| Add external plugin apps to plugins/ Add 13 public plugin apps from the BasedHardware org: - omi-clickup-app - omi-dropbox-app - omi-github-app - omi-google-calendar-app - omi-hive-app - omi-linear-app - omi-notion-app - omi-shipbob-app - omi-shopify-app - omi-slack-app - omi-twitter-app - omi-twitter-chat-tools-app - omi-whoop-app Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> | 7 个月前 |
| Add external plugin apps to plugins/ Add 13 public plugin apps from the BasedHardware org: - omi-clickup-app - omi-dropbox-app - omi-github-app - omi-google-calendar-app - omi-hive-app - omi-linear-app - omi-notion-app - omi-shipbob-app - omi-shopify-app - omi-slack-app - omi-twitter-app - omi-twitter-chat-tools-app - omi-whoop-app Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> | 7 个月前 |
| Add external plugin apps to plugins/ Add 13 public plugin apps from the BasedHardware org: - omi-clickup-app - omi-dropbox-app - omi-github-app - omi-google-calendar-app - omi-hive-app - omi-linear-app - omi-notion-app - omi-shipbob-app - omi-shopify-app - omi-slack-app - omi-twitter-app - omi-twitter-chat-tools-app - omi-whoop-app Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> | 7 个月前 |
| fix(shipbob): require shared secret on chat-tool routes (#14684) The /select-channel and /tools/* routes read uid from the request body and act on that user's stored ShipBob token with no caller authentication, letting anyone who reaches the service read another user's orders/catalog, cancel their receiving orders, or repoint their channel. Add shipbob_tools_auth.py (shared-secret guard, hmac.compare_digest against SHIPBOB_TOOLS_SECRET, Authorization: Bearer header or shipbob_tools_token query param) and apply it via Depends() to all eight routes. Fails closed: 503 when unconfigured, 401 on missing/wrong token. Mirrors the merged mentor_webhook_auth.py precedent. Tests: new test_shipbob_tools_auth.py (unit + route-wiring + integration); updated the cancel_wro regression tests and the hermetic disambiguation stub for the new dependency. Co-authored-by: glmbugbounty <320814379+glmbugbounty@users.noreply.github.com> | 16 天前 |
| Add external plugin apps to plugins/ Add 13 public plugin apps from the BasedHardware org: - omi-clickup-app - omi-dropbox-app - omi-github-app - omi-google-calendar-app - omi-hive-app - omi-linear-app - omi-notion-app - omi-shipbob-app - omi-shopify-app - omi-slack-app - omi-twitter-app - omi-twitter-chat-tools-app - omi-whoop-app Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> | 7 个月前 |
| fix(plugins): bound every requests call with a timeout (#15113) * fix(plugins): bound every requests call with a timeout requests has no default timeout, so an upstream that accepts the connection and then stops answering pins the caller. 19 of the 76 unbounded calls sat in async handlers, where the blocking call holds the event loop and the app stops answering everyone. * chore(ci): fail plugin requests calls that carry no timeout The same class was fixed one app at a time in #14278, #14255 and #14257. The scanner is stdlib only, follows requests.Session aliases, and reports which findings sit in an async handler. * test(clickup): let the due-date double accept the timeout kwarg | 16 小时前 |
| fix(shipbob): harden input validation, type coercion, and null guards (#14210) (#14211) - Coerce limit parameter to bounded integer across get_inventory, get_products, get_wros, and get_orders - Validate quantity and fulfillment_center_id in create_wro with try/except and descriptive error messages - Defensively guard null address in get_fulfillment_centers to prevent AttributeError - Normalize WRO IDs in cancel_wro by stripping leading hashes and whitespace - Defensively format null created_date and expected_arrival_date timestamps - Add typed Pydantic models for chat tool request payloads - Add comprehensive hermetic test suite covering all tools and regression cases Failure-Class: none | 19 天前 |
| Add external plugin apps to plugins/ Add 13 public plugin apps from the BasedHardware org: - omi-clickup-app - omi-dropbox-app - omi-github-app - omi-google-calendar-app - omi-hive-app - omi-linear-app - omi-notion-app - omi-shipbob-app - omi-shopify-app - omi-slack-app - omi-twitter-app - omi-twitter-chat-tools-app - omi-whoop-app Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> | 7 个月前 |
| refactor(plugins): consolidate shared webhook models | 3 个月前 |
| fix(shipbob): require shared secret on chat-tool routes (#14684) The /select-channel and /tools/* routes read uid from the request body and act on that user's stored ShipBob token with no caller authentication, letting anyone who reaches the service read another user's orders/catalog, cancel their receiving orders, or repoint their channel. Add shipbob_tools_auth.py (shared-secret guard, hmac.compare_digest against SHIPBOB_TOOLS_SECRET, Authorization: Bearer header or shipbob_tools_token query param) and apply it via Depends() to all eight routes. Fails closed: 503 when unconfigured, 401 on missing/wrong token. Mirrors the merged mentor_webhook_auth.py precedent. Tests: new test_shipbob_tools_auth.py (unit + route-wiring + integration); updated the cancel_wro regression tests and the hermetic disambiguation stub for the new dependency. Co-authored-by: glmbugbounty <320814379+glmbugbounty@users.noreply.github.com> | 16 天前 |
| fix(shipbob): require shared secret on chat-tool routes (#14684) The /select-channel and /tools/* routes read uid from the request body and act on that user's stored ShipBob token with no caller authentication, letting anyone who reaches the service read another user's orders/catalog, cancel their receiving orders, or repoint their channel. Add shipbob_tools_auth.py (shared-secret guard, hmac.compare_digest against SHIPBOB_TOOLS_SECRET, Authorization: Bearer header or shipbob_tools_token query param) and apply it via Depends() to all eight routes. Fails closed: 503 when unconfigured, 401 on missing/wrong token. Mirrors the merged mentor_webhook_auth.py precedent. Tests: new test_shipbob_tools_auth.py (unit + route-wiring + integration); updated the cancel_wro regression tests and the hermetic disambiguation stub for the new dependency. Co-authored-by: glmbugbounty <320814379+glmbugbounty@users.noreply.github.com> | 16 天前 |
| fix(shipbob): require shared secret on chat-tool routes (#14684) The /select-channel and /tools/* routes read uid from the request body and act on that user's stored ShipBob token with no caller authentication, letting anyone who reaches the service read another user's orders/catalog, cancel their receiving orders, or repoint their channel. Add shipbob_tools_auth.py (shared-secret guard, hmac.compare_digest against SHIPBOB_TOOLS_SECRET, Authorization: Bearer header or shipbob_tools_token query param) and apply it via Depends() to all eight routes. Fails closed: 503 when unconfigured, 401 on missing/wrong token. Mirrors the merged mentor_webhook_auth.py precedent. Tests: new test_shipbob_tools_auth.py (unit + route-wiring + integration); updated the cancel_wro regression tests and the hermetic disambiguation stub for the new dependency. Co-authored-by: glmbugbounty <320814379+glmbugbounty@users.noreply.github.com> | 16 天前 |
| fix(shipbob): require shared secret on chat-tool routes (#14684) The /select-channel and /tools/* routes read uid from the request body and act on that user's stored ShipBob token with no caller authentication, letting anyone who reaches the service read another user's orders/catalog, cancel their receiving orders, or repoint their channel. Add shipbob_tools_auth.py (shared-secret guard, hmac.compare_digest against SHIPBOB_TOOLS_SECRET, Authorization: Bearer header or shipbob_tools_token query param) and apply it via Depends() to all eight routes. Fails closed: 503 when unconfigured, 401 on missing/wrong token. Mirrors the merged mentor_webhook_auth.py precedent. Tests: new test_shipbob_tools_auth.py (unit + route-wiring + integration); updated the cancel_wro regression tests and the hermetic disambiguation stub for the new dependency. Co-authored-by: glmbugbounty <320814379+glmbugbounty@users.noreply.github.com> | 16 天前 |