From 9cd3d2cca8024148f10bfb2d7e7e26db6eda4bb1 Mon Sep 17 00:00:00 2001 From: Chaithanya Kumar Date: Thu, 2 Apr 2026 21:19:12 +0530 Subject: [PATCH] fix(openclaw): remove process.env access to clear security scanner warning (#4676) Co-authored-by: Claude Opus 4.6 (1M context) --- openclaw/config.ts | 39 +++++++-------------------------------- openclaw/package.json | 2 +- 2 files changed, 8 insertions(+), 33 deletions(-) diff --git a/openclaw/config.ts b/openclaw/config.ts index 37dec0edf..c9acc407d 100644 --- a/openclaw/config.ts +++ b/openclaw/config.ts @@ -4,33 +4,10 @@ import type { Mem0Config, Mem0Mode } from "./types.ts"; -// ============================================================================ -// Env Var Resolution -// ============================================================================ - -function resolveEnvVars(value: string): string { - return value.replace(/\$\{([^}]+)\}/g, (_, envVar) => { - const envValue = process.env[envVar]; - if (!envValue) { - throw new Error(`Environment variable ${envVar} is not set`); - } - return envValue; - }); -} - -function resolveEnvVarsDeep(obj: Record): Record { - const result: Record = {}; - for (const [key, value] of Object.entries(obj)) { - if (typeof value === "string") { - result[key] = resolveEnvVars(value); - } else if (value && typeof value === "object" && !Array.isArray(value)) { - result[key] = resolveEnvVarsDeep(value as Record); - } else { - result[key] = value; - } - } - return result; -} +// NOTE: No process.env access in this module. OpenClaw resolves ${VAR} +// syntax in openclaw.json before passing pluginConfig to register(). +// Plugin-side env var resolution was removed to clear OpenClaw's +// security scanner warning ("credential harvesting" pattern). // ============================================================================ // Default Custom Instructions & Categories @@ -200,18 +177,16 @@ export const mem0ConfigSchema = { // The plugin should register successfully and log a setup message. const needsSetup = mode === "platform" && (typeof cfg.apiKey !== "string" || !cfg.apiKey); - // Resolve env vars in oss config + // OpenClaw resolves ${VAR} in pluginConfig before register() — no plugin-side expansion needed let ossConfig: Mem0Config["oss"]; if (cfg.oss && typeof cfg.oss === "object" && !Array.isArray(cfg.oss)) { - ossConfig = resolveEnvVarsDeep( - cfg.oss as Record, - ) as unknown as Mem0Config["oss"]; + ossConfig = cfg.oss as Mem0Config["oss"]; } return { mode, apiKey: - typeof cfg.apiKey === "string" ? resolveEnvVars(cfg.apiKey) : undefined, + typeof cfg.apiKey === "string" ? cfg.apiKey : undefined, userId: typeof cfg.userId === "string" && cfg.userId ? cfg.userId : "default", orgId: typeof cfg.orgId === "string" ? cfg.orgId : undefined, diff --git a/openclaw/package.json b/openclaw/package.json index f838830b6..7f4d42406 100644 --- a/openclaw/package.json +++ b/openclaw/package.json @@ -1,6 +1,6 @@ { "name": "@mem0/openclaw-mem0", - "version": "1.0.1", + "version": "1.0.2", "type": "module", "description": "Mem0 memory backend for OpenClaw — platform or self-hosted open-source", "license": "Apache-2.0",