Harden attachment access controls and stabilize the Weixin bridge.

This persists referenced media safely, adds explicit attachment ACL/backfill flows, and fixes the Weixin sidecar so official login state can bridge reliably into oclaw without duplicate replays or dropped replies.

Made-with: Cursor
This commit is contained in:
oliver 2026-04-28 15:38:55 +08:00
parent 6cfaff06f6
commit 31e3962c74
22 changed files with 1885 additions and 55 deletions

View file

@ -1,14 +1,15 @@
param(
[string]$ChannelId = "oclaw-weixin",
[string]$Package = "@tencent-weixin/oclaw-weixin@2.1.9",
[string]$OclawRuntime = ""
[string]$LocalSourcePath = "",
[switch]$UseOpenclawCli = $false
)
$ErrorActionPreference = "Stop"
function Resolve-RepoRoot {
$here = Split-Path -Parent $PSCommandPath
return (Resolve-Path (Join-Path $here "..")).Path
# runtime/operations/scripts -> repo root
return (Resolve-Path (Join-Path $here "..\\..\\..")).Path
}
$oclawRoot = Resolve-RepoRoot
@ -19,22 +20,63 @@ New-Item -ItemType Directory -Force -Path $sidecarRoot | Out-Null
New-Item -ItemType Directory -Force -Path (Join-Path $sidecarRoot "logs") | Out-Null
New-Item -ItemType Directory -Force -Path $stateDir | Out-Null
if ($UseOpenclawCli) {
$openclawCmd = Get-Command openclaw -ErrorAction SilentlyContinue
if (-not $openclawCmd) {
throw "openclaw command not found. Install first: npm install -g openclaw"
}
npx -y @tencent-weixin/openclaw-weixin-cli@latest install
if ($LASTEXITCODE -ne 0) {
throw "openclaw-weixin-cli install failed with exit code $LASTEXITCODE"
}
Push-Location $sidecarRoot
try {
if (-not (Test-Path (Join-Path $sidecarRoot "package.json"))) {
npm.cmd init -y | Out-Null
if ($LASTEXITCODE -ne 0) {
throw "npm init failed with exit code $LASTEXITCODE"
}
}
npm.cmd install --save-exact tsx@4.21.0 typescript@6.0.3
if ($LASTEXITCODE -ne 0) {
throw "npm install bridge runtime deps failed with exit code $LASTEXITCODE"
}
$bridgeSrc = Join-Path $oclawRoot "runtime\\operations\\weixin_bridge"
Copy-Item -Path (Join-Path $bridgeSrc "runner.ts") -Destination (Join-Path $sidecarRoot "runner.ts") -Force
Copy-Item -Path (Join-Path $bridgeSrc "login.ts") -Destination (Join-Path $sidecarRoot "login.ts") -Force
} finally {
Pop-Location
}
Write-Host "[ok] installed official openclaw-weixin plugin + local bridge runtime"
exit 0
}
if (-not $LocalSourcePath) {
throw "LocalSourcePath is required in sidecar mode. Example: .\\scripts\\weixin_install.ps1 -LocalSourcePath D:\\path\\to\\your-weixin-module"
}
Push-Location $sidecarRoot
try {
if (-not (Test-Path (Join-Path $sidecarRoot "package.json"))) {
npm.cmd init -y | Out-Null
}
if (Test-Path (Join-Path $sidecarRoot "package-lock.json")) {
npm.cmd ci
} else {
# First-time setup: install exact versions for reproducible sidecar runtime.
if ($OclawRuntime) {
npm.cmd install --save-exact $Package $OclawRuntime tsx@4.21.0 typescript@6.0.3
} else {
npm.cmd install --save-exact $Package tsx@4.21.0 typescript@6.0.3
if ($LASTEXITCODE -ne 0) {
throw "npm init failed with exit code $LASTEXITCODE"
}
}
Write-Host "[ok] installed $Package into $sidecarRoot"
$src = (Resolve-Path $LocalSourcePath).Path
npm.cmd install --save-exact $src tsx@4.21.0 typescript@6.0.3
if ($LASTEXITCODE -ne 0) {
throw "npm install local source failed with exit code $LASTEXITCODE"
}
if (-not (Test-Path (Join-Path $sidecarRoot "runner.ts"))) {
throw "install completed but runner.ts is missing (invalid sidecar package/source)"
}
if (-not (Test-Path (Join-Path $sidecarRoot "login.ts"))) {
throw "install completed but login.ts is missing (invalid sidecar package/source)"
}
Write-Host "[ok] installed local weixin sidecar into $sidecarRoot"
} finally {
Pop-Location
}

