openclaw/extensions/vault
Peter Steinberger 074f69e975
refactor(plugins): deslop feature runtime helpers (#162425)
## What Problem This Solves

Feature plugins repeat runtime adapters and utility logic already owned by shared helpers or neighboring modules.

## User Impact

Tool names, descriptions, schemas, manifests, configuration keys, persisted formats, and UI rendering stay unchanged. No migration or operator action is required.

## Why This Change Was Made

- Workboard routes its three remaining read adapters through the existing typed operation binder, preserving argument capture, settlement, and close behavior.
- OpenShell carries resolved targets directly through filesystem helpers; its existing advisory-specific path validation stays intact.
- Copilot uses the existing timeout owner during compaction cancellation and drops a redundant async wrapper.
- Voice Call uses the existing Node-compatible WebSocket SDK transport; its private transport shim and unused direct dependency are removed.
- FaceTime reuses existing boolean, string-list, finite-number, and deferred-promise helpers.
- QA transcript consumers share traversal while keeping their different accepted block types explicit. Mantis and activity readers reuse canonical coercion helpers.
- OnePassword and Vault use Node's stdin consumer while retaining UTF-8 string decoding and existing SecretRef response behavior.
- Memory Core imports its FTS query owner directly and lets the existing timeout resolver own finite-number conversion and clamping. Workboard reuses its local numeric normalization for attachment size.

### Fixes found along the way

Memory Wiki ingestion could exceed the JavaScript argument limit when a file contained many short backtick runs. Fence construction now scans those runs without expanding them into function arguments; the regression exercises ingestion and verifies the persisted source text.

Plivo webhook verification could throw for query/form names such as `__proto__`, `constructor`, and `toString`. A native Map now groups parameters before the existing canonical sorting/signing step. Valid signed cases and invalid signatures are covered through the public verifier.

## Evidence

Independent Codex review completed with no actionable P0–P2 findings. The measured change removes **131 net production lines**; tests add 70 lines and package/lock metadata removes 4.

- Full suites for all 10 touched plugins: **8,352 passed**, 7 skipped, before the disjoint main refresh. Current-base focused selection: **1,298 passed**, 1 skipped; corrected Wiki/Plivo/Workboard selection: **82 passed**.
- Both new regressions fail on the original implementations and pass after repair. The Wiki fixture uses 1,000,000 short backtick runs to exceed the larger Vitest worker stack as well as normal Node's stack.
- `check-changed` completed its guards, formatting, package-lock checks, full typecheck and Knip scan (zero unused exports). It exposed a generic adapter typing problem and a lint shadow; the adapter rewrite was reduced to the existing typed helper and the import was renamed. The final affected lint check passes. Hosted CI remains the final aggregate gate.
- `pnpm plugin-sdk:surface:check` and `pnpm plugin-sdk:check-exports` passed. Both `check-madge-import-cycles.ts` and `check-import-cycles.ts` report **0**.
- Verification of the substantive commit before the advisory-guard rollback on Blacksmith Testbox `tbx_01m3twh0j7d0pfe3rp76nz3hhj`: isolated checkout at `ece0bfefb3`; frozen install; affected stdin/QA tests; focused lint; **1,153 plugin contract tests passed**; both cycle checks 0. Earlier full-suite run: https://github.com/openclaw/openclaw/actions/runs/36806258590

Single-worker test runner wall times: Wiki ingest 1.89s, Plivo webhook verification 2.03s, QA sentinel 1.29s, QA runtime parity 26.08s. The added cases reuse existing fixtures and introduce no additional process or Gateway boots. OnePassword and Vault resolver suites passed at the final commit in 9.35s and 3.16s respectively. Hosted CI timing will be recorded when its run completes.

### Hosted CI follow-up

CI run 36818688919 reported two SDK surface-budget assertions in `test/scripts/plugin-sdk-surface-report.test.ts`: expected exports 4588/callable 2694, current graph 4587/callable 2693. The exact same failures appear in unrelated current PR #162423 at head `b98cff8c52`, run https://github.com/openclaw/openclaw/actions/runs/36820001419/job/110233595392. This PR changes neither SDK entrypoints nor the report/budget/test owners; the head-only SDK report matched 4588/2694 before merge-context changes. This inherited failure remains coordinator-owned.

OpenGrep also rejected the attempted OpenShell normalization cleanup under its existing advisory rule. That optimization was removed completely: `extensions/openshell/src/config.ts` now matches the PR base byte-for-byte. The remaining OpenShell change only removes copied filesystem-helper arguments. No scanner suppression or baseline exception was added.

The replacement head restores only `extensions/openshell/src/config.ts` to its exact base bytes; that scoped rollback received a fresh clean P0–P2 review. Hosted CI is evaluating the replacement head.
2026-10-01 08:04:09 +00:00
..
assets improve(plugins): give bundled logos consistent white icon tiles (#155259) 2026-09-23 19:09:26 -07:00
src refactor(plugins): deslop long-tail extensions (#161096) 2026-09-29 03:46:06 -07:00
index.ts
openclaw.plugin.json feat(plugins): assign one purpose category to every bundled plugin (#142760) 2026-09-10 20:44:20 -07:00
package.json chore(release): close out 2026.9.7 on main (#161587) 2026-09-29 22:39:14 -07:00
README.md feat: show declared plugin capabilities and setup guides (#157956) 2026-09-25 16:43:53 -07:00
vault-secret-id.d.ts
vault-secret-id.js
vault-secret-ref-resolver.js refactor(plugins): deslop feature runtime helpers (#162425) 2026-10-01 08:04:09 +00:00

Vault

Resolve OpenClaw credentials from HashiCorp Vault using SecretRefs. Configuration stores references to Vault fields; resolved secrets stay in the active runtime snapshot instead of being written back into OpenClaw configuration.

Get started

Enable the plugin with openclaw plugins enable vault. Give the Gateway a reachable VAULT_ADDR and scoped Vault authentication, then check openclaw vault status.

Use openclaw vault setup --help to select credential targets and generate a SecretRef plan. Preview the saved plan before applying it:

openclaw secrets apply --from ./vault-secrets-plan.json --dry-run --allow-exec

Follow the guide to apply the reviewed plan and reload secrets.

The resolver supports Vault KV secrets and needs read permission for the selected paths. Enabling the plugin does not provision a Vault server.

See the Vault guide for authentication methods, plan commands, and deployment examples.