Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
64 commits
Select commit Hold shift + click to select a range
f69bdb7
fix(openclaw): contextualize managed audit findings
chengjiew Jul 9, 2026
61b4c2e
test(openclaw): cover secure loopback audit config
chengjiew Jul 9, 2026
f48b03a
fix(openclaw): keep remote insecure auth findings active
chengjiew Jul 9, 2026
9578a1e
test(openclaw): verify audit suppression contract
chengjiew Jul 9, 2026
0986ad0
test(openclaw): keep audit harness linear
chengjiew Jul 9, 2026
c0f0208
fix(openclaw): keep remote device auth warnings active
chengjiew Jul 9, 2026
6d13451
fix(openclaw): harden audit suppression contract
chengjiew Jul 9, 2026
73d21e8
test(openclaw): cover remote audit findings
chengjiew Jul 9, 2026
340085b
test(openclaw): complete real audit matrix
apurvvkumaria Jul 9, 2026
843ab80
fix(openclaw): keep remote-bind audit findings active
apurvvkumaria Jul 9, 2026
6ba1e2d
docs(security): clarify remote dashboard audit scope
apurvvkumaria Jul 9, 2026
81f75cd
fix(openclaw): align remote bind audit lifecycle
chengjiew Jul 9, 2026
1b5f2ac
refactor(onboard): keep registration entrypoint neutral
chengjiew Jul 9, 2026
742fc16
fix(openclaw): prepare remote dashboard posture
chengjiew Jul 9, 2026
16e8a32
test(openclaw): keep remote lifecycle checks linear
chengjiew Jul 9, 2026
ef1d379
fix(onboard): require remote bind contract
chengjiew Jul 9, 2026
5123111
fix(onboard): persist verified remote bind state
chengjiew Jul 9, 2026
90e8cce
fix(openclaw): verify remote dashboard bind contract
prekshivyas Jul 10, 2026
61ab1ba
Merge remote-tracking branch 'origin/main' into fix/6024_openclaw_sec…
prekshivyas Jul 10, 2026
e37befe
test(openclaw): include remote bind metadata in mocks
prekshivyas Jul 10, 2026
0b67c10
Merge branch 'main' into fix/6024_openclaw_security_audit
prekshivyas Jul 10, 2026
16b671d
ci: provision ripgrep for advisor tool shards
prekshivyas Jul 10, 2026
721946a
fix(onboard): require final-stage remote dashboard bind proof
prekshivyas Jul 10, 2026
505b6c6
fix(onboard): reject remote bind config overwrites
prekshivyas Jul 10, 2026
9843ecc
docs(troubleshooting): split remote bind guidance lines
prekshivyas Jul 10, 2026
2c86279
Merge remote-tracking branch 'upstream/main' into HEAD
prekshivyas Jul 10, 2026
07771a9
test(sandbox): budget MCP status subprocess suite
prekshivyas Jul 10, 2026
e86fd8c
test(e2e): wait for dashboard remote bind proof
prekshivyas Jul 10, 2026
cc57a96
test(e2e): keep dashboard proof wait linear
prekshivyas Jul 10, 2026
8967b47
test(e2e): accept dashboard connect background proof
prekshivyas Jul 10, 2026
b7ac87e
test(e2e): document dashboard remote bind parity
prekshivyas Jul 10, 2026
ff15660
test(e2e): accept dashboard forward proof on stderr
prekshivyas Jul 10, 2026
f44b5ec
fix(onboard): fail closed on remote bind rewrites
prekshivyas Jul 10, 2026
63ae5a2
fix(onboard): fail closed on remote bind config rewrites
prekshivyas Jul 10, 2026
4568f0b
Merge remote-tracking branch 'upstream/main' into HEAD
prekshivyas Jul 10, 2026
9e01332
Merge remote-tracking branch 'upstream/fix/6024_openclaw_security_aud…
prekshivyas Jul 10, 2026
5bccefc
Merge remote-tracking branch 'upstream/main' into fix/6024_openclaw_s…
prekshivyas Jul 10, 2026
fa3d143
fix(security): harden remote bind and auth provenance
prekshivyas Jul 10, 2026
24006e1
fix(security): require exact managed proxy patch
prekshivyas Jul 10, 2026
81982b9
Merge branch 'main' into fix/6024_openclaw_security_audit
cjagwani Jul 10, 2026
e1e9e04
fix(security): verify remote forward state
prekshivyas Jul 10, 2026
9286e81
fix(security): reject custom remote dashboard builds
prekshivyas Jul 10, 2026
5505720
Merge remote-tracking branch 'upstream/main' into fix/6024_openclaw_s…
prekshivyas Jul 10, 2026
701fe7d
fix(security): harden remote dashboard bind contracts
prekshivyas Jul 10, 2026
eda1c70
Merge remote-tracking branch 'upstream/main' into fix/6024_openclaw_s…
prekshivyas Jul 10, 2026
932d3ba
test(security): make remote bind evidence explicit
prekshivyas Jul 10, 2026
ca35daf
Merge remote-tracking branch 'upstream/main' into fix/6024_openclaw_s…
prekshivyas Jul 10, 2026
bcd744e
Merge remote-tracking branch 'upstream/main' into fix/6024_openclaw_s…
prekshivyas Jul 10, 2026
f3d0334
refactor(onboard): keep dashboard contract isolated
prekshivyas Jul 11, 2026
2e59b3d
test(onboard): cover remote bind restart edges
prekshivyas Jul 11, 2026
bdc36f0
Merge branch 'main' into fix/6024_openclaw_security_audit
cv Jul 11, 2026
d0c1866
fix(onboard): refresh dashboard bind trust digest
cv Jul 11, 2026
7c7f47c
fix(connect): restore loopback dashboard forwarding
cv Jul 11, 2026
20ec7ef
merge(main): sync current release target
cv Jul 11, 2026
d1aef53
fix(connect): preserve WSL dashboard forwarding
cv Jul 11, 2026
277ef58
merge(main): sync current release target
cv Jul 11, 2026
59e89de
fix(security): preserve WSL dashboard audit findings
cv Jul 11, 2026
2bd260c
merge(main): sync current release target
cv Jul 11, 2026
94b7128
fix(onboard): keep legacy Dockerfiles compatible
cv Jul 11, 2026
6eb0794
Merge branch 'main' into fix/6024_openclaw_security_audit
cv Jul 11, 2026
fa3d7d0
Merge branch 'main' into fix/6024_openclaw_security_audit
cv Jul 11, 2026
baba0bd
fix(connect): honor requested dashboard bind
cv Jul 11, 2026
95b9d34
test(connect): keep remote recovery setup linear
cv Jul 11, 2026
31edc93
merge(main): sync current release target
cv Jul 12, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 5 additions & 1 deletion .github/workflows/base-image.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -97,7 +97,11 @@ jobs:
openclaw_build_arg="OPENCLAW_VERSION=${OPENCLAW_VERSION_INPUT}"
build_args+=(--build-arg "$openclaw_build_arg")
fi
scripts/check-production-build-args.sh "${build_args[@]}"
if [ "${#build_args[@]}" -gt 0 ]; then
scripts/check-production-build-args.sh "${build_args[@]}"
else
scripts/check-production-build-args.sh
fi
if [ -n "${OPENCLAW_VERSION_INPUT}" ]; then
if [[ "$OPENCLAW_VERSION_INPUT" == *$'\r'* || "$OPENCLAW_VERSION_INPUT" == *$'\n'* ]]; then
echo "ERROR: OpenClaw version must not contain CR or LF characters." >&2
Expand Down
7 changes: 6 additions & 1 deletion .github/workflows/main.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -59,7 +59,7 @@ jobs:

real-openclaw-dist-harness:
runs-on: ubuntu-latest
timeout-minutes: 12
timeout-minutes: 20
env:
# This required proof reads reviewed npm metadata/tarballs. Keep npm's
# transient-registry retry policy explicit at the hard merge boundary.
Expand All @@ -86,6 +86,11 @@ jobs:
NEMOCLAW_REAL_OPENCLAW_DIST_HARNESS: "1"
run: npx vitest run --project integration test/openclaw-real-patched-dist-harness.test.ts --silent=false --reporter=default

- name: Audit managed OpenClaw security finding suppressions
env:
NEMOCLAW_REAL_OPENCLAW_AUDIT_HARNESS: "1"
run: npx vitest run --project integration test/openclaw-security-audit-suppressions-real.test.ts --silent=false --reporter=default

cli-test-shards:
runs-on: ubuntu-latest
timeout-minutes: 10
Expand Down
10 changes: 10 additions & 0 deletions Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -838,6 +838,10 @@ ARG NEMOCLAW_UPSTREAM_PROVIDER=
ARG NEMOCLAW_PRIMARY_MODEL_REF=inference/nvidia/nemotron-3-super-120b-a12b
# Default dashboard port 18789 — override at runtime via NEMOCLAW_DASHBOARD_PORT.
ARG CHAT_UI_URL=http://127.0.0.1:18789
ARG NEMOCLAW_DASHBOARD_BIND=
# Internal audit provenance for WSL's default all-interface dashboard forward.
# Onboarding rewrites this for managed OpenClaw images built on WSL.
ARG NEMOCLAW_WSL_DASHBOARD_EXPOSURE=0
ARG NEMOCLAW_INFERENCE_BASE_URL=https://inference.local/v1
ARG NEMOCLAW_INFERENCE_API=openai-completions
ARG NEMOCLAW_CONTEXT_WINDOW=131072
Expand Down Expand Up @@ -876,6 +880,9 @@ ARG NEMOCLAW_EXTRA_AGENTS_JSON_B64=W10=
# since terminal-based pairing is impossible in those contexts.
# Default: "0" (device auth enabled for local deployments — secure by default).
ARG NEMOCLAW_DISABLE_DEVICE_AUTH=0
# Internal audit provenance for the opt-out above. Standard onboarding rewrites
# this to managed-onboard; direct image builders retain operator provenance.
ARG NEMOCLAW_DEVICE_AUTH_OPT_OUT_SOURCE=operator
# Compatibility build arg for older custom Dockerfiles and rebuild tooling.
# NemoClaw-managed images intentionally do not consume it; gateway auth tokens
# are generated at container startup and are never baked into image layers.
Expand Down Expand Up @@ -932,7 +939,10 @@ ENV NEMOCLAW_MODEL=${NEMOCLAW_MODEL} \
NEMOCLAW_MESSAGING_PLAN_B64=${NEMOCLAW_MESSAGING_PLAN_B64} \
NEMOCLAW_EXTRA_AGENTS_JSON_B64=${NEMOCLAW_EXTRA_AGENTS_JSON_B64} \
NEMOCLAW_OPENCLAW_WECHAT_PLUGIN_PREINSTALLED=1 \
NEMOCLAW_DASHBOARD_BIND=${NEMOCLAW_DASHBOARD_BIND} \
NEMOCLAW_WSL_DASHBOARD_EXPOSURE=${NEMOCLAW_WSL_DASHBOARD_EXPOSURE} \
NEMOCLAW_DISABLE_DEVICE_AUTH=${NEMOCLAW_DISABLE_DEVICE_AUTH} \
NEMOCLAW_DEVICE_AUTH_OPT_OUT_SOURCE=${NEMOCLAW_DEVICE_AUTH_OPT_OUT_SOURCE} \
NEMOCLAW_PROXY_HOST=${NEMOCLAW_PROXY_HOST} \
NEMOCLAW_PROXY_PORT=${NEMOCLAW_PROXY_PORT} \
NEMOCLAW_WEB_SEARCH_ENABLED=${NEMOCLAW_WEB_SEARCH_ENABLED} \
Expand Down
6 changes: 4 additions & 2 deletions docs/get-started/quickstart.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -151,7 +151,8 @@ Use these details when your first-run path needs more control.
</Accordion>

<Accordion title="Open the dashboard from a remote host">
The dashboard binds to `127.0.0.1` on the host running NemoClaw.
Outside WSL, the dashboard forward binds to `127.0.0.1` on the host running NemoClaw.
On WSL, it binds on all interfaces so the Windows host can reach it, while the ready summary still prints a loopback dashboard URL.
When you connect over SSH, forward the dashboard port from your workstation, substituting the port from the ready summary.

```bash
Expand Down Expand Up @@ -200,7 +201,8 @@ Use these details when your first-run path needs more control.
If it cannot find the binary or blocking host preflight checks fail, it prints diagnostics and a `To finish setup, run:` block with the explicit `nemoclaw onboard` command.

<Note>
Onboarding builds the sandbox image with `NEMOCLAW_DISABLE_DEVICE_AUTH=1` so the dashboard is usable during setup.
Onboarding builds the sandbox image with a managed `NEMOCLAW_DISABLE_DEVICE_AUTH=1` compatibility setting so the dashboard is usable during setup.
NemoClaw records that this value came from onboarding rather than reporting it as an operator-selected opt-out.
This build-time setting is baked into the image and setting it after onboarding does not affect an existing sandbox.
</Note>
</Accordion>
Expand Down
2 changes: 2 additions & 0 deletions docs/manage-sandboxes/lifecycle.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -118,6 +118,8 @@ If the forward stopped, or the installer reported that no active forward was fou
openshell forward start --background <dashboard-port> my-gpt-claw
```

On WSL, use `0.0.0.0:<dashboard-port>` as the forward target so the Windows host can continue to reach the dashboard.

To list active forwards across all sandboxes, run the following command.

```bash
Expand Down
2 changes: 1 addition & 1 deletion docs/manage-sandboxes/runtime-controls.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -32,7 +32,7 @@ The following table maps each commonly changed item to the layer that owns it an
| Channel tokens (Slack / Discord / Telegram bot credentials) | Rebuild required (tokens are baked into the sandbox image at onboard so they never leave the host clear-text) | `$$nemoclaw <name> channels add <channel>` then accept the rebuild prompt |
| Channel enable/disable (turn a configured channel off without removing the token) | Rebuild required (`openclaw.json` is the source of truth at runtime, refer to #3453) | `$$nemoclaw <name> channels stop <channel>` then rebuild |
| Dashboard forward port | Runtime. Port is re-resolved on next `connect` | `NEMOCLAW_DASHBOARD_PORT=<port> $$nemoclaw <name> connect` |
| Dashboard bind address (loopback compared to all interfaces) | Runtime. Applies on next `connect` | `NEMOCLAW_DASHBOARD_BIND=0.0.0.0 $$nemoclaw <name> connect` (refer to #3259) |
| Dashboard bind address (loopback compared to all interfaces) | Build and runtime. Requires onboarding with the same remote-bind opt-in before `connect` can expose an existing sandbox | `NEMOCLAW_DASHBOARD_BIND=0.0.0.0 $$nemoclaw onboard --recreate-sandbox` for an existing local-only sandbox, then use `NEMOCLAW_DASHBOARD_BIND=0.0.0.0 $$nemoclaw <name> connect` later (refer to #3259) |
| Gateway process environment or startup-only plugin state | Runtime after gateway restart | `$$nemoclaw <name> gateway restart` |
| Default OpenClaw workspace template seed (`AGENTS.md`, `SOUL.md`, `IDENTITY.md`, `USER.md`, `TOOLS.md`, `HEARTBEAT.md`) | Locked at first sandbox boot. Re-onboard required to change the bake-time choice. | Set `NEMOCLAW_MINIMAL_BOOTSTRAP=1` before `$$nemoclaw onboard` to skip default template seeding for new/pristine workspaces. **Does not delete files already present.** Partial mitigation for #2598 (cuts ~3k tokens of project-context overhead off OpenClaw's per-turn bootstrap injection). |
| Web search provider (Brave, Tavily, or disabled) | Rebuild required. Onboarding bakes the provider plugin configuration and credential attachment into the image. | Set `NEMOCLAW_WEB_SEARCH_PROVIDER=brave`, `tavily`, or `none`, rerun `$$nemoclaw onboard`, and accept recreation or pass `--recreate-sandbox`. |
Expand Down
9 changes: 5 additions & 4 deletions docs/reference/commands.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -3115,7 +3115,7 @@ Passthrough commands do not consume flags intended for the downstream command as
| `NEMOCLAW_OLLAMA_PROXY_PORT` | 11435 | Ollama auth proxy |
| `NEMOCLAW_OPENROUTER_RUNTIME_ADAPTER_PORT` | 11437 | Host-side OpenRouter runtime adapter |
<AgentOnly variant="openclaw,hermes">
| `NEMOCLAW_DASHBOARD_BIND` | *unset* (loopback) | Dashboard or API forward bind address. Set to `0.0.0.0` to opt in to remote bind for SSH-deployed hosts. |
| `NEMOCLAW_DASHBOARD_BIND` | *unset* (loopback outside WSL) | Dashboard or API forward bind address. WSL uses an all-interface forward for Windows-host reachability. Set to `0.0.0.0` to opt in to remote bind on other SSH-deployed hosts. |
</AgentOnly>
<AgentOnly variant="openclaw">
| `NEMOCLAW_GATEWAY_WS_HOST` | *unset* (auto-derived inside the sandbox; loopback elsewhere) | Host used for the in-sandbox `OPENCLAW_GATEWAY_URL`; inside the sandbox it defaults to the primary interface address so `sessions_spawn` sub-agents can dial the gateway through the enforced network path. |
Expand All @@ -3133,9 +3133,10 @@ If you run Ollama on port 11435, set `NEMOCLAW_OLLAMA_PROXY_PORT` to another fre
Keep the OpenShell gateway on loopback and use `NEMOCLAW_DASHBOARD_BIND` when you need remote browser/API access.

`NEMOCLAW_DASHBOARD_BIND` controls the dashboard or API port forward bind address.
By default the forward stays on `127.0.0.1` (loopback only).
Set `NEMOCLAW_DASHBOARD_BIND=0.0.0.0` before `$$nemoclaw onboard` (or `$$nemoclaw <sandbox> connect`) to bind the forward on all interfaces, which is useful when the host is reached over SSH or a cloud workstation.
Only `0.0.0.0` enables the remote bind; other values are ignored.
Outside WSL, the forward stays on `127.0.0.1` (loopback only) by default.
On WSL, NemoClaw binds the host-side forward on all interfaces so the Windows host can reach it, while the ready summary continues to print a loopback dashboard URL.
Set `NEMOCLAW_DASHBOARD_BIND=0.0.0.0` before `$$nemoclaw onboard` to prepare the sandbox for remote exposure and bind the forward on all interfaces. Use the same setting for later `$$nemoclaw <sandbox> connect` calls. A sandbox created without this opt-in must be recreated with `NEMOCLAW_DASHBOARD_BIND=0.0.0.0 $$nemoclaw onboard --recreate-sandbox` before a remote-bind connect is allowed.
Only `0.0.0.0` enables the remote bind; onboarding rejects any other non-empty value.
</AgentOnly>

<AgentOnly variant="openclaw">
Expand Down
3 changes: 3 additions & 0 deletions docs/reference/troubleshooting.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -301,6 +301,9 @@ Remote/headless hosts should keep the OpenShell gateway on loopback and bind the
NEMOCLAW_DASHBOARD_BIND=0.0.0.0 NEMOCLAW_GATEWAY_PORT=8990 $$nemoclaw onboard
```

Use `NEMOCLAW_DASHBOARD_BIND=0.0.0.0` again on later `$$nemoclaw <sandbox> connect` calls.
If the sandbox was originally created without remote bind, recreate it with the same onboard command plus `--recreate-sandbox` before connecting remotely.

Docker-driver gateways on OpenShell 0.0.72 reject `NEMOCLAW_GATEWAY_BIND_ADDRESS=0.0.0.0` while gateway JWT auth is active.

Use `NEMOCLAW_GATEWAY_BIND_ADDRESS=0.0.0.0` only on supported gateway modes and only when other hosts on the network should be able to reach the gateway.
Expand Down
31 changes: 27 additions & 4 deletions docs/security/best-practices.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -643,10 +643,10 @@ Device authentication requires each connecting device to go through a pairing fl

| Aspect | Detail |
|---|---|
| Default | Enabled. The gateway requires device pairing for all connections. |
| What you can change | Set `NEMOCLAW_DISABLE_DEVICE_AUTH=1` as a Docker build argument to disable device authentication. This is a build-time setting baked into `openclaw.json` and verified by hash at startup. |
| Default | The base Dockerfile enables device authentication for loopback dashboards. Standard onboarding currently applies a managed compatibility opt-out for immediate dashboard access. NemoClaw also disables device authentication for non-loopback `CHAT_UI_URL` values. |
| What you can change | Outside managed onboarding, set `NEMOCLAW_DISABLE_DEVICE_AUTH=1` only as a deliberate build-time opt-out. The setting and its managed-vs-operator provenance are baked into `openclaw.json` audit metadata and the config is verified by hash at startup. |
| Risk if relaxed | Disabling device auth allows any device on the network to connect to the gateway without proving identity. This is dangerous when combined with LAN-bind changes or cloudflared tunnels in remote deployments, resulting in an unauthenticated, publicly reachable dashboard. |
| Recommendation | Keep device auth enabled (the default). Only disable it for headless or development environments where no untrusted devices can reach the gateway. |
| Recommendation | Prefer loopback access or SSH port forwarding so device authentication stays enabled. If a browser-only remote dashboard requires the compatibility setting, use HTTPS and restrict who can reach the dashboard. |