View file

@ -6,7 +6,8 @@ $ErrorActionPreference = "Stop"
function Resolve-RepoRoot {
$here = Split-Path -Parent $PSCommandPath
return (Resolve-Path (Join-Path $here "..")).Path
# runtime/operations/scripts -> repo root
return (Resolve-Path (Join-Path $here "..\\..\\..")).Path
}
$oclawRoot = Resolve-RepoRoot
@ -14,7 +15,7 @@ $sidecarRoot = Join-Path $oclawRoot "data\\channel_sidecar\\$ChannelId"
$stateDir = Join-Path $sidecarRoot "state"
if (-not (Test-Path $sidecarRoot)) {
throw "sidecar not installed: run .\\scripts\\weixin_install.ps1 first"
New-Item -ItemType Directory -Force -Path $sidecarRoot | Out-Null
}
New-Item -ItemType Directory -Force -Path $stateDir | Out-Null
@ -22,10 +23,19 @@ New-Item -ItemType Directory -Force -Path $stateDir | Out-Null
Push-Location $sidecarRoot
try {
$env:OCLAW_STATE_DIR = $stateDir
if (-not (Test-Path (Join-Path $sidecarRoot "login.ts"))) {
throw "missing login.ts"
if (Test-Path (Join-Path $sidecarRoot "login.ts")) {
npm.cmd exec -- tsx login.ts
exit 0
}
npm.cmd exec -- tsx login.ts
$openclawCmd = Get-Command openclaw -ErrorAction SilentlyContinue
if (-not $openclawCmd) {
throw "official mode requires openclaw command. Install first: npm install -g openclaw"
}
$systemNodeDir = "C:\\Program Files\\nodejs"
if (Test-Path (Join-Path $systemNodeDir "node.exe")) {
$env:PATH = "$systemNodeDir;$env:PATH"
}
openclaw channels login --channel openclaw-weixin
} finally {
Pop-Location
}

