OpenClaw 2026.6.33: security hardening across gateway auth, MCP authority, and channel delivery
A 169-PR release dominated by security and reliability repair. Gateway HTTP now rejects disallowed browser origins before unauthenticated handling, external MCP loopback clients get short-lived session-bound grants instead of inheriting mutable child-process authority, Codex app-server commands require a real human or plugin approval, and secrets are redacted from MCP status output and Telegram-adjacent logs. Operators running exposed gateways should treat this as an upgrade release.
PUBLISHED2026-08-08
OBSERVED2026-08-11
AGE3d
SOURCES1
Highlights
- Response-size caps on provider streams, Discord REST responses, browser fetches, OAuth paths; Telegram credentials kept out of diagnostics
- Run release, liveness checks, and watchdog semantics distinguish genuine stalls from active long model calls and wedged backends
- Discord reconnects no longer silently drop queued messages or repeat ambiguous non-idempotent sends; Telegram bot-to-bot and reply-fence handling preserve thread and authorization result
- Service restarts preserve SecretRef-backed Telegram credentials; OAuth repair no longer overwrites a valid destination profile
- Package installs can select and update from the
extended-stablechannel without silently falling back to another release line
Authority changes
- Codex app-server commands require an actual human/plugin approval
- Exec auto-review bound to the exact resolved command
- Narrow tool allowlists stay owned by the constructing factory
- External MCP loopback clients use short-lived session-bound attach grants
- Gateway message actions retain trusted requester provenance and reject untrusted callers
Fixes
- Gateway HTTP rejects disallowed browser origins before unauthenticated handling; permission repair confined to its intended include; MCP status output redacts secrets
- Bounded agent-run caches, no file-descriptor leak in lock probes, valid UTF-8 close reasons, heartbeat reads survive transient filesystem races
- Anthropic-compatible partial streams no longer hang at their size bound; OpenAI Realtime uses correct auth and transcription secret flow; remote CDP credentials kept out of responses
- Replayed Twilio requests rejected under sustained traffic; corrupt queued channel rows tombstoned without blocking later work; Telegram tokens redacted across split log chunks
COMMUNITY
No curated reactions recorded for this event. Facts and takes are kept in separate layers — community context is added by hand, never blended into the record above.