### Gateway Bind Address

Expand All @@ -655,7 +655,7 @@ NemoClaw binds the OpenShell gateway to loopback by default.
| Aspect | Detail |
|---|---|
| Default | `NEMOCLAW_GATEWAY_BIND_ADDRESS=127.0.0.1`. |
| What you can change | Keep Docker-driver gateways on loopback. Set `NEMOCLAW_DASHBOARD_BIND=0.0.0.0` for remote dashboard/API access. |
| What you can change | Keep Docker-driver gateways on loopback. Set `NEMOCLAW_DASHBOARD_BIND=0.0.0.0` during onboarding and on later `connect` calls for remote dashboard/API access. Recreate a local-only sandbox before changing it to a remote bind. |
| Risk if relaxed | Other hosts on the network may be able to reach the OpenShell gateway; Docker-driver gateways on OpenShell 0.0.72 reject wildcard gateway binds while gateway JWT auth is active. |
| Recommendation | Keep the gateway loopback default and expose only the dashboard forward when remote access is needed. |

Expand Down Expand Up @@ -683,6 +683,29 @@ The `allowInsecureAuth` setting controls whether the gateway permits non-HTTPS a
| Risk if relaxed | Allowing insecure auth over HTTPS defeats the purpose of TLS, because authentication tokens transit in cleartext. |
| Recommendation | Use `https://` for any deployment accessible beyond `localhost`. The default local URL (`http://127.0.0.1:18789`) correctly allows insecure auth for local development. |

OpenClaw's security audit keeps NemoClaw-managed loopback `allowInsecureAuth` findings and provenance-known loopback device-auth opt-out findings visible as accepted findings instead of counting them as unexplained active findings.
Device-auth findings record whether the opt-out came from NemoClaw's managed onboarding compatibility behavior or an operator-provided `NEMOCLAW_DISABLE_DEVICE_AUTH=1`; an opt-out with missing provenance remains active.
For audit reporting, NemoClaw treats a non-loopback `CHAT_UI_URL`, an onboard-time `NEMOCLAW_DASHBOARD_BIND=0.0.0.0`, or WSL's default all-interface dashboard forward as remote dashboard exposure.
For an explicit `NEMOCLAW_DASHBOARD_BIND=0.0.0.0` bind, use the same setting on later `connect` calls.
If the sandbox was created without that explicit setting, NemoClaw refuses the remote forward until you recreate it with `NEMOCLAW_DASHBOARD_BIND=0.0.0.0 $$nemoclaw onboard --recreate-sandbox`; this keeps the generated audit state aligned with the host exposure state.
On WSL, the ready summary still uses a loopback URL, but the generated audit configuration leaves the device-auth and insecure-auth findings active.
For an explicit remote bind with a loopback `CHAT_UI_URL`, NemoClaw disables device auth and enables OpenClaw's Host-header origin fallback because the browser's remote origin is not known at image-build time. Both settings expand access and must remain explicit; use HTTPS or an SSH local forward when possible.
In that state, NemoClaw does not add the loopback-only audit suppressions, so the resulting device-auth, insecure-auth, and Host-header fallback findings remain active.
The generated configuration uses exact audit check IDs and flag details, records why each setting is present, and leaves the original severity and remediation under `suppressedFindings` in JSON output.
The audit also reports that suppressions are active so you can review the accepted risk.
These suppressions change audit reporting only.
They do not make either flag safe, weaken enforcement, or suppress unrelated findings.

Review the accepted findings and their recorded reasons:

```bash
openclaw security audit --json | jq '.suppressedFindings'
```

Remove the underlying risky condition when dashboard compatibility no longer requires it.
Remove these suppressions only after the pinned OpenClaw audit contract test proves that OpenClaw natively classifies intentional loopback development HTTP without them, or after NemoClaw onboarding defaults `CHAT_UI_URL` to `https://localhost` with a generated local certificate.
Regression contracts: `test/generate-openclaw-config-security-audit.test.ts` locks generated suppression scope, `test/openclaw-security-audit-suppressions-real.test.ts` locks the pinned OpenClaw check IDs and details, and `test/e2e/live/dashboard-remote-bind.test.ts` proves a clean-host remote bind leaves all three risky findings active. The preceding removal condition applies to all three contracts.

### Auto-Pair Client Allowlist

The auto-pair watcher automatically approves device pairing requests from recognized clients, so you do not need to manually approve the Control UI.
Expand Down
Loading
Loading