mirror of
https://github.com/openclaw/openclaw.git
synced 2026-04-14 10:41:23 +00:00
Require bridge auth before /sandbox/novnc token redemption and keep the noVNC observer URL out of model-visible prompt context. Local verification: - pnpm test extensions/browser/src/browser/bridge-server.auth.test.ts src/agents/sanitize-for-prompt.test.ts src/agents/pi-embedded-runner.buildembeddedsandboxinfo.test.ts Note: pnpm check currently fails on latest main in unrelated files (src/agents/tools/message-tool.ts and src/gateway/mcp-http.test.ts), outside this PR diff. Thanks @eleqtrizit. Co-authored-by: eleqtrizit <31522568+eleqtrizit@users.noreply.github.com>