Skip to content

Remove temporary Security.AllowViewerAgentExecution after one release #258

Description

@Telli

#256 requires the operator role on every surface that runs the agent or mutates state: /ws, /v1/chat/completions, /v1/responses, A2A execution, /apps/chat, MCP App tool calls, and the mutating MCP tools. #257 adds /ws/live.

To avoid an outage for deployments whose accounts were left on the default viewer role, #256 adds a temporary migration switch, OpenClaw:Security:AllowViewerAgentExecution (default false). It re-admits authenticated identities below operator. Each admission is logged under OpenClaw.Gateway.Authorization, and admin posture reports the viewer_agent_execution_allowed risk flag.

The switch is documented as temporary. Remove it in the release after the one that ships #256.

Remove:

  • SecurityConfig.AllowViewerAgentExecution and its branch in EndpointHelpers.CanExecuteAgent
  • the viewer_agent_execution_allowed posture flag and recommendation
  • the tests that cover the switch
  • the docs (docs/AUTHENTICATION.md, zh-CN translation, CHANGELOG.md) and the admin UI hint that mentions it

Consider: failing startup (or warning loudly) when the removed key is still present in configuration, so operators notice instead of silently losing access.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions