Skip to content

feat: add OpenClaw runtime reauthentication - #711

Merged
rogerchappel merged 2 commits into
mainfrom
codex/reauthenticate-openclaw-runtime
Jul 20, 2026
Merged

rogerchappel merged 2 commits into
mainfrom
codex/reauthenticate-openclaw-runtime

Conversation

@rogerchappel

Copy link
Copy Markdown
Owner

Summary

  • add an authenticated PATCH action that verifies a replacement OpenClaw gateway token before storing it
  • retain the existing device identity and persist paired-device credentials when OpenClaw returns them
  • support approval retries with an opaque sealed identity while keeping raw private keys and device tokens server-side
  • add a Re-authenticate control to personal OpenClaw runtime settings

Security behavior

  • probes only the already-stored gateway URL
  • leaves the existing credential untouched on verification, authorization, or pairing failure
  • rejects plaintext device keys sent by the browser
  • stores the replacement token and any device token with the existing runtime credential encryption
  • prevents concurrent UI submissions

Verification

  • pnpm test: 110 files, 591 tests passed
  • focused runtime route test: 9 tests passed
  • pnpm lint: 0 errors, 56 existing warnings
  • pnpm typecheck
  • pnpm build
  • git diff --check

Risk

High: authentication and encrypted credential persistence. The endpoint is owner/admin scoped and performs no database update until the replacement credential successfully authenticates.

@rogerchappel
rogerchappel marked this pull request as ready for review July 20, 2026 08:05
@rogerchappel
rogerchappel merged commit b9cd5a8 into main Jul 20, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant