Commit Graph
26 Commits
Author SHA1 Message Date
Zayn JarvisandClaude Fable 5 03bd469417 fix(openclaw-plugin): drop SecretRef exec resolver from packaged plugin (#3849)
Marketplace install scanners (ArkClaw) block plugins whose shipped code
contains child_process. Keep env/file SecretRef sources; configuring
{source:"exec"} now fails with a clear error pointing at env/file.

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-08-06 18:50:38 +08:00
Ziyang Guo abc387955d feat(openclaw-plugin): SecretRef support for config.apiKey (#3522) (#3618)
Issue #3522 — the OpenClaw plugin's `config.apiKey` only accepted a plain
string, resolved through local `${ENV_VAR}` interpolation. `INSTALL*.md`
documented this as a known limitation: users who store their other OpenClaw
provider credentials (LLM, TTS, MCP servers) through the standard
`{source, id[, provider]}` SecretRef mechanism (env / file mount /
exec-backed vault such as 1Password, Vault, gopass) had to keep the
OpenViking key as cleartext inside `openclaw.json`.

### config.ts — `string | OpenVikingSecretRef` widening

* Add `OpenVikingSecretRef = "env"|"file"|"exec"` discriminated union type,
  matching the shape OpenClaw core uses for its own credential fields
  (`env` + `file` implemented in-plugin, `exec` forwarded to `child_process`
  so providers like `@transmitt0r/openclaw-plugin-onepassword` can manage
  the OpenViking key without SDK coupling).
* Add `resolveSecret()` resolver with explicit, actionable errors:
  - env: unset var = throw, no silent empty fallback
  - file: `~` expanded, UTF-8 read, whitespace trimmed; unreadable file
    rethrows with the OpenViking field name prefixed so config misconfigs
    surface with a clear label and path
  - exec: lazy `require("node:child_process").execFileSync(provider,[id])`,
    stdout trimmed, 15s timeout; errors prefixed with provider + id
  - unknown source / missing id / missing exec provider = explicit throw
* `memoryOpenVikingConfigSchema.parse()` widens `rawApiKey` to
  `string | OpenVikingSecretRef`, then passes it through
  `resolveSecret(rawApiKey, "config.apiKey")` *before* the existing
  `resolveEnvVars` pass. Plain strings transparently fall through
  `resolveSecret` unchanged, so `${ENV_VAR}` interpolation is preserved
  100% backward-compatibly.
* `OPENVIKING_API_KEY` env fallback is unchanged and triggers only when the
  `apiKey` config key is absent — a user who deliberately sets `apiKey: ""`
  still gets "" (explicitly unauthenticated), not the env fallback.
* `uiHints.apiKey.help` documents the SecretRef shape and recommends it.

### openclaw.plugin.json — widening schema + UI hints

* `configSchema.properties.apiKey` becomes `oneOf: [string, env ref, file ref, exec ref]`.
  Each object variant has a `title`, `additionalProperties: false`,
  `required`, and explicit description per field, so OpenClaw's config UI
  can render them individually instead of showing a generic JSON object blob.
* `uiHints.apiKey.help` matches the new config.ts wording.

### INSTALL.md / INSTALL-ZH.md — SecretRef usage tables

Replace the old "plaintext / chmod 0600" caveat bullet with a 3-row table
(env / file / exec) showing example JSON + notes (Kubernetes secretKeyRef
mount for `file`, 1Password `op://` URL convention for `exec`). The
backward-compat string path is retained at the end of the new bullet so
existing deployments that haven't migrated yet still get the old permission
advice — no surprise behaviour for upgrading users.

### tests/ut/config.test.ts — SecretRef regression suite (10 new cases)

Under a new `describe("… SecretRef (#3522)")`:

1. Backward compat: `${OV_KEY}` interpolation still resolves.
2. env source — happy path with a fresh env var.
3. env source — unset var throws, no silent fallback.
4. file source — real `mkdtemp`-created file, trimmed whitespace. Cleanup
   in `afterEach`.
5. file source — missing-path error message contains readable label + path.
6. exec source — `vi.spyOn(child_process.execFileSync)` asserts provider +
   args, stdout trimmed.
7. exec source — missing `provider` field errors.
8. Schema validation — unknown `source` and missing `id` each throw with
   error messages that name the problem.
9. Env fallback boundary — explicit `apiKey: ""` is NOT overridden by
   OPENVIKING_API_KEY, but `apiKey` absent IS (backward-compat behaviour
   contract pinned with a test so future refactors can't regress).

