be silently widened. Each auto-approval emits an audit log line with the proxy user and granted scopes, and `openclaw security audit` warns when the mode is enabled. * docs: regenerate docs map for trusted-proxy auto-approval section