Skip to content

Commit 14a57dd

Browse files
committed
feat(plugins): checkpoint experimental authorization policies
1 parent e670d6d commit 14a57dd

446 files changed

Lines changed: 38716 additions & 4718 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

CHANGELOG.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,7 @@ Docs: https://docs.openclaw.ai
66

77
### Changes
88

9+
- **Sender-aware authorization policies:** let trusted plugins veto prepared tool calls, message actions, and commands from host-authenticated per-turn principals, with scoped fail-closed policy pins and authority-safe queue, steering, delegation, and native-harness propagation. (#103780)
910
- **External gateway supervision:** add `OPENCLAW_SUPERVISOR_MODE=external` for lifecycle owners such as OCM, preserving verified restart and deferral behavior without exposing native service authority, blocking native service mutation and self-update, and providing a versioned atomic restart-handoff consume contract. Thanks @shakkernerd.
1011
- **ClickClack guided setup:** configure ClickClack from `openclaw onboard` or `openclaw channels add clickclack` with URL, token, and workspace prompts, default-account env fallback, nonfatal live connection validation, and gateway-aware next steps that connect automatically when OpenClaw is already running. Thanks @shakkernerd.
1112
- **ClickClack command menus:** publish each bot's native OpenClaw commands to ClickClack composer autocomplete at gateway startup, with per-account opt-out and nonfatal compatibility handling for older tokens and servers. Thanks @shakkernerd.
Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
53e7eea9a0193d94f5afe8e774456ae71cd3eddf99e5224602fcf13bb845051b config-baseline.json
2-
97c9ec219366ad2fab4d83d5b05eb3ae3df71db68747e7b31cc697a76676c620 config-baseline.core.json
1+
476dc4939943e733027107ad63d8cc23a5ee1161fbe270cabf7ba4394a348458 config-baseline.json
2+
faaed74498c4fc11ea34930e1bdb871bd95c9d38c0bdb38a1a3e232073eb2130 config-baseline.core.json
33
f75efa4f3fa4ac7c2e7dc6580a1dd1efaa8e2e13ec7df9c21838c8ebc44a3dca config-baseline.channel.json
4-
e4f096d6d3c39fefdd1649cab8336b8dfba1f2194eb804fa6126eb25fe2d2b93 config-baseline.plugin.json
4+
2e16473c11b427484212b8ff996339460799a448403677c154703dbe0196091a config-baseline.plugin.json

