mirror of
https://github.com/outbackdingo/optimclaw.git
synced 2026-08-31 08:39:24 +00:00
fix(channels): add host-based credential injection to WASM channel wrapper (#421)
* fix(channels): add host-based credential injection to WASM channel wrapper The channel WASM wrapper was missing the host-based credential injection that the tools wrapper implements. The `credentials` block in channel capabilities files was dead code: Slack's `on_respond` sends requests with no Authorization header, expecting the host to inject the bot token based on `host_patterns`, but the host never did. This caused Slack (and any channel relying on capabilities-declared credentials) to fail all outbound API calls with `not_authed`. Changes: - Add `ResolvedHostCredential` struct mirroring the tools wrapper - Add `host_credentials` field to `ChannelStoreData` - Add `inject_host_credentials()` method on `ChannelStoreData` - Update `redact_credentials()` to also scrub host-injected secret values - Add `secrets_store` field to `WasmChannel` + `with_secrets_store()` builder - Add `resolve_channel_host_credentials()` async helper that decrypts capabilities-declared credentials before each WASM callback - Update `create_store()` and all `call_on_*` / `execute_status` / `execute_poll` call sites to pre-resolve and pass host credentials - Fix leak scan ordering: scan runs on WASM-provided values BEFORE host credential injection, preventing false-positive blocks on injected Bearer tokens (e.g. xoxb- Slack tokens) - Make `credential_injector` module pub(crate) so channels can reuse `inject_credential` and `host_matches_pattern` Fixes #389, root cause of #413 Co-Authored-By: Claude Sonnet 4.6 <[email protected]> * fix(wasm): redact URL-encoded credentials, use url::Url, derive Clone Address review feedback on PR #421: 1. Security: redact_credentials now scrubs URL-encoded forms of secrets in addition to raw values, preventing exfiltration via encoded representations in error strings from reqwest 2. Use url::Url::query_pairs_mut() for query parameter injection instead of manual string manipulation, improving robustness with malformed URLs 3. Derive Clone on ResolvedHostCredential and simplify the per-tick clone in the status repeater loop Co-Authored-By: Claude Opus 4.6 <[email protected]> * style: cargo fmt Co-Authored-By: Claude Opus 4.6 <[email protected]> --------- Co-authored-by: Sprite <[email protected]> Co-authored-by: Claude Sonnet 4.6 <[email protected]>
This commit is contained in:
co-authored by
Sprite
Claude Sonnet 4.6
parent
a21dba0ac1
commit
dc7d9cce34
@@ -76,7 +76,7 @@
|
||||
mod allowlist;
|
||||
mod capabilities;
|
||||
mod capabilities_schema;
|
||||
mod credential_injector;
|
||||
pub(crate) mod credential_injector;
|
||||
mod error;
|
||||
mod host;
|
||||
mod limits;
|
||||
|
||||
Reference in New Issue
Block a user