Covers every branch inside `resolveSecret()`, plus the backward-compat
contracts issue #3522 called out.
2026-07-30 16:21:06 +08:00
Zayn Jarvis 3043e25194 docs(openclaw): document manual plugin configuration (#3446)
* docs(openclaw): document manual plugin configuration

* docs(openclaw): clarify manual config safety

* docs(openclaw): sync manual config guidance
2026-07-23 10:46:53 +08:00
Evo f8ae35c274 fix(openclaw-plugin): require OpenClaw 2026.5.27 (#3021) 2026-07-07 21:35:04 +08:00
Mingjian Que ccf00aa8a4 feat(openclaw): add TOS release installer flow (#2653) 2026-06-17 01:07:50 +08:00
Qin Haojie 794ee3ee41 fix(openclaw): default peer role to assistant (#2626) 2026-06-15 21:54:55 +08:00
Qin HaojieandMijamind719 8353976bc8 feat(plugins): use actor peer scope (#2595)
* feat(plugins): use actor peer scope

* docs(openclaw): clarify actor peer recall scope

---------

Co-authored-by: Mijamind719 <mijamind@163.com>
2026-06-14 10:15:27 +08:00
Qin Haojie ff258768c2 feat(memory): 引入 User/Peer 记忆隔离模型 (#2236)
* feat(memory): introduce user and peer memory isolation

Unify agent-scoped memory behavior into user-owned memory spaces, add peer_id compatibility for session and retrieval paths, and wire memory_policy through session commit flows.

* feat(memory): align session identity around peer IDs

* feat(search): pass peer id through retrieval

* refactor(memory): remove agent identity from integrations

* fix(memory): isolate peer identity from self extraction

* fix(tau2): provision benchmark user configs

* fix(auth): allow admin keys to access data APIs

* fix(openclaw): enable peer memory policy for peer roles

* fix(openclaw): resolve sender for peer recall

* refactor(session): simplify memory extraction routing

* refactor(ov-cli): reduce formatting-only diff

* refactor(message): remove unused message helpers

* refactor(retrieval): simplify peer target resolution

* refactor(namespace): remove deprecated agent namespace policy

* fix(agent): propagate peer id through integrations

* fix(auth): align integration clients with api-key mode
2026-06-05 10:55:48 +08:00
LinQiang391andCursor 87039cac4c docs(openclaw): align plugin docs with ClawHub standard install experience (#2150)
Use explicit clawhub: prefix across all install paths (README, INSTALL, INSTALL-ZH, INSTALL-AGENT, SKILL.md) since bare specs resolve to npm on current OpenClaw. Restructure ClawHub README with Quick Start first screen, How It Works, Tools table, Data Flow and Privacy section. Move engineering details into collapsible section. Demote ov-install to fallback. Fix ov-install params, OpenClaw min version, and parameter table. Allow images in ClawHub bundle.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-21 20:15:23 +08:00
LinQiang391andLinQiang391 933ece4acb docs(openclaw): use canonical OpenViking plugin package (#2099)
Co-authored-by: LinQiang391 <linqiang391@users.noreply.github.com>
2026-05-18 10:55:01 +08:00
LinQiang391andLinQiang391 72a3cd29f0 feat(openclaw-plugin): support OpenClaw install and ClawHub release flow (#1904)
Squashes OpenClaw plugin install compatibility, setup helper source-build support, built dist output, and ClawHub release workflow updates into one publish commit.

