Some checks failed
ClawSweeper Dispatch / dispatch (push) Has been cancelled
CodeQL / Security High (actions) (push) Has been cancelled
CodeQL / Security High (channel-runtime-boundary) (push) Has been cancelled
CodeQL / Security High (core-auth-secrets) (push) Has been cancelled
CodeQL / Security High (mcp-process-tool-boundary) (push) Has been cancelled
CodeQL / Security High (network-ssrf-boundary) (push) Has been cancelled
CodeQL / Security High (plugin-trust-boundary) (push) Has been cancelled
CodeQL / Security High (process-exec-boundary) (push) Has been cancelled
Docs Sync Publish Repo / sync-publish-repo (push) Has been cancelled
Docs / docs (push) Has been cancelled
OpenClaw Stable Main Closeout / Resolve stable release closeout inputs (push) Has been cancelled
OpenClaw Stable Main Closeout / Verify stable main closeout (push) Has been cancelled
Workflow Sanity / no-tabs (push) Has been cancelled
Workflow Sanity / actionlint (push) Has been cancelled
Workflow Sanity / generated-doc-baselines (push) Has been cancelled
CI / runner-admission (push) Has been cancelled
CI / preflight (push) Has been cancelled
CI / security-fast (push) Has been cancelled
CI / pnpm-store-warmup (push) Has been cancelled
CI / build-artifacts (push) Has been cancelled
CI / native-i18n (push) Has been cancelled
CI / ${{ matrix.check_name }} (push) Has been cancelled
CI / ${{ matrix.checkName }} (push) Has been cancelled
CI / checks-node-compat-node22 (push) Has been cancelled
CI / check-bundled-channel-config-metadata (push) Has been cancelled
CI / check-dependencies (push) Has been cancelled
CI / check-guards (push) Has been cancelled
CI / check-lint (push) Has been cancelled
CI / check-prod-types (push) Has been cancelled
CI / check-shrinkwrap (push) Has been cancelled
CI / check-test-types (push) Has been cancelled
CI / check-additional-boundaries-a (push) Has been cancelled
CI / check-additional-boundaries-bcd (push) Has been cancelled
CI / check-additional-extension-bundled (push) Has been cancelled
CI / check-additional-extension-channels (push) Has been cancelled
CI / check-additional-extension-package-boundary (push) Has been cancelled
CI / check-additional-runtime-topology-architecture (push) Has been cancelled
CI / check-session-accessor-boundary (push) Has been cancelled
CI / check-session-transcript-reader-boundary (push) Has been cancelled
CI / check-docs (push) Has been cancelled
CI / skills-python (push) Has been cancelled
CI / macos-swift (push) Has been cancelled
CI / ios-build (push) Has been cancelled
CI / ci-timings-summary (push) Has been cancelled
Native App Locale Refresh / Refresh native fa (push) Has been cancelled
Native App Locale Refresh / Refresh native fr (push) Has been cancelled
Native App Locale Refresh / Refresh native hi (push) Has been cancelled
Native App Locale Refresh / Refresh native id (push) Has been cancelled
Native App Locale Refresh / Refresh native it (push) Has been cancelled
Native App Locale Refresh / Refresh native ja-JP (push) Has been cancelled
Control UI Locale Refresh / plan (push) Has been cancelled
Control UI Locale Refresh / Refresh ${{ matrix.locale }} (push) Has been cancelled
Control UI Locale Refresh / Commit control UI locale refresh (push) Has been cancelled
Live Media Runner Image / Build live media runner image (push) Has been cancelled
Native App Locale Refresh / Refresh native ar (push) Has been cancelled
Native App Locale Refresh / Refresh native de (push) Has been cancelled
Native App Locale Refresh / Refresh native es (push) Has been cancelled
Native App Locale Refresh / Refresh native ko (push) Has been cancelled
Native App Locale Refresh / Refresh native nl (push) Has been cancelled
Native App Locale Refresh / Refresh native pl (push) Has been cancelled
Native App Locale Refresh / Refresh native pt-BR (push) Has been cancelled
Native App Locale Refresh / Refresh native ru (push) Has been cancelled
Native App Locale Refresh / Refresh native sv (push) Has been cancelled
Native App Locale Refresh / Refresh native th (push) Has been cancelled
Native App Locale Refresh / Refresh native tr (push) Has been cancelled
Native App Locale Refresh / Refresh native uk (push) Has been cancelled
Native App Locale Refresh / Refresh native vi (push) Has been cancelled
Native App Locale Refresh / Refresh native zh-CN (push) Has been cancelled
Native App Locale Refresh / Refresh native zh-TW (push) Has been cancelled
Native App Locale Refresh / Commit native locale refresh (push) Has been cancelled
Plugin Init Scaffold Validation / Validate provider scaffold (push) Has been cancelled
Plugin NPM Release / preview_plugins_npm (push) Has been cancelled
Plugin NPM Release / Validate release publish approval (push) Has been cancelled
Plugin NPM Release / preview_plugin_pack (push) Has been cancelled
Plugin NPM Release / publish_plugins_npm (push) Has been cancelled
Sandbox Common Smoke / sandbox-common-smoke (push) Has been cancelled
Website Installer Sync / static (push) Has been cancelled
Website Installer Sync / linux-docker (push) Has been cancelled
Website Installer Sync / macos-installer (push) Has been cancelled
Website Installer Sync / windows-installer (push) Has been cancelled
Website Installer Sync / sync-website (push) Has been cancelled
Adolf is a fork/vendored clone of github.com/openclaw/openclaw (v2026.6.11), free to diverge. Tree copied sans upstream .git; upstream remote added for future syncs. Node pinned to 24 (.nvmrc); engines already require >=22.19. Preserves docs/ARCHITECTURE.md. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LeqyaxJF2nbRXJtae2kNB2
304 lines
9.0 KiB
TypeScript
304 lines
9.0 KiB
TypeScript
// Slack tests cover exec approvals plugin behavior.
