UNPKG

openclaw

Version:

Multi-channel AI gateway with extensible messaging integrations

82 lines (81 loc) 3.28 kB
import { f as resolveLegacyConfigAuditLogPath, m as scrubConfigAuditLog } from "./io.audit-Dor_5i6r.js"; import { t as note } from "./note-DqHk3fA1.js"; import fs from "node:fs/promises"; import os from "node:os"; //#region src/commands/doctor-config-audit-scrub.ts /** Doctor repair for redacting historical config audit log argv records. */ const NOTE_TITLE = "Config audit"; const CONFIG_AUDIT_SCRUB_CHECK_ID = "core/doctor/config-audit-scrub"; function formatEntryCount(count) { return `${count} ${count === 1 ? "entry" : "entries"}`; } async function detectConfigAuditScrubIssue(params) { const env = params?.env ?? process.env; const homedir = params?.homedir ?? os.homedir; return { ...await scrubConfigAuditLog({ fs: { promises: fs }, env, homedir, dryRun: true }), auditPath: resolveLegacyConfigAuditLogPath(env, homedir) }; } function configAuditScrubToHealthFinding(result) { return { checkId: CONFIG_AUDIT_SCRUB_CHECK_ID, severity: "warning", message: `${formatEntryCount(result.rewritten)} in config-audit.jsonl still contain pre-redactor argv values.`, path: result.auditPath, fixHint: "Run `openclaw doctor --fix` to rewrite argv/execArgv fields through the current redactor." }; } function configAuditScrubToRepairEffect(result) { return { kind: "file", action: "would-scrub-config-audit-log", target: result.auditPath, dryRunSafe: false }; } /** * Scrubs pre-redactor config audit records or previews the number of affected entries. * * The rewrite aborts if new records are appended while doctor is processing the JSONL file, so * live gateways do not lose audit entries during cleanup. */ async function maybeScrubConfigAuditLog(params) { const env = params.env ?? process.env; const homedir = params.homedir ?? os.homedir; const scrubFs = { promises: fs }; try { if (params.shouldRepair) { const result = await scrubConfigAuditLog({ fs: scrubFs, env, homedir }); if (result.aborted) { note("Config audit scrub was aborted because new entries were appended to config-audit.jsonl during the rewrite. No records were modified. Stop the gateway (or wait until it is idle) and rerun `openclaw doctor --fix`.", NOTE_TITLE); return; } if (result.rewritten > 0) note(`Scrubbed ${formatEntryCount(result.rewritten)} in config-audit.jsonl that still contained pre-redactor argv values. Rotate any credentials that may have been written to the log before the forward redactor shipped.`, NOTE_TITLE); return; } const preview = await scrubConfigAuditLog({ fs: scrubFs, env, homedir, dryRun: true }); if (preview.rewritten > 0) { const fixCommand = params.doctorFixCommand ?? "openclaw doctor --fix"; note(`${formatEntryCount(preview.rewritten)} in config-audit.jsonl still contain pre-redactor argv values (likely plaintext credentials at rest). Run \`${fixCommand}\` to rewrite the argv/execArgv fields through the same redactor used for new entries.`, NOTE_TITLE); } } catch (err) { note(`Config audit scrub failed: ${err instanceof Error ? err.message : String(err)}`, NOTE_TITLE); } } //#endregion export { maybeScrubConfigAuditLog as i, configAuditScrubToRepairEffect as n, detectConfigAuditScrubIssue as r, configAuditScrubToHealthFinding as t };