mirror of
https://github.com/openclaw/openclaw.git
synced 2026-08-03 20:51:40 +00:00
* feat(gateway): add loopback locality controls * fix(gateway): keep loopback auth delays enforced under concurrency The pending-timer cap let an attacker park cheap failures in every slot and then guess without penalty. Delays now key off a per-key deadline, so parallel guesses wait out the same escalating penalty and are still bounded by the max delay. * fix(gateway): share one loopback penalty timer per key Concurrent failures on a key now share a single timer and deadline instead of allocating one per in-flight request. Also corrects the security doc: the delay raises the cost of repeated guessing from one source, but credentials are compared before the failure response is delayed, so it is not a defense against parallel fan-out. * docs(gateway): record why loopback delay stays post-verification * docs: refresh generated docs map * docs: refresh plugin SDK API baseline * test: update loopback locality CI expectations
Generated Docs Artifacts
SHA-256 files are tracked drift-detection artifacts. Full generated snapshots remain local inspection artifacts.
Tracked (committed to git):
config-baseline.sha256— hashes of config baseline JSON artifacts.config-baseline.counts.json— maximum entry counts for each config baseline kind.plugin-sdk-api-baseline.sha256— one hash per Plugin SDK entrypoint.sqlite-session-transcript-schema-baseline.sha256— hash of the sessions/transcripts SQLite schema baseline.
Local only (gitignored):
config-baseline.json,config-baseline.core.json,config-baseline.channel.json,config-baseline.plugin.jsonplugin-sdk-api-baseline.json,plugin-sdk-api-baseline.jsonl.artifacts/sqlite-session-transcript-schema-baseline.sql
Do not edit any of these files by hand.
- Regenerate config baseline:
pnpm config:docs:gen - Validate config baseline:
pnpm config:docs:check - Regenerate Plugin SDK API baseline:
pnpm plugin-sdk:api:gen - Validate Plugin SDK API contract manifest:
pnpm plugin-sdk:api:check
The Plugin SDK manifest hashes each entrypoint independently. PRs changing separate public modules therefore update separate records instead of racing to overwrite one whole-surface checksum. Concurrent changes to the same entrypoint remain a real merge conflict and require regeneration against combined source.
- Regenerate SQLite sessions/transcripts schema baseline:
pnpm sqlite:sessions-schema:gen - Validate SQLite sessions/transcripts schema baseline:
pnpm sqlite:sessions-schema:check