docs/.generated/plugin-sdk-api-baseline.sha256

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@ e5e67ddf3cab38fcbf9220bc3160715897e2709d9a9ff6ff36f1ecc9453c2367 module/agent-c
1313
30452bae2a689fb75dcb6dba9ef11e5b95f9cbe0c62eb190a0fcb82d0a19ae52 module/agent-core
1414
74daa746deb548379d3f0d6eac3c4d082df1034c4360cc03bf51fee0f10a2e4d module/agent-harness
1515
e09226afd443cee02ed648f032f53bfeb60585617bb523a649995764d3c38da9 module/agent-harness-exec-review-runtime
16-
70ef942580775468e52798ae82ee1084d3f407d76f279c9b3570b258b0ccbd5a module/agent-harness-runtime
16+
898367ed24612c45b4de6b037e1de037e3a2bcb7dc9d1558fa7e3dcccb5faaa6 module/agent-harness-runtime
1717
ec22d7a039fb58d0b8343ad149322960d3d8ca58b3f4c70f2fa8a099f8186d0c module/agent-harness-task-runtime
1818
5f63bf587bf3547d59d0dc5d0dc2fee54745aa6edaab4aa3ae700dba03443edb module/agent-harness-tool-runtime
1919
5168648cd946abad8a92822889f13ceacc87ed502314a66190d0b1eb8ebe76ea module/agent-media-payload
@@ -82,7 +82,7 @@ f687dbadcf1c63d09c03c09d1999bb37e8d49593a311b1c0fa42bcc035477146 module/cli-bac
8282
5f4c67188a022b1c9ad57799df82d2cef6e5744f3ddc29698de4e8e70a30f143 module/codex-mcp-projection
8383
c89ec1b194b76f67a6f4dd108dccf460da6065646cba31374c8aa748f23a39e4 module/collection-runtime
8484
ff4173b17c0140965b08ddf93d4b32c47cd50b65a52ff9ac43db2921658d3a30 module/command-auth
85-
4febe4a5e147a4f1b249355f8a99a8159dc29ed9cee06d4fabe625649d10f21d module/command-auth-native
85+
e7bf15f3d324e124a13eae6fa04f50745e2393b490ba1e85460150e0398b265b module/command-auth-native
8686
fa2df02bede6ed8843e5c2bd605c6ea5cd20313c305593fbd371dba6f1b931c3 module/command-detection
8787
a224ce0381a32ed7a9d2261669c444f7f46701c15bf2f6121e9b057d9910da78 module/command-gating
8888
28a0cae8dee664aef14b1a64c86a46d0fb5637cf9f671790d4fc9ba205e42820 module/command-primitives-runtime
@@ -94,7 +94,7 @@ d340686cf814326b5a554a32cc5ca324a9e1254a933c4d9d8d1ada5ac7109a10 module/command
9494
a821f9cc4e6f9339399d99e73f58c3b00baf139aa9d85c22d73c89d8be5702d2 module/config-contracts
9595
20f3f8042de53e4eee61b64de9102c8c202b9299e6a29235647a4729f70145f2 module/config-mutation
9696
316949815affe623ac63951a5db580527f02663576dffa084f02768f612c0c1c module/config-runtime
97-
e0c0e99a4d797ba583a7d99e258530230ea61c66875bd6cf45843eb9211f4ff0 module/config-schema
97+
275e915d2dff103ebaaef559db4bbbd05f2005b310f70d7135054b7005eb99bf module/config-schema
9898
2efdb1e995106ed5843461b7706100838db80453afa7e27c2c14f9c10a5a1e62 module/config-types
9999
42d15153981cfe3adc1d5f91621434c56f07a9bd48c15ce34742f72dd040c142 module/context-visibility-runtime
100100
03636897fb99cb73e4d8620c8a0e0d72b4d52fc32bf94f525af2aa88c489c6c2 module/conversation-binding-runtime
@@ -201,7 +201,7 @@ ac2114469f321477a1e11133ea629fa672afe1aa9118fd165054009987aec2bb module/outboun
201201
8d8c0c4ebfc6e0c6125df3ae64ec66c10cd797a325de5ea7869fcd84068ab290 module/persistent-dedupe
202202
987648ebe317cc4d6c0505a52d344b12ce9c3a8261a5bd969cee3423c0c53529 module/plugin-config-runtime
203203
32180b2270e462770f064a8b58c0efdd3f71af47b05c6f3874466919052a99f3 module/plugin-entry
204-
60ac40f8b355fc2ed2ebb501360bd6044d054852969f603ff41276116f8254a1 module/plugin-runtime
204+
9109d3b3d5bc6fdef17269eebeb801b4b84bcabb01355610ddce5a2cd5540b01 module/plugin-runtime
205205
109f2b3b0984552e620adfb33c2d5dea6f70b4b440677e77d4fd89679e286683 module/plugin-state-runtime
206206
1a5be86c0c661469b3ba07bb1c3c0db4d893cbe3042040c298a412bfffc10b5b module/poll-runtime
207207
c305e43d9cc43cd699759f36212527a1fc1f1c8d26cfa96425b0dae4a98e91b2 module/process-runtime
@@ -240,7 +240,7 @@ fffda485ad0492168b0b58671a5fe232de028c64cd1c0e36ab710ba7d58bf9d3 module/provide
240240
aa2a56b4448c8ebdec9d06aac95d809995f533093d42fa32cd75e1d852967245 module/question-gateway-runtime
241241
5e6ac90d11f2f6ed764f5c53ef98110551ff4beaa0d5dcc343a3e7d97e41844d module/realtime-bootstrap-context
242242
6f551c1da49e6652f4af775798f45d3f3d5949c884c2e1967fc6254d34e9867e module/realtime-transcription
243-
04832bb02302524d00b0b2b8ef345359cb5e2d680711cafcc0268f75c51661ff module/realtime-voice
243+
1f2b6dfe33bea9627d2c226b45e700fa163e96da84db9be991b215d231082a39 module/realtime-voice
244244
2e09c3181e79e157ed5366b144d116ef8cc06023256ace3fa59b35c43cab513a module/reply-chunking
245245
b673d50862d0c5fd00723252a541ab3baeac196b75f689f56439fdb63a68fda0 module/reply-dedupe
246246
bd2355e94248d21c252148085e5afa5db9a2f3f48f665a8b3e0fcf77326d9b6c module/reply-dispatch-runtime
@@ -277,7 +277,7 @@ f07839f5b8929a179857a0b4b89f8448864078cd5972dd53f9a30e50bf55408d module/session
277277
f59099aa2d536246d4b1297f01bcea66796351a9259debdd45909afeb7a42d86 module/session-store-runtime
278278
b1d0a76337122cb9dbb0c89fbb8bfacc1a88ce689270d3d684019c9a03ce669a module/session-transcript-hit
279279
04c19558a5f27380ea13cadee1e3238729788c18a919fb078b24d2d67d006ecf module/session-transcript-runtime
280-
a8fb87c7c39ec6e874926a311d2306b49843767ee5659e006024c59af822466e module/session-visibility
280+
105f50d48638ea0e52310e6a1fc7dd5d7d4c5433674acbc67334f67689f2fc14 module/session-visibility
281281
695971d31b3e16f0bf9b643acc30df312fe94b3c0dfb27a2e6156c8a00b5e261 module/setup
282282
575fe05081bf9edd1c6d886143e4835c218fb8d0641ce148a4a69d3cefcea2ef module/setup-adapter-runtime
283283
9129c17df1523903f34beffd348ce177fcaa2983e155a8c854a50cf1bd7e99c4 module/setup-runtime

docs/concepts/queue-steering.md

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -38,15 +38,17 @@ Codex review and manual compaction turns reject same-turn steering. When a runti
3838