Co-authored-by: LinQiang391 <linqiang391@users.noreply.github.com>
2026-05-08 17:38:04 +08:00
AutoCoder 4d6f5b65bd fix(openclaw): route auto recall through assemble (#1835) 2026-05-01 16:39:32 +08:00
bot-of-qin-ctxandqin-ctx 9c08d716ca fix(openclaw): treat agent_prefix as prefix only (#1809)
* fix(openclaw): treat agent_prefix as prefix only

* fix(openclaw): treat agent_prefix as prefix only

---------

Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
2026-04-29 22:42:56 +08:00
LinQiang391 dac750e144 refactor(openclaw-plugin): remove local mode and rename agentId to agent_prefix (#1783)
Made-with: Cursor
2026-04-28 22:42:49 +08:00
LinQiang391 09bb76cf61 feat: add ClawHub publishing, setup wizard, and OPENCLAW_STATE_DIR support (#1587)
Made-with: Cursor
2026-04-21 11:27:46 +08:00
mrj666 f6a4b4e3a7 docs(openclaw-plugin): add health check tools guide (#1326)
Add solution for health check tools report http 404 error
2026-04-09 18:56:17 +08:00
Qin Haojie bfc11a3955 fix(openclaw-plugin): simplify install flow and harden helpers (#1095) 2026-03-31 09:53:57 +08:00
LinQiang391 1b634254c2 feat(openclaw-plugin): default plugin install to latest Git tag (#1050)
- Resolve latest semver tag from GitHub API when PLUGIN_VERSION unset

- Mirror logic in install.sh and setup-helper/install.js

- Update INSTALL.md / INSTALL-ZH.md for new defaults and examples

- Bump openclaw-openviking-setup-helper to 0.2.11 (npm)

Made-with: Cursor
2026-03-28 10:22:23 +08:00
LinQiang391 182a4d428f feat(installer, openclaw-plugin): unified installer upgrade (#1020)
- Installer: Python path fix, version compatibility, legacy plugin support (79781f58)
- OpenClaw plugin: manifest/FALLBACK optional+required, download retries, optional 404 UX; session-transcript-repair.ts optional in manifest (installer may skip on 404)
- context-engine unchanged from base (static session-transcript-repair import)
- Docs: INSTALL/INSTALL-ZH; Windows via npm/ov-install; remove install.ps1 and INSTALLER-UPGRADE-PROPOSAL
- setup-helper version bump for npm dev line

Made-with: Cursor
2026-03-27 14:06:13 +08:00
Yaoyao 4c21ef0af6 Update INSTALL.md (#917)
delete uninstall openclaw command
2026-03-24 14:33:34 +08:00
AutoCoder b994bdbba2 Add instructions for cleaning up old version plugins. (#843) 2026-03-21 18:16:28 +08:00
Yaoyao 81a48ddcb0 Update INSTALL.md (#823)
update plugin2.0 installation en version
2026-03-20 20:04:22 +08:00
zhoujiahui 06dad3a953 Update docs (#782)
* docs(openclaw): refresh plugin 2.0 compatibility notes

* docs(openclaw): clarify 2.0 legacy incompatibility

* docs(openclaw): clarify old openclaw is unsupported
2026-03-19 20:59:00 +08:00
AutoCoder c435b345bb update docs for openclaw-plugin (#766) 2026-03-19 15:32:12 +08:00
AutoCoder 51d0be0e98 add openclaw-plugin upgrade description (#758) 2026-03-19 11:49:10 +08:00
Mingjian QueandGPT-5.4 f93d10523b feat(openclaw-plugin 2.0): from memory plugin to context engine (#662)
* feat(openclaw-context-plugin): migrate OpenViking memory plugin to context engine

1. Rename the OpenClaw plugin from memory-openviking to openclaw-context-plugin and switch its kind from memory to context-engine.
2. Keep auto-recall and ingest-reply-assist on before_prompt_build to preserve the existing prompt injection behavior.
3. Move the canonical auto-capture flow from the old agent_end-style lifecycle to ContextEngine afterTurn.
4. Delegate compact handling to the legacy compact engine when it is available, so existing compaction behavior can still be reused.
5. Preserve the OpenViking tools and local process management while updating setup helpers, installers, docs, and OpenClaw config paths to plugins.slots.contextEngine.

Co-authored-by: GPT-5.4 <noreply@openai.com>

* refactor(openclaw-context-plugin): rename plugin id to context-openviking

- rename the runtime plugin id, package name, install destination, and OpenClaw config keys from openclaw-context-plugin to context-openviking
- keep the source directory at examples/openclaw-context-plugin unchanged while updating docs, installers, and setup helpers to use the new runtime name
- remove unused sys imports from the demo scripts so ruff check stays green

---------

Co-authored-by: GPT-5.4 <noreply@openai.com>
2026-03-18 21:10:20 +08:00