openclaw/docs/cli
Mason Huang 004835f4c7
fix(plugins): block untrusted workspace setup-only channel loads (#86953)
Summary:
- This PR blocks disabled workspace-origin channel plugins from setup-only scoped imports, rejects their channel registrations at registry assembly, documents the trust rule, and adds regression coverage.
- PR surface: Source +46, Tests +610, Docs +13. Total +669 across 22 files.
- Reproducibility: yes. source inspection gives a high-confidence reproduction path: current main's setup-only ... ce channel plugin can be imported before this PR. I did not run the repro locally in this read-only review.

Automerge notes:
- PR branch already contained follow-up commit before automerge: test(plugins): cover workspace channel registry guard
- PR branch already contained follow-up commit before automerge: fix(plugins): isolate setup channel registration errors
- PR branch already contained follow-up commit before automerge: fix(channels): mark raw catalog listing internal
- PR branch already contained follow-up commit before automerge: test(channels): cover trusted catalog filtering
- PR branch already contained follow-up commit before automerge: test(channels): mock raw catalog helper
- PR branch already contained follow-up commit before automerge: docs(changelog): credit setup channel hardening

Validation:
- ClawSweeper review passed for head 11438bc1a0.
- Required merge gates passed before the squash merge.

Prepared head SHA: 11438bc1a0
Review: https://github.com/openclaw/openclaw/pull/86953#issuecomment-4545730044

Co-authored-by: masonxhuang <masonxhuang@tencent.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Mason Huang <masonxhuang@tencent.com>
Co-authored-by: Sebastien Tardif <sebtardif@ncf.ca>
Co-authored-by: clawsweeper <274271284+clawsweeper[bot]@users.noreply.github.com>
Co-authored-by: clawsweeper[bot] <274271284+clawsweeper[bot]@users.noreply.github.com>
Approved-by: hxy91819
Co-authored-by: hxy91819 <8814856+hxy91819@users.noreply.github.com>
2026-06-01 09:25:56 +00:00
..
acp.md
agent.md
agents.md
approvals.md
backup.md docs: absorb documentation PR sweep 2026-05-23 10:23:34 +01:00
browser.md fix(browser): document stable tab references (#88393) 2026-05-31 12:09:50 +00:00
channels.md
clawbot.md
commitments.md
completion.md
config.md
configure.md
crestodian.md feat: add Claude Opus 4.8 support (#87890) 2026-05-29 06:10:42 +01:00
cron.md Refactor cron SQLite runtime paths (#88582) 2026-05-31 12:14:48 +01:00
daemon.md
dashboard.md
devices.md fix(gateway): require admin for device role approvals (#87146) 2026-05-27 08:08:51 -07:00
directory.md
dns.md
docs.md fix(docs): use Cloudflare docs search API 2026-05-27 00:58:09 +01:00
doctor.md fix(doctor): keep post-upgrade JSON stable 2026-05-31 22:12:38 +01:00
flows.md
gateway.md docs: absorb docs sweep 2026-05-22 21:52:01 +01:00
health.md
hooks.md
index.md feat(workboard): add worker dispatch CLI 2026-05-31 10:31:56 +01:00
infer.md refactor: unify OpenAI provider identity 2026-05-30 11:48:41 +02:00
logs.md fix(cli): default logs to local timestamps (#85387) 2026-05-26 21:14:47 +01:00
mcp.md docs: expand MCP operator guide 2026-05-31 10:12:44 +01:00
memory.md fix(memory): compact short-term promotion entries 2026-05-29 00:05:54 +01:00
message.md
migrate.md docs(codex): clarify first-party plugin marketplaces 2026-05-31 13:22:00 +01:00
models.md refactor: unify OpenAI provider identity (#88451) 2026-05-31 00:29:44 +01:00
node.md
nodes.md
onboard.md feat: start onboarding for fresh CLI installs (#85519) 2026-05-22 22:00:21 +00:00
pairing.md
path.md fix(oc-path): support deep config edits (#86060) 2026-05-24 18:10:02 -07:00
plugins.md fix(plugins): block untrusted workspace setup-only channel loads (#86953) 2026-06-01 09:25:56 +00:00
policy.md Policy: add policy file comparison command (#86768) 2026-05-28 23:10:27 -07:00
proxy.md
qr.md fix(gateway): gate talk secret bootstrap handoff (#85690) 2026-05-25 11:34:12 +03:00
reset.md
sandbox.md
secrets.md
security.md fix: Hook ingress token unlocks password-mode gateway auth (#86453) 2026-05-25 13:39:56 +00:00
sessions.md feat(cli): add sessions tail progress view 2026-05-30 21:29:39 +01:00
setup.md fix: harden CLI and plugin edge cases (#88896) 2026-06-01 00:30:12 -04:00
skills.md docs: add Skill Workshop guide 2026-05-31 09:05:03 +01:00
status.md refactor: internalize OpenClaw agent runtime (#85341) 2026-05-27 19:24:04 +01:00
system.md
tasks.md
transcripts.md refactor: move transcripts into core 2026-05-26 14:51:11 +01:00
tui.md feat: add core session goals (#87469) 2026-05-29 22:36:29 +02:00
uninstall.md fix: preserve workspaces during state-only uninstall 2026-05-31 19:54:34 +01:00
update.md fix: honor OPENCLAW_HOME defaults (#85802) 2026-05-23 20:39:59 -07:00
voicecall.md
webhooks.md
wiki.md
workboard.md fix(workboard): wire task-backed board runs 2026-06-01 01:41:21 +01:00