3939
## Burst example
4040

41-
If four users send messages while the agent is executing a tool call:
41+
If one user sends four messages while the agent is executing a tool call:
4242

4343
- With default behavior, the active runtime receives all four messages in arrival order before its next model decision. OpenClaw drains them at the next model boundary; Codex receives them as one batched `turn/steer`.
4444
- With `/queue collect`, OpenClaw does not steer. It waits until the active run ends, then creates a followup turn with compatible queued messages after the debounce window.
4545
- With `/queue interrupt`, OpenClaw aborts the active run and starts the newest message instead of steering.
4646

4747
## Scope
4848

49-
Steering always targets the current active session run. It does not create a new session, change the active run's tool policy, or split messages by sender. In multi-user channels, inbound prompts already include sender and route context, so the next model call can see who sent each message.
49+
Steering always targets the current active session run. It never changes that run's tool policy. OpenClaw compares the authenticated sender, account, roles, owner/authorization bits, agent, session, and conversation/thread scope with the immutable identity that minted the active run's tools. Only an exact match can enter that run.
50+
51+
In a multi-user channel, a message from another sender—or from the same sender after relevant role or authorization facts change—waits for a separate followup turn. This prevents one person from borrowing another person's active tool capability. The same check applies to `/steer` and other active-run injection paths.
5052

5153
Use `followup` or `collect` when you want messages to queue by default instead of steering the active run. Use `interrupt` when the newest prompt should replace the active run.
5254

docs/concepts/queue.md

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -39,7 +39,9 @@ Same-turn steering is the default. A prompt that arrives mid-run is injected int
3939
- `steer`: inject messages into the active runtime. OpenClaw delivers all pending steering messages **after the current assistant turn finishes executing its tool calls**, before the next LLM call; Codex app-server receives one batched `turn/steer`. If the run is not actively streaming or steering is unavailable, OpenClaw waits until the active run ends before starting the prompt.
4040
- `followup`: do not steer. Enqueue each message for a later agent turn after the current run ends.
4141
- `collect`: do not steer. Coalesce queued messages into a **single** followup turn after the quiet window. If messages target different channels/threads, they drain individually to preserve routing.
42-
- `interrupt`: abort the active run for that session, then run the newest message.
42+
- `interrupt`: abort the active run only when the incoming turn has the same
43+
authenticated controller authority (or an explicit owner/admin override),
44+
then run the newest message. A different sender queues separately.
4345

4446
For runtime-specific timing and dependency behavior, see [Steering queue](/concepts/queue-steering). For the explicit `/steer <message>` command, see [Steer](/tools/steer).
4547

docs/gateway/config-tools.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -172,6 +172,8 @@ Keys use explicit prefixes: `channel:<channelId>:<senderId>`, `id:<senderId>`, `
172172

173173
Per-agent `agents.list[].tools.toolsBySender` overrides the global sender match when it matches, even with an empty `{}` policy.
174174

175+
Sender matches remain bound to the admitted channel route. A delegated turn that targets a different channel provider or account does not reuse unqualified sender selectors such as `id:`, `username:`, or `name:` from the source route; its sender tool policy denies all tools unless that target route admits a new turn. This prevents the same provider-local user ID or handle on another account from inheriting the source sender's tools.
176+
175177
### `tools.elevated`
176178

177179
Controls elevated exec access outside the sandbox:

docs/gateway/configuration-reference.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -263,7 +263,7 @@ See [MCP](/cli/mcp#openclaw-as-an-mcp-client-registry) and
263263
- `plugins.entries.<id>.llm.allowModelOverride`: explicitly trust this plugin to request model overrides for `api.runtime.llm.complete`.
264264
- `plugins.entries.<id>.llm.allowedModels`: optional allowlist of canonical `provider/model` targets for trusted plugin LLM completion overrides. Use `"*"` only when you intentionally want to allow any model.
265265
- `plugins.entries.<id>.llm.allowAgentIdOverride`: explicitly trust this plugin to run `api.runtime.llm.complete` against a non-default agent id.
266-
- `plugins.entries.<id>.authorization.requiredPolicies`: operator-owned fail-closed pins. Each entry has a plugin-local `id` and one or more required `operations`: `tool.call`, `message.action`, or `command.invoke`. A missing registration or handler denies that operation. See [Authorization policies](/plugins/authorization-policies).
266+
- `plugins.entries.<id>.authorization.requiredPolicies`: operator-owned fail-closed pins. Each entry has a plugin-local `id` and one or more required `operations`: `tool.call`, `message.action`, or `command.invoke`. A missing registration or handler denies that operation. Optional `scope` selectors for `agentIds`, `providers`, `accountIds`, and `conversationIds` limit where the pin applies; fields combine with AND semantics, and a parent conversation ID covers its threads. Omit `scope` for a global pin. See [Authorization policies](/plugins/authorization-policies).
267267
- `plugins.entries.<id>.config`: plugin-defined config object (validated by native OpenClaw plugin schema when available).
268268
- Channel plugin account/runtime settings live under `channels.<id>` and should be described by the owning plugin's manifest `channelConfigs` metadata, not by a central OpenClaw option registry.
269269

0 commit comments

Comments
 (0)