Skip to content

feat: persist runtime device authentication - #707

Merged
rogerchappel merged 4 commits into
mainfrom
codex/wire-openclaw-device-auth
Jul 20, 2026
Merged

rogerchappel merged 4 commits into
mainfrom
codex/wire-openclaw-device-auth

Conversation

@rogerchappel

Copy link
Copy Markdown
Owner

Summary

  • connect the Gateway pool to the encrypted per-runtime device credential store
  • persist newly issued or rotated device tokens before marking a connection ready
  • restore approved scopes only for the matching stable device identity
  • clear rejected device tokens while retaining the shared recovery credential
  • opportunistically encrypt legacy plaintext device private keys
  • stop authentication failures from being repeated across fallback URLs

Why

The protocol client can now perform the official device-token lifecycle, but it needs durable per-runtime storage to survive process restarts and shared-token drift.

Stack

Depends on #706, which depends on #705. Onboarding capture follows in the next stacked PR.

Verification

  • pnpm test -- src/lib/gateway-chat-pool.test.ts src/lib/gateway-client-auth-lifecycle.test.ts src/lib/runtime-device-auth.test.ts
  • pnpm exec tsc --noEmit --pretty false --incremental false
  • pnpm exec eslint src/lib/gateway-chat-pool.ts src/lib/gateway-chat-pool.test.ts
  • pre-push pnpm typecheck
  • pre-push pnpm build
  • git diff --check

@rogerchappel
rogerchappel changed the base branch from codex/persist-openclaw-device-auth to main July 20, 2026 07:31
@rogerchappel
rogerchappel marked this pull request as ready for review July 20, 2026 07:31
@rogerchappel
rogerchappel merged commit 5860d1e into main Jul 20, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant