openclaw/docs/platforms
VihariKanukollu cbbe9dd0a2 security: harden credential handling, API auth, and archive extraction
- Control UI: switch token/password from query params to URL fragments (#token=...)
  - Auto-strips after first load, never logged in server access logs
  - Added defense-in-depth headers (Referrer-Policy, X-Frame-Options, CSP, nosniff)
- macOS: "Open Dashboard" now uses fragments instead of query params
- CLI/onboarding: emit fragment links instead of query param links
- Plugin HTTP: /api/** now requires Gateway auth (fixes unauthenticated Nostr API)
  - Added config toggle gateway.plugins.http.protectApiPaths (default: true)
- Control UI: sends Authorization header for Nostr profile save/import
- Android hardening:
  - WebView: disabled mixed content, multi-window, reduced file URL privileges
  - A2UI bridge: origin validation + 64KB payload cap
  - TLS: enabled hostname verification for DNS names
- Archive extraction: block path traversal + symlink/hardlink entries
- Dependencies: upgraded tar 7.5.7, hono 4.11.7, added overrides for vulnerabilities

Breaking: Old ?token=... dashboard links no longer auto-auth; use #token=... instead
2026-01-29 16:05:38 +05:30
..
mac docs: switch skill metadata key to moltbot 2026-01-28 01:32:53 +01:00
android.md refactor: rename clawdbot to moltbot with legacy compat 2026-01-27 12:21:02 +00:00
digitalocean.md refactor: rename clawdbot to moltbot with legacy compat 2026-01-27 12:21:02 +00:00
exe-dev.md security: harden credential handling, API auth, and archive extraction 2026-01-29 16:05:38 +05:30
fly.md chore: bump beta version to 2026.1.27-beta.1 2026-01-28 01:28:16 +01:00
gcp.md refactor: rename clawdbot to moltbot with legacy compat 2026-01-27 12:21:02 +00:00
hetzner.md refactor: rename clawdbot to moltbot with legacy compat 2026-01-27 12:21:02 +00:00
index.md Branding: update bot.molt bundle IDs + launchd labels 2026-01-27 14:46:50 -06:00
ios.md refactor: rename clawdbot to moltbot with legacy compat 2026-01-27 12:21:02 +00:00
linux.md refactor: rename clawdbot to moltbot with legacy compat 2026-01-27 12:21:02 +00:00
macos-vm.md refactor: rename clawdbot to moltbot with legacy compat 2026-01-27 12:21:02 +00:00
macos.md Branding: update bot.molt bundle IDs + launchd labels 2026-01-27 14:46:50 -06:00
oracle.md refactor: rename clawdbot to moltbot with legacy compat 2026-01-27 12:21:02 +00:00
raspberry-pi.md refactor: rename clawdbot to moltbot with legacy compat 2026-01-27 12:21:02 +00:00
windows.md refactor: rename clawdbot to moltbot with legacy compat 2026-01-27 12:21:02 +00:00