Skip to content

fix(api): allow scoped runtime task updates - #716

Merged
rogerchappel merged 1 commit into
mainfrom
fix/runtime-task-mutation-auth
Jul 22, 2026
Merged

rogerchappel merged 1 commit into
mainfrom
fix/runtime-task-mutation-auth

Conversation

@rogerchappel

Copy link
Copy Markdown
Owner

Summary

  • allow authenticated OpenClaw runtimes to update task status and add comments
  • enforce that bearer-authenticated mutations are limited to the runtime accessible workspace
  • preserve session-authenticated behavior for human users

Why

The CrewCmd agent contract requires task claims, status transitions, and audit comments, but those mutation endpoints accepted browser sessions only. Runtime workers could create and read tasks but could not advance them.

Verification

  • pnpm exec eslint src/app/api/tasks/[id]/route.ts src/app/api/tasks/[id]/comments/route.ts
  • pnpm typecheck
  • pnpm vitest run src/app/api/tasks/route.test.ts
  • live bearer canary: claim task, add pickup comment, requeue task

@rogerchappel
rogerchappel merged commit d8e66ac into main Jul 22, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant