All notable changes to this project will be documented in this file.
[unreleased]
๐ผ Other
[271] fix(service): address review on insider scope enforcement (#271)
Copilot review:
Propagate key scopes: verifyKey/resolveKeyAuth now return the matched
key's (or issuing insider's) scopes and the middleware sets
request.insiderScopes on key auth, so scoped machine insider keys get
filtered archives and listings, and outsider directory shares hide
entries outside the issuer's scopes.
Directory archive size limit counts only in-scope files (getDirSize
takes an optional file filter), so denied content can neither block an
export with 413 nor leak its size.
Split fileContent.ts (430 lines) into fileContent (GET), fileWrite
(PUT) and fileRender (watcher proxy + Markdown pipeline).
SOLID/DRY:
contentRoute.ts owns URL -> content path mapping; the middleware's
string replace chain is gone. Key auth for /api/mermaid-export,
/api/plantuml-export and /api/link-info is now verified against the
content path, so share keys work there as documented (previously
rejected).
scopeAccess.ts holds pure scope decisions; scopeGuard.ts the shared
403 response used by every route-level check.
archiveExport.ts owns directory archive export.
Middleware split into authenticateUtility / resolveUrlKey helpers.
Tests: 494 -> 568 service tests. New route tests for archive export,
file write, file content, file render, link info scope, share route,
getDirSize, key scope propagation. Removed sharing tests that exercised
an inline copy of the code; merged duplicate export format tests.
Docs: scope enforcement in sharing/api-integration/exports guides,
access decision flow diagram, plugin skill; fix scope examples that
used /* (direct children only) where /** was meant; fix /api/path and
/api/share body in the API reference.
[261] [267] fix: tests and typecheck read core and CLI from source, not dist
Service and openclaw vitest configs alias @karmaniverous/jeeves-server-core
to packages/core/src, and their tsconfigs map it with paths, so typecheck
and tests pass on a clean checkout with no dist/. The rollup builds override
paths: {} and still build against the built core package. Service rootDir and
outDir move to tsconfig.build.json (TS 6 rejects source outside rootDir).
The config CLI test runs src/cli/index.ts through tsx instead of
dist/src/cli/index.js.
Source resolution exposes core's @deprecated mermaidCliPath, so the ignored
field is no longer copied into RuntimeConfig.
Closes #267
[261] fix: update root package-lock.json in release-it after:bump hook
[261] feat(openclaw)!: standard OpenClaw plugin on jeeves core 0.6.0 with lazy configRoot
Move the plugin (and jeeves-server-core) to @karmaniverous/jeeves@0.6.0-3,
the static-content core (karmaniverous/jeeves#109).
Remove the ComponentWriter / TOOLS.md "## Server" section, the async
status-menu cache (promptInjection) and the createPluginCli-based
install/uninstall bin. jeeves install installs the plugin with
openclaw plugins install and writes its config.
Resolve configRoot lazily (plugin config, then JEEVES_CONFIG_ROOT) when a
tool runs. register() always succeeds, logs one warning when configRoot is
unset, and defers core init() to first use. Tools invoked without it return
a clear error naming both ways to set it. publicUrl is read per call.
Manifest: configRoot/pluginKey descriptions; configRoot has no default and
is not required. SKILL.md gains name/description frontmatter (#260) and
jeeves install instructions.
Tests: registration without config, tool error, plugin config / OpenClaw
config entry / env var, late config, lazy publicUrl, no conversation hooks,
manifest and skill frontmatter checks.
BREAKING CHANGE: the jeeves-server-openclaw install|uninstall CLI is gone;
install with jeeves install server (or openclaw plugins install). The
plugin no longer writes TOOLS.md; use server_status and the skill.
Closes #261
Closes #263
Closes #260
[261] chore(openclaw): update rollup, @rollup/plugin-commonjs and zod minors
[261] chore(deps): ncu -u --peer across all packages
[261] chore: resolve knip findings and audit advisories (lodash-es override)
[261] chore: apply prettier across the repo; ignore generated CHANGELOGs
[261] fix(openclaw): gate only tools that read configRoot
[261] feat(openclaw): pass lazy apiUrl to createPluginToolset; pin core 0.6.0-4
[V3-7] feat: add publicUrl config for shareable URL rewriting (#145)
When publicUrl is configured in the plugin, all URLs returned to tool
callers are rewritten to use the public domain instead of the local
bind address. When absent, URLs pass through unchanged (dev behavior).
[V3-7] fix: toggle-checkbox route wildcard position (CI fix)
Move wildcard from middle of route path to end: POST /api/file//toggle-checkbox
โ POST /api/toggle-checkbox/. Fastify's find-my-way router requires wildcards
to be the last character in the route.
[35] refactor: migrate openclaw plugin to core v0.4.4 SDK
Remove hand-rolled serviceCommands/pluginRemove in favor of core's
createServiceManager and createPluginCli. Rewrite cli.ts to delegate
to createPluginCli factory. Update index.ts to construct a full
JeevesComponentDescriptor for createComponentWriter.