mirror of
https://github.com/hansjone/oclaw.git
synced 2026-10-11 01:50:46 +08:00
Harden attachment access controls and stabilize the Weixin bridge.
This persists referenced media safely, adds explicit attachment ACL/backfill flows, and fixes the Weixin sidecar so official login state can bridge reliably into oclaw without duplicate replays or dropped replies. Made-with: Cursor
This commit is contained in:
parent
6cfaff06f6
commit
31e3962c74
22 changed files with 1885 additions and 55 deletions
|
|
@ -1,14 +1,15 @@
|
|||
param(
|
||||
[string]$ChannelId = "oclaw-weixin",
|
||||
[string]$Package = "@tencent-weixin/oclaw-weixin@2.1.9",
|
||||
[string]$OclawRuntime = ""
|
||||
[string]$LocalSourcePath = "",
|
||||
[switch]$UseOpenclawCli = $false
|
||||
)
|
||||
|
||||
$ErrorActionPreference = "Stop"
|
||||
|
||||
function Resolve-RepoRoot {
|
||||
$here = Split-Path -Parent $PSCommandPath
|
||||
return (Resolve-Path (Join-Path $here "..")).Path
|
||||
# runtime/operations/scripts -> repo root
|
||||
return (Resolve-Path (Join-Path $here "..\\..\\..")).Path
|
||||
}
|
||||
|
||||
$oclawRoot = Resolve-RepoRoot
|
||||
|
|
@ -19,22 +20,63 @@ New-Item -ItemType Directory -Force -Path $sidecarRoot | Out-Null
|
|||
New-Item -ItemType Directory -Force -Path (Join-Path $sidecarRoot "logs") | Out-Null
|
||||
New-Item -ItemType Directory -Force -Path $stateDir | Out-Null
|
||||
|
||||
if ($UseOpenclawCli) {
|
||||
$openclawCmd = Get-Command openclaw -ErrorAction SilentlyContinue
|
||||
if (-not $openclawCmd) {
|
||||
throw "openclaw command not found. Install first: npm install -g openclaw"
|
||||
}
|
||||
npx -y @tencent-weixin/openclaw-weixin-cli@latest install
|
||||
if ($LASTEXITCODE -ne 0) {
|
||||
throw "openclaw-weixin-cli install failed with exit code $LASTEXITCODE"
|
||||
}
|
||||
Push-Location $sidecarRoot
|
||||
try {
|
||||
if (-not (Test-Path (Join-Path $sidecarRoot "package.json"))) {
|
||||
npm.cmd init -y | Out-Null
|
||||
if ($LASTEXITCODE -ne 0) {
|
||||
throw "npm init failed with exit code $LASTEXITCODE"
|
||||
}
|
||||
}
|
||||
npm.cmd install --save-exact tsx@4.21.0 typescript@6.0.3
|
||||
if ($LASTEXITCODE -ne 0) {
|
||||
throw "npm install bridge runtime deps failed with exit code $LASTEXITCODE"
|
||||
}
|
||||
$bridgeSrc = Join-Path $oclawRoot "runtime\\operations\\weixin_bridge"
|
||||
Copy-Item -Path (Join-Path $bridgeSrc "runner.ts") -Destination (Join-Path $sidecarRoot "runner.ts") -Force
|
||||
Copy-Item -Path (Join-Path $bridgeSrc "login.ts") -Destination (Join-Path $sidecarRoot "login.ts") -Force
|
||||
} finally {
|
||||
Pop-Location
|
||||
}
|
||||
Write-Host "[ok] installed official openclaw-weixin plugin + local bridge runtime"
|
||||
exit 0
|
||||
}
|
||||
|
||||
if (-not $LocalSourcePath) {
|
||||
throw "LocalSourcePath is required in sidecar mode. Example: .\\scripts\\weixin_install.ps1 -LocalSourcePath D:\\path\\to\\your-weixin-module"
|
||||
}
|
||||
|
||||
Push-Location $sidecarRoot
|
||||
try {
|
||||
if (-not (Test-Path (Join-Path $sidecarRoot "package.json"))) {
|
||||
npm.cmd init -y | Out-Null
|
||||
}
|
||||
if (Test-Path (Join-Path $sidecarRoot "package-lock.json")) {
|
||||
npm.cmd ci
|
||||
} else {
|
||||
# First-time setup: install exact versions for reproducible sidecar runtime.
|
||||
if ($OclawRuntime) {
|
||||
npm.cmd install --save-exact $Package $OclawRuntime tsx@4.21.0 typescript@6.0.3
|
||||
} else {
|
||||
npm.cmd install --save-exact $Package tsx@4.21.0 typescript@6.0.3
|
||||
if ($LASTEXITCODE -ne 0) {
|
||||
throw "npm init failed with exit code $LASTEXITCODE"
|
||||
}
|
||||
}
|
||||
Write-Host "[ok] installed $Package into $sidecarRoot"
|
||||
|
||||
$src = (Resolve-Path $LocalSourcePath).Path
|
||||
npm.cmd install --save-exact $src tsx@4.21.0 typescript@6.0.3
|
||||
if ($LASTEXITCODE -ne 0) {
|
||||
throw "npm install local source failed with exit code $LASTEXITCODE"
|
||||
}
|
||||
|
||||
if (-not (Test-Path (Join-Path $sidecarRoot "runner.ts"))) {
|
||||
throw "install completed but runner.ts is missing (invalid sidecar package/source)"
|
||||
}
|
||||
if (-not (Test-Path (Join-Path $sidecarRoot "login.ts"))) {
|
||||
throw "install completed but login.ts is missing (invalid sidecar package/source)"
|
||||
}
|
||||
Write-Host "[ok] installed local weixin sidecar into $sidecarRoot"
|
||||
} finally {
|
||||
Pop-Location
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue