Skip to content

feat(notify): 支持微信Claw - #560

Merged
HarcoChen merged 9 commits into
AUTO-MAS-Project:devfrom
HarcoChen:feat/notify-claw
Sep 5, 2026
Merged

feat(notify): 支持微信Claw#560
HarcoChen merged 9 commits into
AUTO-MAS-Project:devfrom
HarcoChen:feat/notify-claw

Conversation

@HarcoChen

@HarcoChen HarcoChen commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

支持微信claw作为通知渠道,接入通知中心

Sourcery 摘要

通过通知中心支持可配置的微信(OpenClaw/iLink)通知。

新功能:

  • 添加微信(OpenClaw/iLink)作为可配置的通知渠道,用于向目标用户发送文本消息。
  • 在后端配置架构和通知设置界面中公开微信 iLink 通知设置,并提供中文和英文本地化支持。

增强:

  • 将微信 iLink 投递集成到通知目标发现、渠道报告和分发处理流程中。

杂项:

  • 更新前端 API 模型和后端版本元数据。
Original summary in English

Sourcery 总结

通过二维码绑定和通知中心,启用 WeChat Claw/iLink 通知。

新功能:

  • 添加 WeChat Claw/iLink 作为可配置的通知渠道,支持二维码账户绑定、状态管理和解绑。
  • 提供通知设置界面以及本地化用户指引,用于配置 WeChat Claw 通知。

增强功能:

  • 将 WeChat 消息投递集成到通知目标发现、渠道报告、分发、长消息处理和后台会话维护中。
  • 支持平台感知的凭据存储,并在加密密钥存储不可用时提供运行时回退机制。

测试:

  • 扩展平台测试,以验证不受支持平台上的密钥存储能力检测。

维护工作:

  • 为新增的 WeChat Claw 端点和配置架构重新生成前端 API 模型与服务。
  • 更新后端版本元数据和健康检查 API 模型字段。
Original summary in English

Sourcery 摘要

将基于二维码绑定的微信 Claw/iLink 和 QQ 官方机器人渠道集成到通知中心。

新功能:

  • 为微信 Claw/iLink 和 QQ 官方机器人渠道添加二维码绑定和通知发送功能。
  • 在通知设置 UI 中提供微信和 QQ 通知控制、绑定状态、扫码登录、重新绑定和解绑功能。
  • 维护微信 iLink 会话和 QQ 访问令牌,以支持可靠的出站消息发送,包括长消息处理。

错误修复:

  • 在活动任务界面中将通知渠道故障显示为警告。
  • 当平台提供的安全存储不可用时,避免以明文形式持久化渠道密钥。

增强功能:

  • 将新渠道集成到通知目标发现、渠道报告、分发、生命周期管理和配置处理中。
  • 添加平台感知的安全存储能力检测,并支持运行时凭据回退。

文档:

  • 添加中文、英文和日文版本的微信 Claw 和 QQ 官方机器人设置指南。

测试:

  • 添加任务通知失败报告和不受支持平台的密钥存储检测测试覆盖。

杂项:

  • 为新的绑定端点和更新后的后端健康状态元数据重新生成前端 API 模型和服务。
Original summary in English

Sourcery 摘要

将微信 Claw/iLink 和 QQ 官方机器人集成为通知中心中可通过二维码绑定的通知渠道。

新功能:

  • 为微信 Claw/iLink 和 QQ 官方机器人渠道添加二维码绑定和通知投递功能。
  • 在通知设置中提供微信和 QQ 渠道控制、绑定状态、二维码登录、重新绑定和解绑功能,并提供本地化指导。

Bug 修复:

  • 在活动任务界面中将通知投递失败显示为警告。
  • 当平台安全存储不可用时,避免以明文形式持久化渠道密钥。

增强功能:

  • 将两个渠道集成到通知目标发现、报告、调度、长消息处理、令牌/会话维护和生命周期管理中。
  • 添加与平台相关的密钥存储能力检测,并支持以内存凭据作为回退方案。

文档:

  • 在通知设置界面中添加本地化的微信 Claw 和 QQ 官方机器人设置指南。

测试:

  • 添加对任务通知失败报告、二维码绑定流程、凭据存储模式、令牌缓存、并发处理以及不支持平台的密钥存储的测试覆盖。

日常维护:

  • 为新的绑定端点和更新后的后端健康状态元数据重新生成前端 API 模型和服务。
  • 更新后端版本元数据和健康检查 API 字段。
Original summary in English

Sourcery 总结

将基于二维码绑定的微信 Claw/iLink 和 QQ 官方机器人渠道集成到通知中心。

新功能:

  • 为微信 Claw/iLink 和 QQ 官方机器人添加二维码绑定和通知发送功能。
  • 在通知设置中展示这两个渠道,提供绑定状态、启用控制、解绑、配对码支持和本地化指导。

错误修复:

  • 在任务活动页面中将通知发送失败显示为警告。
  • 当平台安全存储不可用时,避免以明文形式持久化渠道密钥。

增强功能:

  • 将微信和 QQ 的消息发送集成到通知目标发现、消息分发、长消息处理、令牌/会话维护和生命周期管理中。
  • 支持平台感知的凭据存储,并在内存中提供运行时回退;同时自动恢复微信会话上下文和 QQ 访问令牌。

文档:

  • 为微信 Claw 和 QQ 官方机器人通知渠道添加本地化设置指南。

测试:

  • 增加对二维码绑定流程、通知失败报告、凭据存储回退、令牌缓存、并发重新绑定、解绑以及不支持的平台密钥存储检测的测试覆盖。

杂项:

  • 重新生成前端 API 模型和服务,以支持新的绑定端点及更新后的后端健康状态元数据。
  • 更新后端版本元数据。
Original summary in English

Sourcery 摘要

将基于二维码绑定的微信 Claw/iLink 和 QQ 官方 Bot 渠道集成到通知中心,并提供安全的凭据管理和可靠的消息投递。

新功能:

  • 为微信 Claw/iLink 和 QQ 官方 Bot 渠道添加二维码绑定和通知投递功能。
  • 在通知设置 UI 中提供微信和 QQ 的通知控制、绑定状态、二维码登录、重新绑定和解绑流程。
  • 维护平台专属的渠道凭据、访问令牌和微信会话上下文,以确保可靠的出站消息投递。

错误修复:

  • 在任务活动视图中将通知投递失败显示为警告。
  • 当平台安全存储不可用时,避免以明文形式持久化渠道密钥。

增强功能:

  • 将新渠道集成到通知目标发现、分发、报告、长消息处理和后台生命周期管理中。
  • 当不支持加密存储时,添加自动会话和令牌恢复功能,并在运行时回退到凭据。

文档:

  • 在通知设置 UI 中添加本地化的微信 Claw 和 QQ 官方 Bot 设置指南。

测试:

  • 添加对二维码绑定流程、通知失败报告、凭据存储回退、令牌缓存、并发处理以及不支持平台的密钥存储检测的测试覆盖。

维护:

  • 为新的绑定端点和更新后的后端健康状态元数据重新生成前端 API 模型和服务。
  • 更新后端版本元数据。
Original summary in English

Sourcery 摘要

将微信 Claw/iLink 和 QQ 官方机器人集成为通知中心中支持二维码绑定的通知渠道。

新功能:

  • 为微信 Claw/iLink 和 QQ 官方机器人渠道添加二维码绑定和通知发送功能。
  • 在通知设置中提供绑定状态、启用、重新绑定、解绑、配对码和本地化设置流程。

错误修复:

  • 在任务活动视图中将通知发送失败显示为警告。
  • 当平台安全存储不可用时,避免以明文形式持久化渠道密钥。

增强功能:

  • 将新渠道集成到通知目标发现、报告、分发、长消息处理、令牌/会话维护和生命周期管理中。
  • 支持平台感知的凭据存储,并在运行时以内存存储作为回退方案,同时自动维护微信会话上下文。

文档:

  • 添加微信 Claw 和 QQ 官方机器人渠道的本地化通知设置指南。

测试:

  • 添加对二维码绑定流程、通知失败报告、凭据存储回退、令牌缓存、并发处理以及不支持平台的安全存储检测的测试覆盖。

杂项:

  • 为新的绑定端点和更新后的后端健康状态元数据重新生成前端 API 模型和服务。
  • 更新后端版本元数据。
Original summary in English

Sourcery 总结

将微信 Claw/iLink 和 QQ 官方机器人频道集成到通知中心,提供可靠的消息投递和安全的凭据管理。

新功能:

  • 为微信 Claw/iLink 和 QQ 官方机器人频道添加二维码绑定和通知投递功能。
  • 在通知设置中提供频道绑定状态、启用、重新绑定和解绑流程,并提供本地化指引。

错误修复:

  • 在任务活动视图中将任务通知投递失败显示为警告。
  • 当平台安全存储不可用时,避免以明文形式持久化频道密钥。

增强功能:

  • 将新频道集成到通知目标发现、投递报告、长消息处理,以及凭据和会话生命周期管理中。
  • 支持感知平台的安全凭据存储,并提供仅运行时存储的回退方案以及令牌/会话恢复功能。

文档:

  • 添加微信 Claw 和 QQ 官方机器人通知的本地化设置指南。

测试:

  • 增加对二维码绑定流程、通知失败报告、凭据存储回退、令牌缓存、并发处理以及不支持平台的安全存储检测的测试覆盖。

日常维护:

  • 为新的绑定端点和健康状态元数据重新生成前端 API 模型和服务。
  • 更新后端版本元数据。
Original summary in English

Sourcery 摘要

将微信 Claw/iLink 和 QQ 官方机器人集成为支持二维码绑定的通知渠道,并实现安全的凭据处理和可靠的消息投递。

新功能:

  • 为微信 Claw/iLink 和 QQ 官方机器人渠道添加二维码绑定和通知投递功能。
  • 在通知设置中提供渠道状态、绑定、重新绑定、解绑和启用控制,并提供本地化指引。

Bug 修复:

  • 在任务活动视图中将任务通知投递失败显示为警告。
  • 当平台安全存储不可用时,避免以明文形式持久化渠道密钥。

增强功能:

  • 将新渠道集成到通知目标发现、分发、报告、长消息处理以及凭据/会话生命周期管理中。
  • 支持感知平台的凭据存储,并提供仅运行时存储的回退机制以及渠道访问状态恢复功能。

文档:

  • 添加微信 Claw 和 QQ 官方机器人通知的本地化设置指引。

测试:

  • 增加对二维码绑定流程、通知失败报告、凭据存储回退、令牌缓存、并发处理以及不支持平台的安全存储检测的测试覆盖。

维护工作:

  • 为新的绑定端点和健康状态元数据重新生成前端 API 模型和服务。
Original summary in English

Sourcery 摘要

将微信 Claw/iLink 和 QQ 官方机器人集成为通知中心中安全管理、可通过二维码绑定的通知渠道。

新功能:

  • 为微信 Claw/iLink 和 QQ 官方机器人渠道添加二维码绑定和通知投递功能。
  • 在通知设置界面中提供渠道状态、绑定、重新绑定、解绑和启用控制,并提供本地化的中文、英文和日文操作指南。

Bug 修复:

  • 在任务活动视图中将通知投递失败显示为警告。
  • 当平台安全存储不可用时,避免以明文形式持久化渠道密钥。

增强功能:

  • 将新渠道集成到通知目标发现、投递报告、长消息处理以及凭据或会话生命周期管理中。
  • 支持访问令牌缓存、会话恢复,以及基于平台的运行时凭据回退机制,以确保可靠的出站投递。

文档:

  • 添加微信 Claw 和 QQ 官方机器人通知的本地化设置指南。

测试:

  • 增加对二维码绑定流程、通知失败报告、凭据存储回退、令牌缓存、并发处理以及不受支持的平台安全存储检测的测试覆盖。

日常维护:

  • 重新生成前端 API 模型和服务,以支持新的绑定端点和更新后的后端健康状态元数据。
  • 更新后端版本元数据。
Original summary in English

Summary by Sourcery

Integrate WeChat Claw/iLink and QQ Official Bot as securely managed, QR-bindable notification channels in the notification center.

New Features:

  • Add QR-code binding and notification delivery for WeChat Claw/iLink and QQ Official Bot channels.
  • Expose channel status, binding, rebinding, unbinding, and enablement controls in the notification settings UI with localized Chinese, English, and Japanese guidance.

Bug Fixes:

  • Surface notification delivery failures as warnings in task activity views.
  • Avoid persisting channel secrets in plaintext when platform secure storage is unavailable.

Enhancements:

  • Integrate the new channels with notification target discovery, dispatch reporting, long-message handling, and credential or session lifecycle management.
  • Support access-token caching, session recovery, and platform-aware runtime credential fallback for reliable outbound delivery.

Documentation:

  • Add localized setup guidance for WeChat Claw and QQ Official Bot notifications.

Tests:

  • Add coverage for QR binding flows, notification failure reporting, credential-storage fallback, token caching, concurrency, and unsupported-platform secure-storage detection.

Chores:

  • Regenerate frontend API models and services for the new binding endpoints and updated backend health metadata.
  • Update backend version metadata.

@sourcery-ai

sourcery-ai Bot commented Sep 5, 2026

Copy link
Copy Markdown

审查者指南

本 PR 通过新增微信 iLink 与 QQ 官方机器人管理器,将二维码绑定、凭据生命周期、安全存储回退、长消息发送和令牌/会话维护接入后端通知中心;同时扩展通知分发与失败提示、前端扫码配置界面、本地化文案、生成 API 客户端及相关测试。

微信 Claw 二维码绑定和通知发送时序图

sequenceDiagram
    actor User
    participant UI as NotificationSettings
    participant API as OpenClawWeixinAPI
    participant Manager as OpenClawWeixinManager
    participant WeChat as WeChat_iLink
    participant Storage as CredentialStorage

