fix(openclaw): remove process.env access to clear security scanner warning (#4676)

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
Chaithanya Kumar
2026-04-02 21:19:12 +05:30
committed by GitHub
parent c53f1f126d
commit 9cd3d2cca8
2 changed files with 8 additions and 33 deletions
+7 -32
View File
@@ -4,33 +4,10 @@
import type { Mem0Config, Mem0Mode } from "./types.ts"; import type { Mem0Config, Mem0Mode } from "./types.ts";
// ============================================================================ // NOTE: No process.env access in this module. OpenClaw resolves ${VAR}
// Env Var Resolution // syntax in openclaw.json before passing pluginConfig to register().
// ============================================================================ // Plugin-side env var resolution was removed to clear OpenClaw's
// security scanner warning ("credential harvesting" pattern).
function resolveEnvVars(value: string): string {
return value.replace(/\$\{([^}]+)\}/g, (_, envVar) => {
const envValue = process.env[envVar];
if (!envValue) {
throw new Error(`Environment variable ${envVar} is not set`);
}
return envValue;
});
}
function resolveEnvVarsDeep(obj: Record<string, unknown>): Record<string, unknown> {
const result: Record<string, unknown> = {};
for (const [key, value] of Object.entries(obj)) {
if (typeof value === "string") {
result[key] = resolveEnvVars(value);
} else if (value && typeof value === "object" && !Array.isArray(value)) {
result[key] = resolveEnvVarsDeep(value as Record<string, unknown>);
} else {
result[key] = value;
}
}
return result;
}
// ============================================================================ // ============================================================================
// Default Custom Instructions & Categories // Default Custom Instructions & Categories
@@ -200,18 +177,16 @@ export const mem0ConfigSchema = {
// The plugin should register successfully and log a setup message. // The plugin should register successfully and log a setup message.
const needsSetup = mode === "platform" && (typeof cfg.apiKey !== "string" || !cfg.apiKey); const needsSetup = mode === "platform" && (typeof cfg.apiKey !== "string" || !cfg.apiKey);
// Resolve env vars in oss config // OpenClaw resolves ${VAR} in pluginConfig before register() — no plugin-side expansion needed
let ossConfig: Mem0Config["oss"]; let ossConfig: Mem0Config["oss"];
if (cfg.oss && typeof cfg.oss === "object" && !Array.isArray(cfg.oss)) { if (cfg.oss && typeof cfg.oss === "object" && !Array.isArray(cfg.oss)) {
ossConfig = resolveEnvVarsDeep( ossConfig = cfg.oss as Mem0Config["oss"];
cfg.oss as Record<string, unknown>,
) as unknown as Mem0Config["oss"];
} }
return { return {
mode, mode,
apiKey: apiKey:
typeof cfg.apiKey === "string" ? resolveEnvVars(cfg.apiKey) : undefined, typeof cfg.apiKey === "string" ? cfg.apiKey : undefined,
userId: userId:
typeof cfg.userId === "string" && cfg.userId ? cfg.userId : "default", typeof cfg.userId === "string" && cfg.userId ? cfg.userId : "default",
orgId: typeof cfg.orgId === "string" ? cfg.orgId : undefined, orgId: typeof cfg.orgId === "string" ? cfg.orgId : undefined,
+1 -1
View File
@@ -1,6 +1,6 @@
{ {
"name": "@mem0/openclaw-mem0", "name": "@mem0/openclaw-mem0",
"version": "1.0.1", "version": "1.0.2",
"type": "module", "type": "module",
"description": "Mem0 memory backend for OpenClaw — platform or self-hosted open-source", "description": "Mem0 memory backend for OpenClaw — platform or self-hosted open-source",
"license": "Apache-2.0", "license": "Apache-2.0",