View file

@ -7,7 +7,8 @@ $ErrorActionPreference = "Stop"
function Resolve-RepoRoot {
$here = Split-Path -Parent $PSCommandPath
return (Resolve-Path (Join-Path $here "..")).Path
# runtime/operations/scripts -> repo root
return (Resolve-Path (Join-Path $here "..\\..\\..")).Path
}
$oclawRoot = Resolve-RepoRoot
@ -16,24 +17,105 @@ $stateDir = Join-Path $sidecarRoot "state"
$logDir = Join-Path $sidecarRoot "logs"
$pidFile = Join-Path $sidecarRoot "pid.txt"
if (-not (Test-Path $sidecarRoot)) {
throw "sidecar not installed: run .\\scripts\\weixin_install.ps1 first"
function Get-SidecarProcesses {
$escapedSidecarRoot = $sidecarRoot.Replace("\", "\\")
$patterns = @(
"*$ChannelId*",
"*runner.ts*",
"*$escapedSidecarRoot*"
)
Get-CimInstance Win32_Process | Where-Object {
$cmd = [string]($_.CommandLine)
if (-not $cmd) { return $false }
foreach ($pattern in $patterns) {
if ($cmd -like $pattern) { return $true }
}
return $false
}
}
if (-not (Test-Path (Join-Path $sidecarRoot "runner.ts"))) {
throw "missing runner.ts (sidecar code). Re-run repo sync or restore file."
function Stop-SidecarProcesses {
$procs = @(Get-SidecarProcesses | Sort-Object ProcessId -Descending)
foreach ($proc in $procs) {
try {
taskkill.exe /PID $proc.ProcessId /T /F | Out-Null
} catch {
# Best-effort cleanup; keep going if a process already exited.
}
}
return $procs.Count
}
function Set-OfficialWeixinBaseUrl([string]$BaseUrl) {
$weixinRoot = Join-Path $env:USERPROFILE ".openclaw\\openclaw-weixin"
$accountsListPath = Join-Path $weixinRoot "accounts.json"
if (-not (Test-Path $accountsListPath)) {
Write-Host "[warn] official mode: accounts.json not found, skip baseUrl rewrite"
return
}
$ids = @()
try {
$parsed = Get-Content -Path $accountsListPath -Raw | ConvertFrom-Json
if ($parsed -is [System.Array]) {
$ids = @($parsed)
}
} catch {
Write-Host "[warn] official mode: failed to parse accounts.json"
return
}
foreach ($aid in $ids) {
$idText = [string]$aid
if (-not $idText) { continue }
$accPath = Join-Path (Join-Path $weixinRoot "accounts") "$idText.json"
if (-not (Test-Path $accPath)) { continue }
try {
$obj = Get-Content -Path $accPath -Raw | ConvertFrom-Json
$obj.baseUrl = $BaseUrl
$json = $obj | ConvertTo-Json -Depth 8
$utf8NoBom = New-Object System.Text.UTF8Encoding($false)
[System.IO.File]::WriteAllText($accPath, $json + "`n", $utf8NoBom)
Write-Host "[ok] official mode: set baseUrl for $idText -> $BaseUrl"
} catch {
Write-Host "[warn] official mode: failed to rewrite $accPath"
}
}
}
if (-not (Test-Path $sidecarRoot)) {
New-Item -ItemType Directory -Force -Path $sidecarRoot | Out-Null
}
New-Item -ItemType Directory -Force -Path $logDir | Out-Null
New-Item -ItemType Directory -Force -Path $stateDir | Out-Null
$cleaned = Stop-SidecarProcesses
Remove-Item -Force $pidFile -ErrorAction SilentlyContinue
$logPath = Join-Path $logDir "weixin_sidecar.log"
$errPath = Join-Path $logDir "weixin_sidecar.err.log"
$cmd = "cmd.exe"
$args = @(
"/c",
"cd /d $sidecarRoot && set OCLAW_STATE_DIR=$stateDir&& set AIA_GATEWAY_BASE_URL=$GatewayBaseUrl&& npm.cmd exec -- tsx runner.ts"
)
if (Test-Path (Join-Path $sidecarRoot "runner.ts")) {
$cmd = "cmd.exe"
$args = @(
"/c",
"cd /d $sidecarRoot && set OCLAW_STATE_DIR=$stateDir&& set AIA_GATEWAY_BASE_URL=$GatewayBaseUrl&& npm.cmd exec -- tsx runner.ts"
)
$p = Start-Process -FilePath $cmd -ArgumentList $args -WorkingDirectory $sidecarRoot -PassThru -WindowStyle Hidden -RedirectStandardOutput $logPath -RedirectStandardError $errPath
Set-Content -Path $pidFile -Value $p.Id
Write-Host "[ok] started weixin sidecar pid=$($p.Id) cleaned=$cleaned out=$logPath err=$errPath"
exit 0
}
$p = Start-Process -FilePath $cmd -ArgumentList $args -WorkingDirectory $sidecarRoot -PassThru -WindowStyle Hidden -RedirectStandardOutput $logPath -RedirectStandardError $errPath
$openclawCmd = Get-Command openclaw -ErrorAction SilentlyContinue
if (-not $openclawCmd) {
throw "official mode requires openclaw command. Install first: npm install -g openclaw"
}
# Ensure OpenClaw runs on the real Node.js runtime (includes npm layout).
$systemNodeDir = "C:\\Program Files\\nodejs"
if (Test-Path (Join-Path $systemNodeDir "node.exe")) {
$env:PATH = "$systemNodeDir;$env:PATH"
}
Set-OfficialWeixinBaseUrl -BaseUrl $GatewayBaseUrl
$args = @("/c", "openclaw gateway --allow-unconfigured")
$p = Start-Process -FilePath "cmd.exe" -ArgumentList $args -WorkingDirectory $oclawRoot -PassThru -WindowStyle Hidden -RedirectStandardOutput $logPath -RedirectStandardError $errPath
Set-Content -Path $pidFile -Value $p.Id
Write-Host "[ok] started weixin sidecar pid=$($p.Id) out=$logPath err=$errPath"
Write-Host "[ok] started openclaw gateway bridge pid=$($p.Id) cleaned=$cleaned out=$logPath err=$errPath"

