Share concurrent Session Share node listings under service-owned authority and bound progressive chat-startup waits to five seconds. Retain compatible pending pages and publish completed refreshes through the existing catalog lifecycle, preserving current caller filtering. Targeted metadata, pagination, and non-progress clients retain complete-response semantics.
A synthetic six-caller progressive burst behind a 30-second node response improves from 30000 ms p99 and six RPCs to 5000 ms and one RPC. Testbox validation passed 41 focused tests, 64 existing gateway/service tests, typechecks, lint, and architecture checks. Independent review found no remaining actionable issues.
* test(upgrade): assert explicit baseline plugin
* fix(session-share): hide subagents and tool activity
Publish only user and assistant conversation text from eligible root sessions. Preserve forks, redaction, read-only storage, and pagination; reject cursors from the previous mixed-item projection. Skip unrelated local adoption scans for publication-only catalog queries.
* feat(node-host): advertise an explicit node command allowlist
Persist exact node command selection and restrict ancillary publication and hosting. Preserve the unchanged assertion baseline under the work-order stop rule; check:changed requests removing the obsolete runtime.ts count (2 to 0).
* feat(plugin-sdk): session transcript catalog reader
Expose bounded read-only native display pages and portable attribution through the existing runtime subpath. Keep pagination scoped to the original active transcript branch and allow an explicit bounded native cursor length.
* feat(session-share): read-only OpenClaw session catalog across paired gateways
Publish explicitly selected native session groups through two paired node commands. Validate the closed wire contract, reject remote profile claims, and keep receiver identity binding opt-in and display-only.
* fix(gateway): show published session catalogs to view-scoped roles
Let publication consent satisfy catalog read visibility for roles allowed to view others, while owner-only and unprofiled callers stay hidden. Preserve published attribution without accepting a remote local-session adoption claim. Regression tests reproduce four pre-fix failures; final validation stopped at the work-order baseline gate.
* docs: session sharing across gateways
Document sessions-only node setup, explicit publication groups, receiver attribution, view-scoped catalog access, and read-only limits. Add the bundled plugin inventory and generated reference entry. Live proof runbook remains outside the repository; build and rig execution are blocked by the work-order baseline restriction.
* fix(session-share): preserve source storage and paired reconnects
Respect configured stores through listing, paging, and revocation. Keep cold listings available and bound raw transcript reads. Prefer the established paired node credential on service restart, suppress unrelated host metrics, and refresh the approved plugin configuration docs.
* refactor(gateway): separate authorized catalog reads
Keep the catalog dispatcher within its owned scope and preserve post-read role checks and sender projection. Align the rebased tests with their shared setup and imports.