mirror of
https://github.com/openclaw/openclaw.git
synced 2026-08-02 16:41:37 +00:00
* feat(gateway): share the canonical browser-origin policy with plugins Export resolveAcceptedBrowserOrigin through openclaw/plugin-sdk/webhook-request-guards so browser-facing plugin routes reuse the Gateway's real origin contract instead of a narrow allowedOrigins array check. Private LAN/Tailnet Control UI loads and the Host-header fallback were previously rejected with 403 by plugin offer routes while the Control UI itself worked. Moves the loopback/forwarded-header helpers to net.ts (re-exported from auth.ts) so the guard can delegate without importing gateway auth, and migrates the Codex realtime broker onto the shared seam. * feat(talk): let providers own agent delegation for realtime voice Adds an optional runAgentConsult callback to the browser-session create request and injects the existing embedded consult runtime from talk-client, bound to the same agent and session key the GA tool path uses. Providers whose realtime protocol delegates work through their own control channel (rather than GA function calls) can now reach the OpenClaw agent without a client round-trip. Threads the effective per-session model into browser-session capability resolution so a request-level model override selects the right capability set, and propagates a caller abort signal into consultRealtimeVoiceAgent so a superseded delegation stops its run. * feat(openai): support GPT-Live realtime voice over ChatGPT OAuth Implements OpenAI's quicksilver/frameless session natively for Talk browser sessions. The Gateway creates the WebRTC call (multipart sdp+session to https://api.openai.com/v1/live) and owns the sideband control socket, so the browser never holds upstream credentials; delegation.created events run through the OpenClaw agent and stream back as speakable context appends. Verified end-to-end on 2026-07-28 against a ChatGPT Pro OAuth profile: call create 201 with an rtc_* id and answer SDP, sideband session.started, session.close teardown. ChatGPT OAuth is preferred over a Platform API key because /v1/live access for platform keys is waitlist-gated; the legacy chatgpt.com backend route returns 403 for every model and protocol version and is not used. Accepted models are gpt-live-1-codex and gpt-live-1-boulder-alpha; the voice allowlist is the ten values the route actually accepts, since an invalid voice is rejected at call creation and cannot be repaired afterwards (session.update reports immutable_field_update). * docs: document GPT-Live Talk support and its route gotchas Records the working route and auth, the accepted models and voices, the browser-only scope, and the two traps that cost the most time: the chatgpt.com backend route returns 403 Voice session access denied for every model, and that same 403 is also what an invalid voice returns, so it must not be read as an account entitlement block. * fix(openai): resolve GPT-Live CI failures * refactor(openai): own zod runtime dependency * fix(openai): satisfy lint and live-shard gates for GPT-Live Types the retry-delay finish callback as Error so the rejection reason is provably an Error at the call site; the abort path already normalized a non-Error AbortSignal reason, but the unknown parameter type hid that from static analysis. Registers the new GPT-Live live test in the native-live-extensions-openai shard expectation. The shard selector already picked the file up from the real tree; only the hardcoded list in the tooling test lagged. * fix(openai): clean up post-rebase capability resolver * fix(openai): preserve GPT-Live delegation fragments * fix(openai): close GPT-Live sideband handoff race * fix(openai): accept UUID GPT-Live call ids * style: apply oxfmt to GPT-Live sources and Talk docs * style: format Talk docs after rebase * fix(openai): keep GPT-Live transcript context across ignored delegations