openclaw/docs
Yuval Dinodia 0a588fa795
fix(acp): /acp sessions exposes every gateway session to non-owner senders (#110745)
* fix(acp): scope /acp sessions listing for non-owner senders

/acp sessions listed every ACP session on the gateway for any sender
allowlisted via commands.allowFrom, exposing other senders' session
labels, agent ids, runtime state, and thread bindings. The handler now
returns only the current bound or requester session for non-owner
senders, while owner identity and operator.admin clients keep the full
gateway-wide listing, matching the documented contract.

Fixes #103055

* test(acp): cover empty and missing-session cases for /acp sessions scoping

* fix(acp): avoid non-owner session scans

* docs(acp): remove duplicated session scope text

* test(acp): cover internal session visibility

* fix(acp): require current ACP metadata

* test(acp): reject sessions target tokens

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-18 18:38:48 -06:00
..
.generated feat(config): add compaction.thinkingLevel to override thinking level during compaction (#98074) 2026-07-18 17:18:28 -07:00
.i18n docs: explain pull request automation workflow (#101748) 2026-07-16 20:29:15 -07:00
announcements docs: rewrite published docs grounded in current source (#100142) 2026-07-05 00:32:47 -04:00
assets docs(readme): trim banner whitespace for a more compact hero 2026-07-09 14:53:52 -07:00
automation feat(cron): add per-job dynamic cadence (#110978) 2026-07-18 23:43:39 +01:00
channels docs: document channel ingress guarantees (#111069) 2026-07-18 17:26:41 -07:00
clawhub docs: rewrite published docs grounded in current source (#100142) 2026-07-05 00:32:47 -04:00
cli fix(channels): recover dead-lettered inbound events (#111029) 2026-07-19 00:44:23 +01:00
concepts docs: align interactive client behavior (#111047) 2026-07-18 17:00:14 -07:00
debug docs: rewrite published docs grounded in current source (#100142) 2026-07-05 00:32:47 -04:00
diagnostics refactor: prune redundant OpenClaw env controls (#109211) 2026-07-16 10:06:39 -07:00
gateway docs: document channel ingress guarantees (#111069) 2026-07-18 17:26:41 -07:00
help feat(models): make per-agent allowlists explicit (#110888) 2026-07-18 21:42:05 +01:00
images chore: remove unused tracked assets 2026-05-26 02:21:58 +01:00
install feat(onboarding): offer detected Claude Code/Codex/Hermes memory imports across CLI, macOS, and Linux onboarding (#108977) 2026-07-16 10:10:01 -07:00
maturity fix(docs): preserve canonical maturity product labels 2026-07-17 09:44:52 -04:00
nodes docs: align interactive client behavior (#111047) 2026-07-18 17:00:14 -07:00
plan refactor: flip sessions and transcripts to sqlite storage (#98236) 2026-07-11 14:50:37 -07:00
platforms feat(macos): Quick Chat power features — voice dictation, paste-to-app, model/reasoning control (#110994) 2026-07-18 17:21:03 -07:00
plugins feat: add live-validated Zoom meeting guest plugin (#111048) 2026-07-18 17:17:26 -07:00
providers docs: align interactive client behavior (#111047) 2026-07-18 17:00:14 -07:00
refactor refactor(macos): move PortGuardian state to SQLite (#110527) 2026-07-18 18:15:17 +01:00
reference feat(config): add compaction.thinkingLevel to override thinking level during compaction (#98074) 2026-07-18 17:18:28 -07:00
releases docs: publish release notes for v2026.7.1 (#107040) 2026-07-13 22:54:04 -06:00
security fix(onboarding): leave session.dmScope unset so the personal-agent default "main" applies (#110225) 2026-07-18 03:54:45 +01:00
snippets/plugin-publish docs: restore source-backed contract details (#100182) 2026-07-05 01:26:25 -04:00
specs improve: stream native sessions as hosts finish (#110211) 2026-07-17 23:59:57 +01:00
start feat(macos): render system chat option cards (#110584) 2026-07-18 13:23:59 +01:00
tools fix(acp): /acp sessions exposes every gateway session to non-owner senders (#110745) 2026-07-18 18:38:48 -06:00
web feat(ui): add realtime Talk camera controls (#111042) 2026-07-18 17:03:32 -07:00
agent-runtime-architecture.md fix(openai): align auth availability with effective routes (#104685) 2026-07-11 15:26:48 -07:00
AGENTS.md docs: rewrite published docs grounded in current source (#100142) 2026-07-05 00:32:47 -04:00
auth-credential-semantics.md docs: rewrite published docs grounded in current source (#100142) 2026-07-05 00:32:47 -04:00
brave-search.md
ci.md perf(ci): parallelize gateway watch artifact check (#110609) 2026-07-18 11:01:08 +01:00
CLAUDE.md
date-time.md docs: rewrite published docs grounded in current source (#100142) 2026-07-05 00:32:47 -04:00
docs.json feat: add live-validated Zoom meeting guest plugin (#111048) 2026-07-18 17:17:26 -07:00
docs_map.md docs: document channel ingress guarantees (#111069) 2026-07-18 17:26:41 -07:00
index.md fix(sqlite): reject runtimes vulnerable to WAL corruption (#106065) 2026-07-13 13:59:00 +08:00
logging.md docs: rewrite published docs grounded in current source (#100142) 2026-07-05 00:32:47 -04:00
nav-tabs-underline.js docs: document repo support scripts 2026-06-04 08:01:15 -04:00
network.md docs: rewrite published docs grounded in current source (#100142) 2026-07-05 00:32:47 -04:00
openclaw-agent-runtime.md refactor: flip sessions and transcripts to sqlite storage (#98236) 2026-07-11 14:50:37 -07:00
perplexity.md
prose.md docs: rewrite published docs grounded in current source (#100142) 2026-07-05 00:32:47 -04:00
style.css fix(docs): expose generated taxonomy links 2026-07-15 07:28:58 -04:00
tts.md
vps.md docs: rewrite published docs grounded in current source (#100142) 2026-07-05 00:32:47 -04:00
whatsapp-openclaw.jpg