UNPKG

openclaw

Version:

Multi-channel AI gateway with extensible messaging integrations

31 lines (30 loc) 7.63 kB
import { _ as compileSafeRegexDetailed, c as redactSensitiveText, g as compileSafeRegex, v as hasNestedRepetition, y as testRegexWithBoundedInput } from "../redact-DduLliKq.js"; import { i as formatErrorMessage, r as extractErrorCode } from "../errors-BXgSefBE.js"; import { i as isPathInside, m as FsSafeError, r as isNotFoundPathError } from "../path-BlG8lhgR.js"; import { A as resolveAbsolutePathForWrite, D as canonicalPathFromExistingAncestor, E as assertAbsolutePathInput, O as findExistingAncestor, T as pathExistsSync, _ as resolveLocalPathFromRootsSync, c as withTimeout, d as resolveExistingPathsWithinRoot, f as resolvePathWithinRoot, h as resolveWritablePathWithinRoot, k as resolveAbsolutePathForRead, m as resolveStrictExistingPathsWithinRoot, p as resolvePathsWithinRoot, r as writeExternalFileWithinRoot, t as ensureAbsoluteDirectory, u as pathScope, w as pathExists } from "../fs-safe-aqmM_n6V.js"; import { n as writeViaSiblingTempPath, r as sanitizeUntrustedFileName, t as writeSiblingTempFile } from "../sibling-temp-CLpkwDtX.js"; import { a as root, r as openLocalFileSafely } from "../secure-temp-dir-XAWcZnE2.js"; import { n as assertNoSymlinkParentsSync, t as assertNoSymlinkParents } from "../symlink-parents-LGlX4F0x.js"; import { a as resolveRegularFileAppendFlags, i as readRegularFileSync, n as appendRegularFileSync, o as statRegularFile, r as readRegularFile, s as statRegularFileSync, t as appendRegularFile } from "../regular-file-BD2zl6_l.js"; import { c as isRecord } from "../utils-CCC-BEJH.js"; import { n as resolvePreferredOpenClawTmpDir } from "../tmp-openclaw-dir-DOKojISm.js"; import { i as replaceFileAtomicSync, n as replaceFileAtomic, t as movePathWithCopyFallback } from "../replace-file-BrS02dAb.js"; import { n as privateFileStoreSync, t as privateFileStore } from "../private-file-store-BAvApZYp.js"; import { a as parseDotPath, c as toDotPath, i as normalizePositiveTimerMs, l as writeJsonFileSecure, n as isNonEmptyString, o as parseEnvValue, r as normalizePositiveInt, s as readTextFileIfExists, t as ensureDirForFile, u as writeTextFileAtomic } from "../shared-CuqTS6Vs.js"; import { a as isChannelAccountEffectivelyEnabled, c as pushInactiveSurfaceWarning, i as hasOwnProperty, l as pushWarning, n as collectSecretInputAssignment, o as isEnabledFlag, r as createResolverContext, s as pushAssignment, t as applyResolvedAssignments } from "../runtime-shared-DR5938Io.js"; import { t as safeEqualSecret } from "../secret-equal-DRsL8lKD.js"; import { r as ensurePortAvailable } from "../ports-CoxQQbiY.js"; import { i as hasProxyEnvConfigured } from "../proxy-env-B9aW4MXJ.js"; import { t as normalizeHostname } from "../hostname-D8MH4bbf.js"; import { _ as resolvePinnedHostnameWithPolicy, c as isBlockedHostnameOrIp, d as isPrivateNetworkAllowedByPolicy, p as matchesHostnameAllowlist, t as SsrFBlockedError } from "../ssrf-CvPEXMGn.js"; import { a as parseAccessGroupAllowFromEntry, t as ACCESS_GROUP_ALLOW_FROM_PREFIX } from "../allow-from-Ddq5GeWG.js"; import { a as resolveDmGroupAccessWithCommandGate, c as resolveOpenDmAllowlistAccess, i as resolveDmGroupAccessDecision, l as resolvePinnedMainDmOwnerFromAllowlist, n as readStoreAllowFromForDmPolicy, o as resolveDmGroupAccessWithLists, r as resolveDmAllowState, s as resolveEffectiveAllowFromLists, t as DM_GROUP_ACCESS_REASON } from "../dm-policy-shared-BjnswXJt.js"; import { i as generateSecureToken } from "../secure-random-Ds4AFLgz.js"; import { a as getChannelSurface, c as normalizeSecretStringValue, i as getChannelRecord, l as resolveChannelAccountSurface, n as collectNestedChannelFieldAssignments, o as hasConfiguredSecretInputValue, r as collectSimpleChannelFieldAssignments, s as isBaseFieldActiveForChannelSurface, t as