|
|
import type { OpenClawConfig } from "openclaw/plugin-sdk/config-contracts";
|
|
import { describe, expect, it } from "vitest";
|
|
import {
|
|
getSlackExecApprovalApprovers,
|
|
isSlackExecApprovalApprover,
|
|
isSlackExecApprovalAuthorizedSender,
|
|
isSlackExecApprovalClientEnabled,
|
|
isSlackExecApprovalTargetRecipient,
|
|
normalizeSlackApproverId,
|
|
resolveSlackExecApprovalTarget,
|
|
shouldHandleSlackExecApprovalRequest,
|
|
shouldSuppressLocalSlackExecApprovalPrompt,
|
|
} from "./exec-approvals.js";
|
|
|
|
function buildConfig(
|
|
execApprovals?: NonNullable<NonNullable<OpenClawConfig["channels"]>["slack"]>["execApprovals"],
|
|
channelOverrides?: Partial<NonNullable<NonNullable<OpenClawConfig["channels"]>["slack"]>>,
|
|
): OpenClawConfig {
|
|
return {
|
|
channels: {
|
|
slack: {
|
|
botToken: "xoxb-test",
|
|
appToken: "xapp-test",
|
|
...channelOverrides,
|
|
execApprovals,
|
|
},
|
|
},
|
|
} as OpenClawConfig;
|
|
}
|
|
|
|
describe("slack exec approvals", () => {
|
|
it("requires explicit enablement even when owner approvers resolve", () => {
|
|
expect(isSlackExecApprovalClientEnabled({ cfg: buildConfig() })).toBe(false);
|
|
expect(
|
|
isSlackExecApprovalClientEnabled({
|
|
cfg: buildConfig({ enabled: true }),
|
|
}),
|
|
).toBe(false);
|
|
expect(
|
|
isSlackExecApprovalClientEnabled({
|
|
cfg: buildConfig({ approvers: ["U123"] }),
|
|
}),
|
|
).toBe(false);
|
|
expect(
|
|
isSlackExecApprovalClientEnabled({
|
|
cfg: {
|
|
...buildConfig(),
|
|
commands: { ownerAllowFrom: ["slack:U123OWNER"] },
|
|
} as OpenClawConfig,
|
|
}),
|
|
).toBe(false);
|
|
expect(
|
|
isSlackExecApprovalClientEnabled({
|
|
cfg: buildConfig({ enabled: "auto", approvers: ["U123"] }),
|
|
}),
|
|
).toBe(true);
|
|
expect(
|
|
isSlackExecApprovalClientEnabled({
|
|
cfg: buildConfig({ enabled: false, approvers: ["U123"] }),
|
|
}),
|
|
).toBe(false);
|
|
});
|
|
|
|
it("prefers explicit approvers when configured", () => {
|
|
const cfg = buildConfig(
|
|
{ approvers: ["U456"] },
|
|
{ allowFrom: ["U123"], defaultTo: "user:U789" },
|
|
);
|
|
|
|
expect(getSlackExecApprovalApprovers({ cfg })).toEqual(["U456"]);
|
|
expect(isSlackExecApprovalApprover({ cfg, senderId: "U456" })).toBe(true);
|
|
expect(isSlackExecApprovalApprover({ cfg, senderId: "u456" })).toBe(true);
|
|
expect(isSlackExecApprovalApprover({ cfg, senderId: "U123" })).toBe(false);
|
|
});
|
|
|
|
it("canonicalizes configured exec approver ids before matching uppercase senders", () => {
|
|
const explicitCfg = buildConfig({ approvers: ["u456"] });
|
|
expect(getSlackExecApprovalApprovers({ cfg: explicitCfg })).toEqual(["U456"]);
|
|
expect(isSlackExecApprovalApprover({ cfg: explicitCfg, senderId: "U456" })).toBe(true);
|
|
|
|
const ownerFallbackCfg = {
|
|
...buildConfig({ enabled: true }),
|
|
commands: { ownerAllowFrom: ["slack:u123owner"] },
|
|
} as OpenClawConfig;
|
|
expect(getSlackExecApprovalApprovers({ cfg: ownerFallbackCfg })).toEqual(["U123OWNER"]);
|
|
expect(isSlackExecApprovalApprover({ cfg: ownerFallbackCfg, senderId: "U123OWNER" })).toBe(
|
|
true,
|
|
);
|
|
});
|
|
|
|
it("does not infer approvers from allowFrom or DM default routes", () => {
|
|
const cfg = buildConfig(
|
|
{ enabled: true },
|
|
{
|
|
allowFrom: ["slack:U123"],
|
|
dm: { allowFrom: ["<@U456>"] },
|
|
defaultTo: "user:U789",
|
|
},
|
|
);
|
|
|
|
expect(getSlackExecApprovalApprovers({ cfg })).toStrictEqual([]);
|
|
expect(isSlackExecApprovalApprover({ cfg, senderId: "U789" })).toBe(false);
|
|
});
|
|
|
|
it("falls back to commands.ownerAllowFrom for exec approvers", () => {
|
|
const cfg = {
|
|
...buildConfig({ enabled: true }),
|
|
commands: { ownerAllowFrom: ["slack:U123", "user:U456", "<@U789>"] },
|
|
} as OpenClawConfig;
|
|
|
|
expect(getSlackExecApprovalApprovers({ cfg })).toEqual(["U123", "U456", "U789"]);
|
|
expect(isSlackExecApprovalApprover({ cfg, senderId: "U456" })).toBe(true);
|
|
});
|
|
|
|
it("defaults target to dm", () => {
|
|
expect(
|
|
resolveSlackExecApprovalTarget({ cfg: buildConfig({ enabled: true, approvers: ["U1"] }) }),
|
|
).toBe("dm");
|
|
});
|
|
|
|
it("matches slack target recipients from generic approval forwarding targets", () => {
|
|
const cfg = {
|
|
channels: {
|
|
slack: {
|
|
botToken: "xoxb-test",
|
|
appToken: "xapp-test",
|
|
},
|
|
},
|
|
approvals: {
|
|
exec: {
|
|
enabled: true,
|
|
mode: "targets",
|
|
targets: [
|
|
{ channel: "slack", to: "user:u123target" },
|
|
{ channel: "slack", to: "channel:C123" },
|
|
],
|
|
},
|
|
},
|
|
} as OpenClawConfig;
|
|
|
|
expect(isSlackExecApprovalTargetRecipient({ cfg, senderId: "U123TARGET" })).toBe(true);
|
|
expect(isSlackExecApprovalTargetRecipient({ cfg, senderId: "u123target" })).toBe(true);
|
|
expect(isSlackExecApprovalTargetRecipient({ cfg, senderId: "U999OTHER" })).toBe(false);
|
|
expect(isSlackExecApprovalAuthorizedSender({ cfg, senderId: "U123TARGET" })).toBe(true);
|
|
expect(isSlackExecApprovalAuthorizedSender({ cfg, senderId: "u123target" })).toBe(true);
|
|
});
|
|
|
|
it("keeps the local Slack approval prompt path active", () => {
|
|
const payload = {
|
|
channelData: {
|
|
execApproval: {
|
|
approvalId: "req-1",
|
|
approvalSlug: "req-1",
|
|
},
|
|
},
|
|
};
|
|
|
|
expect(
|
|
shouldSuppressLocalSlackExecApprovalPrompt({
|
|
cfg: buildConfig({ enabled: true, approvers: ["U123"] }),
|
|
payload,
|
|
}),
|
|
).toBe(true);
|
|
|
|
expect(
|
|
shouldSuppressLocalSlackExecApprovalPrompt({
|
|
cfg: buildConfig(),
|
|
payload,
|
|
}),
|
|
).toBe(false);
|
|
});
|
|
|
|
it("normalizes wrapped sender ids", () => {
|
|
expect(normalizeSlackApproverId("user:U123OWNER")).toBe("U123OWNER");
|
|
expect(normalizeSlackApproverId("user:u123owner")).toBe("U123OWNER");
|
|
expect(normalizeSlackApproverId("slack:u123owner")).toBe("U123OWNER");
|
|
expect(normalizeSlackApproverId("<@U123OWNER>")).toBe("U123OWNER");
|
|
expect(normalizeSlackApproverId("<@u123owner>")).toBe("U123OWNER");
|
|
expect(normalizeSlackApproverId("u123owner")).toBe("U123OWNER");
|
|
expect(normalizeSlackApproverId("C123CHANNEL")).toBeUndefined();
|
|
expect(normalizeSlackApproverId("slack:C123CHANNEL")).toBeUndefined();
|
|
expect(normalizeSlackApproverId("user:C123CHANNEL")).toBeUndefined();
|
|
expect(normalizeSlackApproverId("<@C123CHANNEL>")).toBeUndefined();
|
|
});
|
|
|
|
it("applies agent and session filters to request handling", () => {
|
|
const cfg = buildConfig({
|
|
enabled: true,
|
|
approvers: ["U123"],
|
|
agentFilter: ["ops-agent"],
|
|
sessionFilter: ["slack:direct:", "tail$"],
|
|
});
|
|
|
|
expect(
|
|
shouldHandleSlackExecApprovalRequest({
|
|
cfg,
|
|
request: {
|
|
id: "req-1",
|
|
request: {
|
|
command: "echo hi",
|
|
agentId: "ops-agent",
|
|
sessionKey: "agent:ops-agent:slack:direct:U123:tail",
|
|
},
|
|
createdAtMs: 0,
|
|
expiresAtMs: 1000,
|
|
},
|
|
}),
|
|
).toBe(true);
|
|
|
|
expect(
|
|
shouldHandleSlackExecApprovalRequest({
|
|
cfg,
|
|
request: {
|
|
id: "req-2",
|
|
request: {
|
|
command: "echo hi",
|
|
agentId: "other-agent",
|
|
sessionKey: "agent:other-agent:slack:direct:U123:tail",
|
|
},
|
|
createdAtMs: 0,
|
|
expiresAtMs: 1000,
|
|
},
|
|
}),
|
|
).toBe(false);
|
|
|
|
expect(
|
|
shouldHandleSlackExecApprovalRequest({
|
|
cfg,
|
|
request: {
|
|
id: "req-3",
|
|
request: {
|
|
command: "echo hi",
|
|
agentId: "ops-agent",
|
|
sessionKey: "agent:ops-agent:discord:channel:123",
|
|
},
|
|
createdAtMs: 0,
|
|
expiresAtMs: 1000,
|
|
},
|
|
}),
|
|
).toBe(false);
|
|
});
|
|
|
|
it("rejects requests bound to another channel or Slack account", () => {
|
|
const cfg = buildConfig({
|
|
enabled: true,
|
|
approvers: ["U123"],
|
|
});
|
|
|
|
expect(
|
|
shouldHandleSlackExecApprovalRequest({
|
|
cfg,
|
|
accountId: "work",
|
|
request: {
|
|
id: "req-1",
|
|
request: {
|
|
command: "echo hi",
|
|
turnSourceChannel: "discord",
|
|
turnSourceAccountId: "work",
|
|
},
|
|
createdAtMs: 0,
|
|
expiresAtMs: 1000,
|
|
},
|
|
}),
|
|
).toBe(false);
|
|
|
|
expect(
|
|
shouldHandleSlackExecApprovalRequest({
|
|
cfg,
|
|
accountId: "work",
|
|
request: {
|
|
id: "req-2",
|
|
request: {
|
|
command: "echo hi",
|
|
turnSourceChannel: "slack",
|
|
turnSourceAccountId: "other",
|
|
sessionKey: "agent:ops-agent:missing",
|
|
},
|
|
createdAtMs: 0,
|
|
expiresAtMs: 1000,
|
|
},
|
|
}),
|
|
).toBe(false);
|
|
|
|
expect(
|
|
shouldHandleSlackExecApprovalRequest({
|
|
cfg,
|
|
accountId: "work",
|
|
request: {
|
|
id: "req-3",
|
|
request: {
|
|
command: "echo hi",
|
|
turnSourceChannel: "slack",
|
|
turnSourceAccountId: "work",
|
|
sessionKey: "agent:ops-agent:missing",
|
|
},
|
|
createdAtMs: 0,
|
|
expiresAtMs: 1000,
|
|
},
|
|
}),
|
|
).toBe(true);
|
|
});
|
|
});
|