mirror of
https://github.com/outbackdingo/optimclaw.git
synced 2026-08-25 14:53:34 +00:00
* Add GitHub tool for IronClaw - manage repos, issues, PRs, and workflows * Add Discord channel for IronClaw - slash commands and button interactions * Security fixes: URL encoding, secret validation, Discord button handler - Add URL encoding for all path segments and query parameters (P1) - Add path segment validation to prevent path traversal - Add secret_exists check for better error messages (P2) - Fix http_request signature to use 5 args (P2) - Fix Discord button handler to check member field (P2) - Fix typo in Discord slash command format (P2) - Add github.capabilities.json and discord.capabilities.json (Blocker) - Add Cargo.toml for Discord channel (Blocker) - Add limit caps (max 100) for all list operations (P3) - Remove debug logging * Apply Copilot review fixes Security & Code Quality: - Use secret_get instead of workspace_read for GitHub token - Remove manual Authorization header (host injects via capabilities) - Add validation for file paths (reject path traversal) - Add validation for workflow_id and git refs - Fix url_encode_query comment - Add release profile optimizations to Cargo.toml files - Fix package names to match conventions (github-tool, discord-channel) - Add metadata fields to Cargo.toml - Fix rate limits to be consistent (60/min, 3600/hr) - Fix Discord user_name to filter empty global_name - Fix Discord metadata serialization error handling - Update Discord README to clarify which secrets are used by host vs WASM - Better formatting for Discord command option values * applied all PR change requests and comments * cleaned up workspace * Adding validation for empty path segments and event enum in GitHub tool * addedvalidation for events and vaidation to reject empty file path in github tools and implemented safe UTF-8 trunacating * added codegen units and updated truncating logic also update capabilities.json as requested by copilot review * added codegen units and updated truncating logic also update capabilities.json as requested by copilot review * fixed message trucating and remove url_encode alias, also appled all requested changes from last PR comment --------- Co-authored-by: root <root@cafx> Co-authored-by: Peni <[email protected]> Co-authored-by: Illia Polosukhin <[email protected]> Co-authored-by: firat.sertgoz <[email protected]>
39 lines
1.0 KiB
JSON
39 lines
1.0 KiB
JSON
{
|
|
"type": "channel",
|
|
"name": "discord",
|
|
"description": "Discord Gateway/Webhook channel for handling slash commands, buttons, and messages",
|
|
"capabilities": {
|
|
"http": {
|
|
"allowlist": [
|
|
{ "host": "discord.com", "path_prefix": "/api/v10" }
|
|
],
|
|
"credentials": {
|
|
"discord_bot_token": {
|
|
"secret_name": "discord_bot_token",
|
|
"location": { "type": "header", "header_name": "Authorization", "prefix": "Bot " },
|
|
"host_patterns": ["discord.com"]
|
|
}
|
|
},
|
|
"rate_limit": {
|
|
"requests_per_minute": 60,
|
|
"requests_per_hour": 3600
|
|
}
|
|
},
|
|
"secrets": {
|
|
"allowed_names": ["discord_bot_token", "discord_*"]
|
|
},
|
|
"channel": {
|
|
"allowed_paths": ["/webhook/discord"],
|
|
"allow_polling": false,
|
|
"callback_timeout_secs": 45,
|
|
"workspace_prefix": "channels/discord/",
|
|
"emit_rate_limit": {
|
|
"messages_per_minute": 100,
|
|
"messages_per_hour": 5000
|
|
}
|
|
}
|
|
},
|
|
"config": {
|
|
"require_signature_verification": true
|
|
}
|
|
} |