Merge branch 'main' into self_upgrade

This commit is contained in:
sky5454 2026-03-31 10:25:11 +08:00
commit 20d70b786f
3 changed files with 19 additions and 3 deletions

View file

@ -24,7 +24,7 @@ services:
picoclaw-gateway:
image: docker.io/sipeed/picoclaw:latest
container_name: picoclaw-gateway
restart: on-failure
restart: unless-stopped
profiles:
- gateway
# Uncomment to access host network; leave commented unless needed.
@ -40,7 +40,7 @@ services:
picoclaw-launcher:
image: docker.io/sipeed/picoclaw:launcher
container_name: picoclaw-launcher
restart: on-failure
restart: unless-stopped
profiles:
- launcher
environment:

View file

@ -112,6 +112,18 @@ func NewBaseChannel(
for _, opt := range opts {
opt(bc)
}
// Security Audit: Check for open-by-default (unsecured) channels.
// PicoClaw aims to be secure-by-default. If allow_from is empty, the bot
// currently defaults to accepting messages from ANYONE. To explicitly
// acknowledge and permit this (e.g. for a public bot), use ["*"].
if len(bc.allowList) == 0 {
logger.WarnCF("channels", "SECURITY: Channel allows EVERYONE (allow_from is empty)", map[string]any{
"channel": bc.name,
"hint": "Set allow_from to your ID, or use '*' to explicitly acknowledge open access.",
})
}
return bc
}
@ -187,6 +199,9 @@ func (c *BaseChannel) IsAllowed(senderID string) bool {
}
for _, allowed := range c.allowList {
if allowed == "*" {
return true
}
// Strip leading "@" from allowed value for username matching
trimmed := strings.TrimPrefix(allowed, "@")
allowedID := trimmed
@ -221,7 +236,7 @@ func (c *BaseChannel) IsAllowedSender(sender bus.SenderInfo) bool {
}
for _, allowed := range c.allowList {
if identity.MatchAllowed(sender, allowed) {
if allowed == "*" || identity.MatchAllowed(sender, allowed) {
return true
}
}

View file

@ -42,6 +42,7 @@ func NewGitHubCopilotProvider(uri string, connectMode string, model string) (*Gi
session, err := client.CreateSession(context.Background(), &copilot.SessionConfig{
Model: model,
OnPermissionRequest: copilot.PermissionHandler.ApproveAll,
Hooks: &copilot.SessionHooks{},
})
if err != nil {