Repository navigation
fix(dashboard): guard non-string apiKey in CLI tool cards - #10872
Merged
diegosouzapw merged 1 commit intoAug 21, 2026
Merged
diegosouzapw merged 1 commit into
diegosouzapw merged 1 commit into
Conversation
The masked-key matching from (diegosouzapw#523) called `apiKey.slice(0, 8)` behind a bare truthiness check. CLIs may store the provider key as a structured secret reference object instead of a plaintext string — OpenClaw's SecretRef, for example: "apiKey": { "source": "file", "provider": "default", "id": "/KEY" } An object is truthy, so `.slice()` threw `TypeError: apiKey.slice is not a function`, the React error boundary caught it, and the whole /dashboard/cli-agents/openclaw page rendered as "Internal Server Error" (a client-side crash, not an actual server 500). Narrow the check to `typeof apiKey === "string"` in all four affected cards: OpenClaw, Droid, Cline and Kilo. When the key is a reference the card simply skips pre-selecting the matching API key, which is the correct behaviour — there is no plaintext key to match against.
muhamadgalihsaputra
pushed a commit
to niyatna/NiyatnaRoute
that referenced
this pull request
Sep 27, 2026
…pw#10872) Validado no worktree combinado do lote: typecheck:core, lint, gates de qualidade e o novo teste OpenClawToolCard-secret-ref-apikey.test.tsx (via vitest) verdes. Correção real e bem isolada de um crash client-side (`e.apiKey.slice is not a function`). CI vermelho neste PR é o base-red já rastreado em diegosouzapw#9985. Obrigado!
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Opening
/dashboard/cli-agents/openclawrenders the error boundary — the page shows:This is misleading: the server render succeeds (the route returns HTTP 200 with full HTML/RSC). It is a client-side crash:
Cause
The masked-key matching added in (#523) reads the provider
apiKeyout of the CLI's own config file and matches it against the masked keys from/api/keysby prefix/suffix:That assumes
apiKeyis always a plaintext string. It isn't. CLIs increasingly support structured secret references so the key never has to sit in plaintext on disk. OpenClaw calls these SecretRefs, and~/.openclaw/openclaw.jsonthen contains:An object is truthy, so the guard passes and
.slice()throws, taking the whole page down. Anyone who externalises their key instead of pasting it in plaintext hits this.Reproduced on the published
omniroute@3.8.49against OpenClaw2026.7.1-2.Fix
Narrow the guard to
typeof apiKey === "string"in the four cards that share this pattern:OpenClawToolCard.tsxDroidToolCard.tsxClineToolCard.tsxKiloToolCard.tsxWhen the key is a reference, the card skips pre-selecting a matching API key — the correct behaviour, since there is no plaintext value to match against. Everything else on the card renders normally.
Only OpenClaw is confirmed crashing in the wild today; the other three are the identical unguarded pattern and are fixed pre-emptively.
Test
tests/unit/ui/OpenClawToolCard-secret-ref-apikey.test.tsxrenders the card with an object-shapedapiKeyand asserts no error escapes.Verified TDD-style: the test fails on the unpatched component with
TypeError: provider.apiKey.slice is not a functionthrown from theuseEffect, and passes with the guard.ESLint and Prettier are clean on all five files.