feat: add clawctl open command - #84
Conversation
|
🦞👀 Pull request received. I will update this pull request when review starts. ClawSweeper review completeClawSweeper finished reviewing this revision. The review result is being finalized. |
|
Codex review: needs maintainer review before merge. Reviewed September 21, 2026, 3:55 PM ET / 19:55 UTC (Revision 4). ClawSweeper reviewWhat this changesAdds Merge readiness✅ Ready for maintainer review This PR remains useful: current main lacks the command, the earlier code findings are addressed, and the updated installed-package evidence resolves the remaining stale-session proof concern. No blocking introduced defect was found. Priority: P2 Review scores
Verification
How this fits togetherThe Windows launcher manages an isolated OpenClaw session and its gateway. The new command asks packaged OpenClaw for a browser handoff, validates its destination and session identity, then activates the Windows default browser. flowchart LR
A[clawctl open] --> B[Check setup and running gateway]
B --> C[Packaged OpenClaw dashboard]
C --> D[One-time browser handoff]
D --> E{Observed port and current session}
E -->|Valid| F[Windows default browser]
E -->|Invalid| G[Safe error without credentials]
Before mergeNone. Agent review detailsSecurityNone. Review metrics
Technical reviewBest possible solution: Keep upstream responsible for authenticated handoff creation and the Windows launcher responsible for validating and activating it without exposing credentials. Do we have a high-confidence way to reproduce the issue? Not applicable as a feature request; main’s command tree confirms the missing capability, and supplied installed-package runs demonstrate the proposed behavior. Is this the best way to solve the issue? Yes. Reusing upstream dashboard resolution while keeping destination validation and browser activation in the Windows host preserves the existing ownership boundaries. AGENTS.md: found and applied where relevant. Codex review notes: model internal, reasoning medium; reviewed against ee41ab70e76c. LabelsLabel changes:
Label justifications:
EvidenceWhat I checked:
Likely related people:
Rating scale
Overall follows the weaker of proof and patch quality. Workflow
HistoryReview history (3 earlier review cycles)
|
Require completed setup and a running managed gateway before opening OpenClaw's verified one-time Control UI handoff in the default browser. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 9ff501e8-3075-418e-9816-146dedceca22
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 9ff501e8-3075-418e-9816-146dedceca22
7f46faf to
747ea81
Compare
|
@clawsweeper re-review |
|
🦞🧹 I asked ClawSweeper to review this item again. |
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 9ff501e8-3075-418e-9816-146dedceca22
|
@clawsweeper re-review |
|
🦞🧹 I asked ClawSweeper to review this item again. Re-review progress:
|
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 9ff501e8-3075-418e-9816-146dedceca22
|
@clawsweeper re-review |
|
🦞🧹 I asked ClawSweeper to review this item again. |
What Problem This Solves
The packaged
clawctlsurface has no safe command that opens the authenticated Control UI for its managed gateway.User Impact
User impact: after setup and gateway startup, users can run
clawctl opento open OpenClaw's verified one-time browser handoff without revealing the long-lived gateway token.Why This Change Was Made
clawctl openrequires completed setup and a positively observed running managed gateway, then delegates TLS, base-path, authentication, readiness, and one-time pairing resolution to packaged OpenClaw'sdashboard --jsonflow. The launcher accepts only an absolute loopback HTTP(S) handoff whose port the managed gateway was actually observed listening on, opens it through the Windows default browser, and never writes the authenticated URL to human output, JSON, or logs.Because the managed gateway can be pinned to a port that the agent's own OpenClaw configuration does not name, the dashboard child is resolved against the gateway's single verified observed port through upstream's supported
OPENCLAW_GATEWAY_PORTcontract. Without that, upstream resolved its default port and reported the gateway as not running.Gateway status output now directs users to
clawctl openinstead of recommending token disclosure. Missing or incomplete setup and non-running gateways fail without starting lifecycle work or opening a browser.Evidence
Validated at head
04b5124c241fea9d0b369921516655e575773edb:.\scripts\Test-DotNetQuality.ps1— passed with 0 warnings and 0 errors.dotnet test .\OpenClaw.Gateway.MSIX.slnx --configuration Release --no-restore— 834 passed..\scripts\Test-NativeAotCli.Tests.ps1— 18 NativeAOT scenarios passed..\scripts\Test-DocReferences.ps1— 0 findings..\scripts\Test-Deploy-LocalPackage.Tests.ps1— passed, including repair of missing or modified staged redirect scripts.Real end-to-end runs against an installed local package with completed setup and a running managed gateway:
clawctl open --jsonexited0and the default browser opened the Control UI. Standard output carried only{"ok":true,...,"gateway":{"state":"running"}}with no URL, token fragment, or port.51789while the agent's owngateway.portremained unset, so upstream's own resolution still pointed at its default.clawctl open --jsonexited0with no host environment override set, targeting the gateway purely from its observed port.openclaw dashboard --json, which reaches upstream without the override exactly as the previous revision did, exited1with{"ok":false,"reason":"Gateway is not running."}. That is the defect this revision fixes.Destination and session authority, exercised through the production validator using genuine captured upstream handoff output rather than synthetic text:
Stale-session final effect, observed against the installed package with a genuine handoff in flight. The recorded session was replaced while a real
clawctl openwas resolving its handoff, then restored byte-for-byte:The browser was not activated, and no authenticated URL or token was emitted. Repeating the replacement across a range of timings produced the same rejection whenever it landed inside the run; the session-identity guard fires while the handoff is still being resolved, so activation is never reached. The final pre-activation re-check of the recorded sandbox and generation is the defense-in-depth behind that guard; its window is too narrow to drive from outside the process, so it is covered by deterministic final-effect tests instead, which also assert zero browser calls for a substituted port and for a replaced session.
Not run: signing and MSIX composition lanes, because this change does not modify package contents, manifest, signing inputs, or release policy. The captured authenticated handoff used for the authority checks was held outside the repository and deleted; no authenticated URL or token appears in this PR, the tests, or the repository.