Skip to content

fix: seal OpenClaw probe credentials - #708

Merged
rogerchappel merged 5 commits into
mainfrom
codex/seal-openclaw-probe-auth
Jul 20, 2026
Merged

rogerchappel merged 5 commits into
mainfrom
codex/seal-openclaw-probe-auth

Conversation

@rogerchappel

Copy link
Copy Markdown
Owner

Summary

  • capture the device token issued by a successful OpenClaw probe
  • encrypt the token and Ed25519 private key before returning probe data to the browser
  • return only opaque ciphertext for pairing retries
  • package sealed credentials as runtime metadata for the onboarding persistence step

Why

The initial shared-token handshake is the moment OpenClaw issues the durable device credential. CrewCMD previously discarded it and returned the raw private key to the browser.

Stack

Depends on #707, #706, and #705. The next stacked PR persists the sealed metadata when onboarding creates the runtime.

Verification

  • pnpm test -- src/app/api/runtimes/probe/route.test.ts src/lib/gateway-client-auth-lifecycle.test.ts src/lib/runtime-device-auth.test.ts
  • pnpm exec tsc --noEmit --pretty false --incremental false
  • pnpm exec eslint src/app/api/runtimes/probe/route.ts src/app/api/runtimes/probe/route.test.ts
  • pre-push pnpm typecheck
  • pre-push pnpm build
  • git diff --check

@rogerchappel
rogerchappel changed the base branch from codex/wire-openclaw-device-auth to main July 20, 2026 07:31
@rogerchappel
rogerchappel marked this pull request as ready for review July 20, 2026 07:31
@rogerchappel
rogerchappel merged commit 994bf89 into main Jul 20, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant