Skip to content

Commit 3cc5d4e

Browse files
Antonio Noelclaude
authored andcommitted
fix: address all P1/P2 review findings from Greptile + Codex
- F5: read gateway token from env var OPENCLAW_GATEWAY_TOKEN too (not just file) - F6: treat empty sig file as suspicious (attacker truncation bypass) - F7: sync loadConfig now returns {} on HMAC rejection (degraded safe mode) - F8: add writeConfigHmacSigSync for internal createConfigIO write paths - Remove redundant async HMAC write from exported wrapper (internal path handles it) Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
1 parent 211bdb7 commit 3cc5d4e

11,313 files changed

Lines changed: 68 additions & 29 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

._.codex

4 KB
Binary file not shown.

._.dockerignore

4 KB
Binary file not shown.

._.env.example

4 KB
Binary file not shown.

._.gitignore

4 KB
Binary file not shown.

._.markdownlint-cli2.jsonc

4 KB
Binary file not shown.

._.npmignore

4 KB
Binary file not shown.

._.oxfmtrc.jsonc

4 KB
Binary file not shown.

._.oxlintrc.json

4 KB
Binary file not shown.

._.pre-commit-config.yaml

4 KB
Binary file not shown.

._AGENTS.md

4 KB
Binary file not shown.

0 commit comments

Comments
 (0)