seteiro and Xubin Ren
c6a4d46a2a
docs(security): recommend env-var references over plaintext API keys
...
Prefer ${VAR} env references in config over plaintext keys on disk. Closes #4803
2026-07-22 01:45:28 +08:00
chengyongru and GitHub
462a0dfb0f
refactor(channels): make built-in channels self-contained ( #4908 )
...
* refactor(channels): own setup and instance contracts
* refactor(channels): isolate management contracts
* refactor(channels): normalize activation contracts
* fix(channels): enforce management contracts
* refactor(channels): finish setup ownership migration
* fix(channels): harden management contracts
* fix(channels): enforce lazy loading and runtime ownership
* fix(feishu): make multi-instance startup idempotent
* fix(webui): render channel setup contracts cleanly
* fix(feishu): stop websocket clients cleanly
* fix(channels): enforce persistence and activation gates
* fix(channels): preserve global feature action scope
* fix(channels): apply defaults for single plugins
* fix(channels): enforce management contract boundaries
* refactor(feishu): remove identity helper indirection
* fix(channels): preserve management setup contracts
* refactor(channels): generalize instance settings UI
* refactor(channels): package channel plugins with web UI metadata
* refactor(channels): make built-ins self-contained packages
* test(channels): colocate tests with channel packages
* fix(dingtalk): use official brand icon
* feat(channels): colocate webui translations
* docs(channels): clarify plugin ownership
* test(exec): remove output wait race
* refactor(channels): unify plugin descriptors
* fix(channels): enforce descriptor-owned contracts
* refactor(channels): finish package-owned plugin setup
* refactor(channels): use repository-owned packages only
* fix(channels): self-describe dependencies and runtime state
* fix(channels): warn about legacy entry points
2026-07-19 23:30:49 +08:00
chengyongru and Xubin Ren
883776358e
fix: keep local api serve unauthenticated
...
maintainer edit: Align OpenAI-compatible API auth with the WebSocket channel boundary: loopback serve remains usable without a key, while wildcard binds still fail before agent initialization unless api.api_key is configured.
2026-07-08 12:16:12 +08:00
chengyongru and Xubin Ren
28141ce20b
docs: update serve api key requirement
...
maintainer edit: Align OpenAI-compatible API docs and examples with the new fail-closed api.api_key requirement while keeping /health documented as unauthenticated.
2026-07-08 12:16:12 +08:00
chengyongru and Xubin Ren
ed48325346
fix: cover API auth guard regressions
...
Maintainer edit: restore CI by updating serve/onboard tests, add auth/config coverage, and keep auth failures on the OpenAI-compatible error shape.
2026-07-01 13:09:49 +08:00
chengyongru and Xubin Ren
b015515f30
docs(security): remove whatsapp bridge wording
2026-06-27 11:05:03 +08:00
chengyongru and Xubin Ren
be88e14424
docs(security): trim whatsapp migration note
2026-06-27 11:05:03 +08:00
chengyongru and Xubin Ren
2a9e288dfe
refactor(whatsapp): replace bridge with neonize
2026-06-27 11:05:03 +08:00
Xubin Ren
9823130432
docs: clarify bwrap sandbox is Linux-only
2026-04-05 19:28:46 +00:00
Re-bin
998021f571
docs: refresh install/update guidance and bump v0.1.4.post4
2026-03-08 16:57:28 +00:00
Re-bin
bbfc1b40c1
security: deny-by-default allowFrom with wildcard support and startup validation
2026-03-02 06:13:37 +00:00
Xubin Ren and GitHub
831eb07945
docs: update security guideline
2026-02-18 02:00:30 +08:00
Re-bin
fd7e477b18
fix(security): bind WhatsApp bridge to localhost + optional token auth
2026-02-13 05:37:56 +00:00
Re-bin
c5191eed1a
refactor: unify workspace restriction for file tools, remove redundant checks, fix SECURITY.md
2026-02-06 09:16:20 +00:00
copilot-swe-agent[bot] and kingassune
56d301de3e
Address code review feedback: improve function naming and consolidate patterns
...
Co-authored-by: kingassune <6126851+kingassune@users.noreply.github.com >
2026-02-03 22:12:01 +00:00
copilot-swe-agent[bot] and kingassune
cbb99c64e5
Add comprehensive security documentation and improve command filtering
...
Co-authored-by: kingassune <6126851+kingassune@users.noreply.github.com >
2026-02-03 22:10:43 +00:00