fix: refresh Windows Launcher command references - #96
Conversation
Use the supported gateway restart and authenticated dashboard browser commands in the copy-only reference. Update command grouping, descriptions, clipboard regressions, and README guidance. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
|
🦞👀 Pull request received. I will update this pull request when review starts. ClawSweeper review completeClawSweeper finished reviewing this revision. The review result is being finalized. |
|
Codex review: needs maintainer review before merge. Reviewed September 22, 2026, 6:38 PM ET / 22:38 UTC (Revision 3). ClawSweeper reviewWhat this changesUpdates the Windows Launcher’s copyable command reference and README to use supported restart and dashboard commands, puts gateway actions first, and adjusts regression tests. Merge readiness✅ Ready for maintainer review This PR remains useful because current main still displays the older command recipes. The updated browser diagnostics resolve the previous proof blocker, and no blocking correctness or security findings remain. Priority: P3 Review scores
Verification
How this fits togetherThe Windows Launcher tab renders isolation status and copyable commands inside OpenClaw’s Control UI. Users copy those commands into their Windows terminal; the page itself does not execute them. flowchart LR
A[Launcher isolation report] --> B[Windows Launcher page]
C[Supported command references] --> B
B --> D[Copy button]
D --> E[Clipboard or manual selection]
E --> F[User runs command in terminal]
F --> G[Existing launcher command owners]
Before mergeNone. Agent review detailsSecurityNone. Review metricsNone. Technical reviewBest possible solution: Keep the launcher reference aligned with the existing command owners while preserving its copy-only interaction. Do we have a high-confidence way to reproduce the issue? Not applicable as a runtime defect: source inspection confirms the old reference text on current main, and the supplied browser evidence demonstrates the updated presentation and copying. Is this the best way to solve the issue? Yes. Updating the existing reference data and its tests is the narrowest solution; the patch reuses supported commands without introducing another execution path. AGENTS.md: found and applied where relevant. Codex review notes: model internal, reasoning medium; reviewed against 54e718d6d967. LabelsLabel changes:
Label justifications:
EvidenceWhat I checked:
Likely related people:
Rating scale
Overall follows the weaker of proof and patch quality. Workflow
History |
Move the advanced agent PowerShell row below status, restart, and dashboard. Align order regressions and README without changing command behavior. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
What Problem This Solves
The Windows Launcher command reference still shows a stop/start chain and a
dashboard URL-display recipe instead of the supported ClawCtl commands.
User Impact
Users can copy
clawctl gateway-service restartandclawctl openfrom theClawCtl group. Open dashboard now opens the default browser when the copied
command is run. It requires completed setup and a running gateway, and does not
print authenticated URLs or tokens.
ClawCtl lists Gateway status, Restart Gateway, and Open dashboard first, followed
by Agent session PowerShell and Launcher help. The advanced shell no longer
precedes the common gateway commands. OpenClaw still lists Gateway chat TUI,
then OpenClaw help.
The page remains informational and copy-only. Unaffected commands, activation,
isolation reporting, authentication, themes, and clipboard fallback are unchanged.
Why This Change Was Made
We already have a dedicated restart operation and a verified, authenticated
browser handoff. This follow-up updates the command text, dashboard grouping and
order, descriptions, README, and exact clipboard regressions without changing
CLI or runtime behavior.
Evidence
Head:
8ced9ef59e327919425141186084c1d373260e14.Base:
54e718d6d96720741147493d4c95c8da605c5c12from canonicalmain..\scripts\Test-GatewayIsolationPlugin.Tests.ps1: 52/52 Node tests passed,plus disposable payload success/failure fixtures.
.\scripts\Test-DocReferences.ps1: zero findings.git diff --check: passed.Browser behavior, not just the screenshot
Fresh terminal diagnostics captured at 2026-09-22 22:09:47 UTC from the
committed plugin in Edge 153.0.4234.48, Playwright 1.63.0, Node v24.18.0.
The loopback component fixture calls the actual plugin route handler with a
synthetic
enabledreport and embeds it in anallow-scriptsiframe.The wrapper does not implement Gateway authentication.
All seven commands matched DOM and visual order. The primary copy path called
the browser's real
document.execCommand("copy"); each result below was readback through the actual clipboard, not a mocked return value. Terminal excerpt:
For the explicitly fault-injected fallback cases, both programmatic copy APIs
were denied. The UI selected the exact command and announced manual-copy
guidance without changing the clipboard sentinel; real Ctrl+C then copied the
selected command. No command-triggered network requests, navigation, or browser
opening occurred during the interaction window.
Existing command-owner and native CLI checks
The completed Test Gateway MSIX host job
provides public terminal logs for this revision:
CI checked out merge
611bcf8ba358f5998e62a172ed662f99e5cb35ee(base
54e718d6d967plus head8ced9ef59e32). GitHub's commit API confirmsits tree is identical to the PR head:
04e18c1cae6a8b8e11df1759c733b4eb0adc27b0.No duplicate local build was needed.
The unfiltered .NET suite includes the existing
restart owner regressions
and open-command regressions:
single-lock stop/start, refusal after unverified stop, setup/running-gateway
requirements, handoff binding, and authenticated-URL non-disclosure. These use
fixture-owned collaborators, not a live installed Gateway. The NativeAOT driver
executes the real startup/CLI path with injected collaborators; its intentional
wrong-executable-name negative check fails as expected.
Rendered reference
The screenshot below is fresh local component/browser fixture proof, with a
synthetic isolation report, captured at native 2400 x 2240 resolution. It shows
the gateway-first order, exact commands, and ClawCtl/OpenClaw grouping. It is not
installed-package, Gateway authentication, restart execution, or authenticated
browser-handoff proof. No historical screenshots are reused.
The browser diagnostics and CI checks above cover the changed copy-only
presentation and existing owner contracts. They do not prove installed Gateway
authentication, a real gateway restart, or a real authenticated browser handoff.
No new local build, VM, installed-package, signing, healthy-upgrade, or broad
browser/runtime matrix was run to gather this evidence. Existing automatic CI
is linked above; no manual workflow or review run was dispatched.