Peter Steinberger
97e56cb73c
fix(discord): land proxy/media/reaction/model-picker regressions
...
Reimplements core Discord fixes from #25277 #25523 #25575 #25588 #25731 with expanded tests.
- thread proxy-aware fetch into inbound attachment/sticker downloads
- fetch /gateway/bot via proxy dispatcher before ws connect
- wire statusReactions emojis/timing overrides into controller
- compact model-picker custom_id keys with backward-compatible parsing
Co-authored-by: openperf <openperf@users.noreply.github.com >
Co-authored-by: chilu18 <chilu18@users.noreply.github.com >
Co-authored-by: Yipsh <Yipsh@users.noreply.github.com >
Co-authored-by: lbo728 <lbo728@users.noreply.github.com >
Co-authored-by: s1korrrr <s1korrrr@users.noreply.github.com >
2026-02-25 00:03:30 +00:00
Peter Steinberger
55cf92578d
fix(security): harden system.run companion command binding
2026-02-25 00:02:03 +00:00
Fred White
b7deb062ea
fix: normalize "bedrock" provider ID to "amazon-bedrock"
...
Add "bedrock" and "aws-bedrock" as aliases for the canonical
"amazon-bedrock" provider ID in normalizeProviderId().
Without this mapping, configuring a model as "bedrock/..." causes
the auth resolution fallback to miss the Bedrock-specific AWS SDK
path, since the fallback check requires normalized === "amazon-bedrock".
This primarily affects the main agent when the explicit auth override
is not preserved through config merging.
Fixes #15716
2026-02-24 23:57:11 +00:00
suko
b3e6653503
fix(onboard): avoid false 'telegram plugin not available' block
2026-02-24 23:55:27 +00:00
Peter Steinberger
b0bb3cca8a
test(types): fix ts narrowing regressions in followup and matrix queue tests
2026-02-24 23:54:51 +00:00
Mark Musson
e22a2d77ba
fix(whatsapp): stop retry loop on non-retryable 440 close
2026-02-24 23:52:49 +00:00
Peter Steinberger
def993dbd8
refactor(tmp): harden temp boundary guardrails
2026-02-24 23:51:10 +00:00
Vincent Koc
cc386f4962
Telegram tests: route exact do not do that to control lane
2026-02-24 18:50:53 -05:00
Vincent Koc
83f586b93b
Gateway tests: cover exact do not do that stop matching
2026-02-24 18:50:53 -05:00
Vincent Koc
91391bbe01
Auto-reply tests: assert exact do not do that behavior
2026-02-24 18:50:53 -05:00
Vincent Koc
7bb08ba945
Auto-reply: add exact stop trigger for do not do that
2026-02-24 18:50:53 -05:00
Peter Steinberger
53f9b7d4e7
fix(automation): harden announce delivery + cron coding profile ( #25813 #25821 #25822 )
...
Co-authored-by: Shawn <shenghuikevin@shenghuideMac-mini.local >
Co-authored-by: 不做了睡大觉 <user@example.com >
Co-authored-by: Marcus Widing <widing.marcus@gmail.com >
2026-02-24 23:49:34 +00:00
Peter Steinberger
36d1e1dcff
refactor(telegram): simplify DM media auth precheck flow
2026-02-24 23:49:10 +00:00
Peter Steinberger
316fad13aa
refactor(outbound): unify attachment hydration flow
2026-02-24 23:48:43 +00:00
Brian Mendonca
9924f7c84e
fix(security): classify hook sessions case-insensitively
2026-02-24 23:48:09 +00:00
Brian Mendonca
48b052322b
Security: sanitize inherited host exec env
2026-02-24 23:46:39 +00:00
Peter Steinberger
9514201fb9
fix(telegram): block unauthorized DM media downloads
2026-02-24 23:44:50 +00:00
Brian Mendonca
5a64f6d766
Gateway/Security: protect /api/channels plugin root
2026-02-24 23:44:32 +00:00
Peter Steinberger
453664f09d
refactor(zalo): split monitor access and webhook logic
2026-02-24 23:40:51 +00:00
Peter Steinberger
58309fd8d9
refactor(matrix,tests): extract helpers and inject send-queue timing
2026-02-24 23:37:50 +00:00
Peter Steinberger
a2529c25ff
test(matrix,discord,sandbox): expand breakage regression coverage
2026-02-24 23:37:50 +00:00
Peter Steinberger
13a1c46396
fix(web-search): reduce provider auto-detect log noise
2026-02-24 23:32:29 +00:00
Peter Steinberger
79a7b3d22e
test(line): align tmp-root expectation after sandbox hardening
2026-02-24 23:31:54 +00:00
Peter Steinberger
4355e08262
refactor: harden safe-bin trusted dir diagnostics
2026-02-24 23:29:44 +00:00
Peter Steinberger
5c2a483375
refactor(outbound): centralize attachment media policy
2026-02-24 23:29:05 +00:00
Peter Steinberger
54648a9cf1
refactor: centralize followup origin routing helpers
2026-02-24 23:28:58 +00:00
Peter Steinberger
9b53102100
test: add routing/session isolation edge-case regressions
2026-02-24 23:28:58 +00:00
Peter Steinberger
e7a5f9f4d8
fix(channels,sandbox): land hard breakage cluster from reviewed PR bases
...
Lands reviewed fixes based on #25839 (@pewallin), #25841 (@joshjhall), and #25737/@25713 (@DennisGoldfinger/@peteragility), with additional hardening + regression tests for queue cleanup and shell script safety.
Fixes #25836
Fixes #25840
Fixes #25824
Fixes #25868
Co-authored-by: Peter Wallin <pwallin@gmail.com >
Co-authored-by: Joshua Hall <josh@yaplabs.com >
Co-authored-by: Dennis Goldfinger <dennisgoldfinger@gmail.com >
Co-authored-by: peteragility <peteragility@users.noreply.github.com >
2026-02-24 23:27:56 +00:00
Peter Steinberger
5552f9073f
refactor(sandbox): centralize network mode policy helpers
2026-02-24 23:26:46 +00:00
Peter Steinberger
14b6eea6e3
feat(sandbox): block container namespace joins by default
2026-02-24 23:20:34 +00:00
Peter Steinberger
ccbeb332e0
fix: harden routing/session isolation for followups and heartbeat
2026-02-24 23:20:27 +00:00
Peter Steinberger
270ab03e37
fix: enforce local media root checks for attachment hydration
2026-02-24 23:17:48 +00:00
Peter Steinberger
b67e600bff
fix(security): restrict default safe-bin trusted dirs
2026-02-24 23:13:37 +00:00
Peter Steinberger
d3da67c7a9
fix(security): lock sandbox tmp media paths to openclaw roots
2026-02-24 23:10:19 +00:00
Peter Steinberger
bf8ca07deb
fix(config): soften antigravity removal fallout ( #25538 )
...
Land #25538 by @chilu18 to keep legacy google-antigravity-auth config entries non-fatal after removal (see #25862 ).
Co-authored-by: chilu18 <chilu.machona@icloud.com >
2026-02-24 23:02:45 +00:00
Peter Steinberger
9ef0fc2ff8
fix(sandbox): block @-prefixed workspace path bypass
2026-02-24 17:23:14 +00:00
Ayaan Zaidi
f154926cc0
fix: land telegram empty-html fallback hardening ( #25096 ) (thanks @Glucksberg)
2026-02-24 22:34:21 +05:30
Ayaan Zaidi
6e31bca198
fix(telegram): fail loud on empty text fallback
2026-02-24 22:34:21 +05:30
Glucksberg
566a8e7137
chore(telegram): suppress handled empty-text retry logs
2026-02-24 22:34:21 +05:30
Glucksberg
51b3e23680
fix(telegram): fallback to plain text when threaded markdown renders empty
...
Minimal fix path for Telegram empty-text failures in threaded replies.
- fallback to plain text when formatted htmlText is empty
- retry plain text on parse/empty-text API errors
- add focused regression test for threaded mode case
Related: #25091
Supersedes alternative fix path in #17629 if maintainers prefer minimal scope.
2026-02-24 22:34:21 +05:30
Peter Steinberger
0f0a680d3d
fix(exec): block shell-wrapper positional argv approval smuggling
2026-02-24 15:17:03 +00:00
Mariano Belinky
4ec0af00fe
Agents: fix embedded auth-profile failure helper typing
2026-02-24 15:16:11 +00:00
Peter Steinberger
d18ae2256f
refactor: unify channel plugin resolution, family ordering, and changelog entry tooling
2026-02-24 15:15:22 +00:00
Peter Steinberger
878b4e0ed7
refactor: unify tools.fs workspaceOnly resolution
2026-02-24 15:14:05 +00:00
Peter Steinberger
13bfe7faa6
refactor(sandbox): share bind parsing and host-path policy checks
2026-02-24 15:04:47 +00:00
Peter Steinberger
0e155690be
fix(config): add operational guidance to legacy talk help
...
Co-authored-by: Nimrod Gutman <nimrod.g@singular.net >
2026-02-24 15:02:52 +00:00
Peter Steinberger
44162055a8
fix(config): dedupe talk schema help keys
2026-02-24 15:02:52 +00:00
Nimrod Gutman
d58f71571a
feat(talk): add provider-agnostic config with legacy compatibility
2026-02-24 15:02:52 +00:00
Nimrod Gutman
d1f28c954e
feat(gateway): surface talk elevenlabs config metadata
2026-02-24 15:02:52 +00:00
Peter Steinberger
3b4dac764b
fix: doctor plugin-id mapping for channel auto-enable ( #25275 ) (thanks @zerone0x)
2026-02-24 14:55:23 +00:00