mirror of
https://github.com/outbackdingo/optimclaw.git
synced 2026-08-30 16:19:21 +00:00
* test: add failing tests for Discord signature validation and capabilities alias (Red phase) TDD Red phase for #148. Adds 19 tests across 4 categories: - Category 1: CredentialLocationSchema header_name alias (2 failing) - Category 2: Ed25519 signature verification (3 failing) - Category 3: Router signature key management (2 failing) - Category 5: Discord capabilities public_key setup (1 failing) All 8 failures are expected — stubs return false/None by design. Implementation will follow in Green phase. Co-Authored-By: Claude Opus 4.6 <[email protected]> * fix: add Discord Ed25519 signature verification and capabilities alias (#148) Implement the Green phase for Discord channel security fixes: - Add real Ed25519 signature verification in signature.rs using ed25519-dalek - Add #[serde(alias = "header_name")] to CredentialLocationSchema::Header for backward compatibility with external JSON files - Add signature_keys storage to WasmChannelRouter (register/get/unregister) - Add discord_public_key to discord.capabilities.json setup.required_secrets - Add nested capabilities resolution to CapabilitiesFile for channel-level JSON compatibility Co-Authored-By: Claude Opus 4.6 <[email protected]> * style: address PR #372 review comments - Fix invalid hex character in test fake_pub_key (router.rs) - Simplify signature parsing with from_slice/try_from (signature.rs) - Use idiomatic Option::or for nested capability merging (capabilities_schema.rs) Co-Authored-By: Claude Opus 4.6 <[email protected]> * fix: enforce signature verification, staleness check, key validation, recursive resolve Address PR #372 review feedback: - Wire verify_discord_signature() into webhook_handler with Ed25519 signature + timestamp staleness check (5s window via now_secs param) - Validate Ed25519 keys in register_signature_key() (hex decode + VerifyingKey::try_from) before storing, return Result<(), String> - Recursively resolve nested capabilities in resolve_nested() - Add 25 new tests: 8 staleness, 6 key validation, 7 webhook integration (tower::oneshot), 4 resolve_nested edge cases - Fix pre-existing clippy warning in signal.rs Co-Authored-By: Claude Opus 4.6 <[email protected]> * fix: wire register_signature_key() into all channel loading paths The Ed25519 signature key registration was implemented and tested but never called from production code. All three channel loading paths (setup_wasm_channels, activate_wasm_channel, refresh_active_channel) now read the public key from the secrets store and register it with the webhook router, enabling Discord signature verification. Adds `signature_key_secret_name` field to WebhookSchema so channels can declare which secret contains their Ed25519 public key. Co-Authored-By: Claude Opus 4.6 <[email protected]> --------- Co-authored-by: Claude Opus 4.6 <[email protected]>
59 lines
1.6 KiB
JSON
59 lines
1.6 KiB
JSON
{
|
|
"type": "channel",
|
|
"name": "discord",
|
|
"description": "Discord Gateway/Webhook channel for handling slash commands, buttons, and messages",
|
|
"setup": {
|
|
"required_secrets": [
|
|
{
|
|
"name": "discord_bot_token",
|
|
"prompt": "Enter your Discord Bot Token (from Developer Portal)",
|
|
"optional": false
|
|
},
|
|
{
|
|
"name": "discord_public_key",
|
|
"prompt": "Enter your Discord Application Public Key (from Developer Portal > General Information)",
|
|
"optional": false
|
|
}
|
|
]
|
|
},
|
|
"capabilities": {
|
|
"http": {
|
|
"allowlist": [
|
|
{ "host": "discord.com", "path_prefix": "/api/v10" }
|
|
],
|
|
"credentials": {
|
|
"discord_bot_token": {
|
|
"secret_name": "discord_bot_token",
|
|
"location": { "type": "header", "name": "Authorization", "prefix": "Bot " },
|
|
"host_patterns": ["discord.com"]
|
|
}
|
|
},
|
|
"rate_limit": {
|
|
"requests_per_minute": 60,
|
|
"requests_per_hour": 3600
|
|
}
|
|
},
|
|
"secrets": {
|
|
"allowed_names": ["discord_bot_token", "discord_*"]
|
|
},
|
|
"channel": {
|
|
"allowed_paths": ["/webhook/discord"],
|
|
"allow_polling": false,
|
|
"callback_timeout_secs": 45,
|
|
"workspace_prefix": "channels/discord/",
|
|
"emit_rate_limit": {
|
|
"messages_per_minute": 100,
|
|
"messages_per_hour": 5000
|
|
},
|
|
"webhook": {
|
|
"signature_key_secret_name": "discord_public_key"
|
|
}
|
|
}
|
|
},
|
|
"config": {
|
|
"require_signature_verification": true,
|
|
"owner_id": null,
|
|
"dm_policy": "pairing",
|
|
"allow_from": []
|
|
}
|
|
} |