diff --git a/.editorconfig b/.editorconfig new file mode 100644 index 000000000..cdc283d0a --- /dev/null +++ b/.editorconfig @@ -0,0 +1,35 @@ +# EditorConfig is awesome: https://EditorConfig.org + +# top-most EditorConfig file +root = true + +# Default settings for all files +[*] +charset = utf-8 +end_of_line = lf +insert_final_newline = true +trim_trailing_whitespace = true + +# Go files +[*.go] +indent_style = tab +indent_size = 4 + +# JSON, YAML, and Markdown files +[*.{json,yml,yaml,md}] +indent_style = space +indent_size = 2 + +# JavaScript/TypeScript files +[*.{js,ts,tsx}] +indent_style = space +indent_size = 2 + +# Shell scripts +[*.sh] +indent_style = space +indent_size = 2 + +# Makefile +[Makefile] +indent_style = tab diff --git a/.gitignore b/.gitignore index 135867842..4b35ebe77 100644 --- a/.gitignore +++ b/.gitignore @@ -69,3 +69,24 @@ web/backend/dist/* docker/data .omc/ + +# Temporary files +*.tmp +*.temp +*.log + +# Local development +local/ +local.* + +# Node modules for frontend +web/frontend/node_modules/ +web/frontend/dist/ +web/frontend/.cache/ + +# Python virtual environments +venv/ +env/ +ENV/ +__pycache__/ +*.py[cod] diff --git a/README.md b/README.md index 5aac4bbc9..21740ace1 100644 --- a/README.md +++ b/README.md @@ -5,7 +5,7 @@

$10 Hardware · 10MB RAM · ms Boot · Let's Go, PicoClaw!

- Go + Go Hardware License
diff --git a/docker/docker-compose.full.yml b/docker/docker-compose.full.yml index 6f34448c4..9c1d58d2b 100644 --- a/docker/docker-compose.full.yml +++ b/docker/docker-compose.full.yml @@ -10,6 +10,10 @@ services: container_name: picoclaw-agent-full profiles: - agent + environment: + # PicoClaw runs as root in container by default + # If running as non-root user, update these paths to match the user's home directory + - HOME=/root volumes: - ../config/config.json:/root/.picoclaw/config.json:ro - picoclaw-workspace:/root/.picoclaw/workspace @@ -30,6 +34,10 @@ services: restart: unless-stopped profiles: - gateway + environment: + # PicoClaw runs as root in container by default + # If running as non-root user, update these paths to match the user's home directory + - HOME=/root volumes: # Configuration file - ../config/config.json:/root/.picoclaw/config.json:ro diff --git a/docker/docker-compose.yml b/docker/docker-compose.yml index 7c940621f..b5643d79d 100644 --- a/docker/docker-compose.yml +++ b/docker/docker-compose.yml @@ -12,7 +12,7 @@ services: #extra_hosts: # - "host.docker.internal:host-gateway" volumes: - - ./data:/root/.picoclaw + - ./data:/home/picoclaw/.picoclaw entrypoint: ["picoclaw", "agent"] stdin_open: true tty: true @@ -31,7 +31,7 @@ services: #extra_hosts: # - "host.docker.internal:host-gateway" volumes: - - ./data:/root/.picoclaw + - ./data:/home/picoclaw/.picoclaw # ───────────────────────────────────────────── # PicoClaw Launcher (Web Console + Gateway) @@ -52,4 +52,4 @@ services: - "18800:18800" - "18790:18790" volumes: - - ./data:/root/.picoclaw + - ./data:/home/picoclaw/.picoclaw diff --git a/pkg/channels/base.go b/pkg/channels/base.go index 3585fb075..97c14332c 100644 --- a/pkg/channels/base.go +++ b/pkg/channels/base.go @@ -5,6 +5,7 @@ import ( "crypto/rand" "encoding/binary" "encoding/hex" + "fmt" "regexp" "strconv" "strings" @@ -128,9 +129,16 @@ func NewBaseChannel( // currently defaults to accepting messages from ANYONE. To explicitly // acknowledge and permit this (e.g. for a public bot), use ["*"]. if len(bc.allowList) == 0 { - logger.WarnCF("channels", "SECURITY: Channel allows EVERYONE (allow_from is empty)", map[string]any{ - "channel": bc.name, - "hint": "Set allow_from to your ID, or use '*' to explicitly acknowledge open access.", + logger.WarnCF("channels", fmt.Sprintf("SECURITY: Channel '%s' allows EVERYONE (allow_from is empty). This is a potential security risk.", bc.name), map[string]any{ + "channel": bc.name, + "channelID": bc.name, + "hint": "Set allow_from to your ID, or use ['*'] to explicitly acknowledge open access. See: https://github.com/sipeed/picoclaw/blob/main/docs/configuration.md", + }) + } else { + logger.InfoCF("channels", fmt.Sprintf("Channel '%s' allow_from configured (%d entries)", bc.name, len(bc.allowList)), map[string]any{ + "channel": bc.name, + "allow_list": bc.allowList, + "count": len(bc.allowList), }) }