mirror of
https://github.com/openclaw/openclaw.git
synced 2026-08-02 14:41:35 +00:00
* feat(sessions): enforce visibility and membership * feat(ui): add session sharing controls * docs: add session sharing implementation report * refactor(sessions): use canonical creator identity * fix(sessions): adopt creator ownership contract * docs: refresh session sharing rebase report * docs: record final creator integration proof * docs: record final main rebase * chore: drop worktree report artifact * fix(sessions): keep drafts owner-only * fix(ui): preserve redacted session restrictions * fix(sessions): preserve scoped sharing authorization * fix(sessions): re-verify session instance inside sharing mutation queue * test(sessions): cover stale sharing mutation * fix(sessions): bind membership to session instance, gate absence blocking on sharing * fix(sessions): preserve entry normalization on rebase * fix(sessions): atomic visibility instance guard, reset visibility on recreate * docs(ui): name the absence-heuristic tradeoff and link follow-up * feat(protocol): expose session sharing row state * docs: note generated creator identity type * fix(sessions): bind member writes and visibility rollback to session instance * fix(ui): discard stale-connection sharing loads; drop worktree scratch files * fix(ui): block composer only on observed sharing state, never on list absence * fix(gateway): authorize agent runs against the resolved session (close keyless bypass) * chore(protocol): allowlist Control UI-only session.sharing event for mobile * test(config): record session.sharing keys in common-tier snapshot * refactor(sessions): unexport internal sharing helpers * test(gateway): update sessions changed routing assertions * fix(sessions): align sharing identity with created actor * fix(sessions): align membership identities and storage keys * fix(gateway): re-filter drafts against fresh sharing state in sessions.list * fix(gateway): drafts stay owner+admin only in the sessions.list fresh filter * fix(ui): re-export sharing protocol types for the Control UI * fix(ui): keep SessionSharingRole internal to satisfy deadcode gate * fix(gateway): read runtime config lazily in session-mutation authorization authorizeSessionMutation ran on every gateway request but eagerly called context.getRuntimeConfig() — a non-trivial config resolve — for methods that are never session mutations. Read config only once a real session-mutation target is resolved. Also register the four session sharing methods in the 2026.7 release-train inventory test. * fix(gateway): share one config snapshot across session-mutation authorization Group rename/delete discovery and the authorization loop were each resolving runtime config separately after the lazy-read change. Memoize the resolve so non-session requests still pay nothing, while any session mutation resolves config at most once and both discovery and authorization use that single snapshot (no double reload, no mid-request config-change split). * fix(gateway): resolve session-sharing CI gates - isGatewayAdmin: null-safe connect access so internal/plugin-runtime runs (which reach authorization with a connect-less client) do not crash. - emitSessionsChanged: scope only to a concrete session key; a [undefined] sessionKeys scope filters nothing correctly and would strip draft gating. - session stores: mark the sync TOCTOU re-read and the sqlite_master existence probe as narrowly-justified raw SQLite primitives. - tests: provide getRuntimeConfig to the session-action contract context, drop a shadowed 'call' binding, use structuredClone, and assert the agent-scoped sessions.changed broadcast shape. * docs(gateway): note best-effort participation gate + refresh native i18n baseline Session ownership/visibility are usability features, not a security boundary (docs/concepts/multi-user.md, SECURITY.md); document that the pre-dispatch authorization is intentionally not commit-bound to the resolved instance. Also refresh apps/.i18n/native-source.json after the session-sharing protocol codegen shifted line numbers of existing native strings (position-only). * test(gateway): reset session sharing snapshots * style(gateway): format sharing reset import