## What Problem This Solves Feature plugins repeat runtime adapters and utility logic already owned by shared helpers or neighboring modules. ## User Impact Tool names, descriptions, schemas, manifests, configuration keys, persisted formats, and UI rendering stay unchanged. No migration or operator action is required. ## Why This Change Was Made - Workboard routes its three remaining read adapters through the existing typed operation binder, preserving argument capture, settlement, and close behavior. - OpenShell carries resolved targets directly through filesystem helpers; its existing advisory-specific path validation stays intact. - Copilot uses the existing timeout owner during compaction cancellation and drops a redundant async wrapper. - Voice Call uses the existing Node-compatible WebSocket SDK transport; its private transport shim and unused direct dependency are removed. - FaceTime reuses existing boolean, string-list, finite-number, and deferred-promise helpers. - QA transcript consumers share traversal while keeping their different accepted block types explicit. Mantis and activity readers reuse canonical coercion helpers. - OnePassword and Vault use Node's stdin consumer while retaining UTF-8 string decoding and existing SecretRef response behavior. - Memory Core imports its FTS query owner directly and lets the existing timeout resolver own finite-number conversion and clamping. Workboard reuses its local numeric normalization for attachment size. ### Fixes found along the way Memory Wiki ingestion could exceed the JavaScript argument limit when a file contained many short backtick runs. Fence construction now scans those runs without expanding them into function arguments; the regression exercises ingestion and verifies the persisted source text. Plivo webhook verification could throw for query/form names such as `__proto__`, `constructor`, and `toString`. A native Map now groups parameters before the existing canonical sorting/signing step. Valid signed cases and invalid signatures are covered through the public verifier. ## Evidence Independent Codex review completed with no actionable P0–P2 findings. The measured change removes **131 net production lines**; tests add 70 lines and package/lock metadata removes 4. - Full suites for all 10 touched plugins: **8,352 passed**, 7 skipped, before the disjoint main refresh. Current-base focused selection: **1,298 passed**, 1 skipped; corrected Wiki/Plivo/Workboard selection: **82 passed**. - Both new regressions fail on the original implementations and pass after repair. The Wiki fixture uses 1,000,000 short backtick runs to exceed the larger Vitest worker stack as well as normal Node's stack. - `check-changed` completed its guards, formatting, package-lock checks, full typecheck and Knip scan (zero unused exports). It exposed a generic adapter typing problem and a lint shadow; the adapter rewrite was reduced to the existing typed helper and the import was renamed. The final affected lint check passes. Hosted CI remains the final aggregate gate. - `pnpm plugin-sdk:surface:check` and `pnpm plugin-sdk:check-exports` passed. Both `check-madge-import-cycles.ts` and `check-import-cycles.ts` report **0**. - Verification of the substantive commit before the advisory-guard rollback on Blacksmith Testbox `tbx_01m3twh0j7d0pfe3rp76nz3hhj`: isolated checkout at ` |
||
|---|---|---|
| .. | ||
| assets | ||
| src | ||
| index.ts | ||
| openclaw.plugin.json | ||
| package.json | ||
| README.md | ||
| vault-secret-id.d.ts | ||
| vault-secret-id.js | ||
| vault-secret-ref-resolver.js | ||
Vault
Resolve OpenClaw credentials from HashiCorp Vault using SecretRefs. Configuration stores references to Vault fields; resolved secrets stay in the active runtime snapshot instead of being written back into OpenClaw configuration.
Get started
Enable the plugin with openclaw plugins enable vault. Give the Gateway a
reachable VAULT_ADDR and scoped Vault authentication, then check
openclaw vault status.
Use openclaw vault setup --help to select credential targets and generate a
SecretRef plan. Preview the saved plan before applying it:
openclaw secrets apply --from ./vault-secrets-plan.json --dry-run --allow-exec
Follow the guide to apply the reviewed plan and reload secrets.
The resolver supports Vault KV secrets and needs read permission for the selected paths. Enabling the plugin does not provision a Vault server.
See the Vault guide for authentication methods, plan commands, and deployment examples.