collectConditionalChannelFieldAssignments } from "../channel-secret-basic-runtime-BTUuyj14.js"; import { t as collectNestedChannelTtsAssignments } from "../channel-secret-tts-runtime-BmiaVQR9.js"; import { n as mapHookExternalContentSource, r as resolveHookExternalContentSource, t as isExternalHookSession } from "../external-content-source-CO610hNP.js"; import { a as wrapWebContent, i as wrapExternalContent, n as detectSuspiciousPatterns, r as getHookType, t as buildSafeExternalPrompt } from "../external-content-pX-Pk1Iu.js"; import { n as writeFileFromPathWithinRoot, r as buildUntrustedChannelMetadata, t as openFileWithinRoot } from "../security-runtime-CQm7DD1u.js"; import { n as filterSupplementalContextItems, r as shouldIncludeSupplementalContext, t as evaluateSupplementalContextVisibility } from "../context-visibility-C5CaKMWO.js"; import { n as resolveAccessGroupAllowFromMatches, r as resolveAccessGroupAllowFromState, t as expandAllowFromWithAccessGroups } from "../access-groups-BLRdV-0W.js"; export { ACCESS_GROUP_ALLOW_FROM_PREFIX, DM_GROUP_ACCESS_REASON, FsSafeError, FsSafeError as SafeOpenError, SsrFBlockedError, appendRegularFile, appendRegularFileSync, applyResolvedAssignments, assertAbsolutePathInput, assertNoSymlinkParents, assertNoSymlinkParentsSync, buildSafeExternalPrompt, buildUntrustedChannelMetadata, canonicalPathFromExistingAncestor, collectConditionalChannelFieldAssignments, collectNestedChannelFieldAssignments, collectNestedChannelTtsAssignments, collectSecretInputAssignment, collectSimpleChannelFieldAssignments, compileSafeRegex, compileSafeRegexDetailed, createResolverContext, detectSuspiciousPatterns, ensureAbsoluteDirectory, ensureDirForFile, ensurePortAvailable, evaluateSupplementalContextVisibility, expandAllowFromWithAccessGroups, extractErrorCode, filterSupplementalContextItems, findExistingAncestor, formatErrorMessage, generateSecureToken, getChannelRecord, getChannelSurface, getHookType, hasConfiguredSecretInputValue, hasNestedRepetition, hasOwnProperty, hasProxyEnvConfigured, isBaseFieldActiveForChannelSurface, isBlockedHostnameOrIp, isChannelAccountEffectivelyEnabled, isEnabledFlag, isExternalHookSession, isNonEmptyString, isNotFoundPathError, isPathInside, isPrivateNetworkAllowedByPolicy, isRecord, mapHookExternalContentSource, matchesHostnameAllowlist, movePathWithCopyFallback, normalizeHostname, normalizePositiveInt, normalizePositiveTimerMs, normalizeSecretStringValue, openFileWithinRoot, openLocalFileSafely, parseAccessGroupAllowFromEntry, parseDotPath, parseEnvValue, pathExists, pathExistsSync, pathScope, privateFileStore, privateFileStoreSync, pushAssignment, pushInactiveSurfaceWarning, pushWarning, readRegularFile, readRegularFileSync, readStoreAllowFromForDmPolicy, readTextFileIfExists, redactSensitiveText, replaceFileAtomic, replaceFileAtomicSync, resolveAbsolutePathForRead, resolveAbsolutePathForWrite, resolveAccessGroupAllowFromMatches, resolveAccessGroupAllowFromState, resolveChannelAccountSurface, resolveDmAllowState, resolveDmGroupAccessDecision, resolveDmGroupAccessWithCommandGate, resolveDmGroupAccessWithLists, resolveEffectiveAllowFromLists, resolveExistingPathsWithinRoot, resolveHookExternalContentSource, resolveLocalPathFromRootsSync, resolveOpenDmAllowlistAccess, resolvePathWithinRoot, resolvePathsWithinRoot, resolvePinnedHostnameWithPolicy, resolvePinnedMainDmOwnerFromAllowlist, resolvePreferredOpenClawTmpDir, resolveRegularFileAppendFlags, resolveStrictExistingPathsWithinRoot, resolveWritablePathWithinRoot, root, safeEqualSecret, sanitizeUntrustedFileName, shouldIncludeSupplementalContext, statRegularFile, statRegularFileSync, testRegexWithBoundedInput, toDotPath, withTimeout, wrapExternalContent, wrapWebContent, writeExternalFileWithinRoot, writeFileFromPathWithinRoot, writeJsonFileSecure, writeSiblingTempFile, writeTextFileAtomic, writeViaSiblingTempPath };