fix(security): enforce workspaceOnly for sandbox image tool

This commit is contained in:
Peter Steinberger
2026-02-24 02:17:06 +00:00
parent 0026255def
commit dd9d9c1c60
5 changed files with 129 additions and 2 deletions

View File

@@ -41,6 +41,7 @@ export function createOpenClawTools(options?: {
agentDir?: string;
sandboxRoot?: string;
sandboxFsBridge?: SandboxFsBridge;
workspaceOnly?: boolean;
workspaceDir?: string;
sandboxed?: boolean;
config?: OpenClawConfig;
@@ -78,6 +79,7 @@ export function createOpenClawTools(options?: {
options?.sandboxRoot && options?.sandboxFsBridge
? { root: options.sandboxRoot, bridge: options.sandboxFsBridge }
: undefined,
workspaceOnly: options?.workspaceOnly,
modelHasVision: options?.modelHasVision,
})
: null;