View file

@ -6,14 +6,42 @@ $ErrorActionPreference = "Stop"
function Resolve-RepoRoot {
$here = Split-Path -Parent $PSCommandPath
return (Resolve-Path (Join-Path $here "..")).Path
# runtime/operations/scripts -> repo root
return (Resolve-Path (Join-Path $here "..\\..\\..")).Path
}
$oclawRoot = Resolve-RepoRoot
$sidecarRoot = Join-Path $oclawRoot "data\\channel_sidecar\\$ChannelId"
$pidFile = Join-Path $sidecarRoot "pid.txt"
$systemNodeDir = "C:\\Program Files\\nodejs"
if (Test-Path (Join-Path $systemNodeDir "node.exe")) {
$env:PATH = "$systemNodeDir;$env:PATH"
}
function Get-SidecarProcesses {
$escapedSidecarRoot = $sidecarRoot.Replace("\", "\\")
$patterns = @(
"*$ChannelId*",
"*runner.ts*",
"*$escapedSidecarRoot*"
)
Get-CimInstance Win32_Process | Where-Object {
$cmd = [string]($_.CommandLine)
if (-not $cmd) { return $false }
foreach ($pattern in $patterns) {
if ($cmd -like $pattern) { return $true }
}
return $false
}
}
if (-not (Test-Path $pidFile)) {
$sidecarProcs = @(Get-SidecarProcesses)
if ($sidecarProcs.Count -gt 0) {
$pids = ($sidecarProcs | Select-Object -ExpandProperty ProcessId) -join ","
Write-Host "status=orphaned count=$($sidecarProcs.Count) pids=$pids"
exit 0
}
Write-Host "status=stopped"
exit 0
}
@ -31,8 +59,25 @@ try {
} catch {}
if ($exists) {
Write-Host "status=running pid=$procId"
$sidecarProcs = @(Get-SidecarProcesses)
Write-Host "status=running pid=$procId matches=$($sidecarProcs.Count)"
} else {
$sidecarProcs = @(Get-SidecarProcesses)
if ($sidecarProcs.Count -gt 0) {
$pids = ($sidecarProcs | Select-Object -ExpandProperty ProcessId) -join ","
Write-Host "status=orphaned stale_pid=$procId count=$($sidecarProcs.Count) pids=$pids"
exit 0
}
$openclawCmd = Get-Command openclaw -ErrorAction SilentlyContinue
if ($openclawCmd) {
try {
$txt = (& openclaw channels status --probe) -join "`n"
if ($txt -match "openclaw-weixin .*running") {
Write-Host "status=running mode=official"
exit 0
}
} catch {}
}
Write-Host "status=stale_pid pid=$procId"
}

View file

@ -4,17 +4,63 @@ param(
)
$ErrorActionPreference = "Stop"
$systemNodeDir = "C:\\Program Files\\nodejs"
if (Test-Path (Join-Path $systemNodeDir "node.exe")) {
$env:PATH = "$systemNodeDir;$env:PATH"
}
function Resolve-RepoRoot {
$here = Split-Path -Parent $PSCommandPath
return (Resolve-Path (Join-Path $here "..")).Path
# runtime/operations/scripts -> repo root
return (Resolve-Path (Join-Path $here "..\\..\\..")).Path
}
$oclawRoot = Resolve-RepoRoot
$sidecarRoot = Join-Path $oclawRoot "data\\channel_sidecar\\$ChannelId"
$pidFile = Join-Path $sidecarRoot "pid.txt"
function Get-SidecarProcesses {
$escapedSidecarRoot = $sidecarRoot.Replace("\", "\\")
$patterns = @(
"*$ChannelId*",
"*runner.ts*",
"*$escapedSidecarRoot*"
)
Get-CimInstance Win32_Process | Where-Object {
$cmd = [string]($_.CommandLine)
if (-not $cmd) { return $false }
foreach ($pattern in $patterns) {
if ($cmd -like $pattern) { return $true }
}
return $false
}
}
function Stop-SidecarProcesses {
param(
[switch]$ForceKill
)
$procs = @(Get-SidecarProcesses | Sort-Object ProcessId -Descending)
foreach ($proc in $procs) {
try {
if ($ForceKill) {
taskkill.exe /PID $proc.ProcessId /T /F | Out-Null
} else {
taskkill.exe /PID $proc.ProcessId /T | Out-Null
}
} catch {
# Ignore already-exited processes and continue best-effort cleanup.
}
}
return $procs.Count
}
if (-not (Test-Path $pidFile)) {
$killed = Stop-SidecarProcesses -ForceKill:$Force
if ($killed -gt 0) {
Write-Host "[ok] cleaned stale sidecar processes count=$killed"
exit 0
}
Write-Host "[ok] not running (no pid file)"
exit 0
}
@ -36,6 +82,11 @@ try {
# Ignore if already dead.
}
$killed = Stop-SidecarProcesses -ForceKill:$Force
Remove-Item -Force $pidFile -ErrorAction SilentlyContinue
Write-Host "[ok] stopped pid=$procId"
$openclawCmd = Get-Command openclaw -ErrorAction SilentlyContinue
if ($openclawCmd) {
try { openclaw gateway stop | Out-Null } catch {}
}
Write-Host "[ok] stopped pid=$procId extra_cleaned=$killed"