    User->>UI: start_login()
    UI->>API: POST /api/setting/openclaw-weixin/login/start
    API->>Manager: start_login()
    Manager->>WeChat: get_bot_qrcode()
    WeChat-->>Manager: qrcode and qr_url
    Manager-->>UI: sessionId and qrUrl
    User->>WeChat: Scan QR code
    UI->>API: POST /login/check(sessionId, verifyCode)
    API->>Manager: check_login(session_id, verify_code)
    Manager->>WeChat: get_qrcode_status()
    WeChat-->>Manager: confirmed credentials
    Manager->>Storage: Save encrypted credentials or runtime fallback
    Manager-->>UI: connected

    Note over Manager,WeChat: Notification dispatch uses send(title, content)
    Manager->>WeChat: sendmessage() for each text chunk
    WeChat-->>Manager: delivery result
Loading

通过新渠道发送通知的时序图

sequenceDiagram
    participant Task as TaskNotification
    participant Dispatch as NotifyDispatch
    participant Notify as NotificationService
    participant Weixin as OpenClawWeixinManager
    participant QQ as OpenClawQQManager
    participant WeChat as WeChat_iLink
    participant QQAPI as QQ_OfficialBotAPI
    participant UI as TaskActivityView

    Task->>Dispatch: dispatch_task_report()
    Dispatch->>Notify: send_openclaw_weixin(title, content)
    Notify->>Weixin: send(title, content)
    Weixin->>WeChat: sendmessage() per text chunk
    WeChat-->>Weixin: result
    Dispatch->>Notify: send_openclaw_qq(title, content)
    Notify->>QQ: send(title, content)
    QQ->>QQ: _ensure_access_token()
    QQ->>QQAPI: send C2C message per text chunk
    QQAPI-->>QQ: result
    Dispatch-->>UI: TASK_NOTICE warning when a channel fails
Loading

文件级变更

变更 详情 文件
新增微信 Claw/iLink 与 QQ 官方机器人通知渠道的扫码绑定、状态管理、解绑和出站消息能力。
  • 增加 FastAPI 状态、二维码登录轮询和解绑端点及对应响应模型。
  • 实现微信 iLink 与 QQ 官方机器人协议适配,包括二维码会话、凭据保存、消息发送、长文本拆分、微信会话状态及 QQ access token 管理。
  • 在应用启动和关闭流程中注册并清理渠道管理器。
app/api/__init__.py
app/api/openclaw_qq.py
app/api/openclaw_weixin.py
app/models/schema.py
app/services/openclaw_qq.py
app/services/openclaw_weixin.py
app/services/notification.py
main.py
将新通知渠道接入通知中心的配置、目标发现、分发和失败报告流程。
  • 增加微信和 QQ 通知开关及内部协议凭据配置,并在通知目标中识别和投递对应渠道。
  • 为通知正文提供渠道内容,并将投递失败通过 WebSocket 同步到任务活动页面。
app/core/notify.py
app/models/config.py
app/models/schema.py
app/tools/game_sign_notify.py
完善凭据安全策略,在支持的平台使用密文存储,否则仅以内存凭据运行。
  • 增加平台密钥存储能力探测和异常识别。
  • 避免在不支持安全存储的平台将 Bot Token 或客户端密钥写入明文配置。
  • 覆盖凭据保存、回退、解绑、令牌缓存和并发行为测试。
app/utils/platform/common/secret.py
app/utils/platform/windows/secret.py
tests/platform/test_entries.py
tests/services/test_openclaw_qq.py
tests/services/test_openclaw_weixin.py
在通知设置中提供微信和 QQ 的本地化扫码绑定 UI,并生成前端 API 类型与服务。
  • 新增绑定状态展示、二维码登录轮询、配对码输入、重新绑定、解绑和启用控制。
  • 添加中英文、日文和中文本地化文案及使用指引。
  • 生成新端点的 TypeScript 模型和 API 服务,并更新健康检查模型元数据。
  • 增加前端扫码轮询、过期处理和并发旧响应隔离测试。
frontend/src/views/setting/TabNotify.vue
frontend/src/views/setting/components/ClawBinding.vue
frontend/src/views/setting/useClawBinding.ts
frontend/src/views/setting/useClawBinding.test.ts
frontend/src/api/index.ts
frontend/src/api/models/GlobalConfig_Notify.ts
frontend/src/api/models/BackendHealthOut.ts
frontend/src/api/models/OpenClawQQQrCheckIn.ts
frontend/src/api/models/OpenClawQQQrCheckOut.ts
frontend/src/api/models/OpenClawQQQrStartOut.ts
frontend/src/api/models/OpenClawQQStatusOut.ts
frontend/src/api/models/OpenClawWeixinQrCheckIn.ts
frontend/src/api/models/OpenClawWeixinQrCheckOut.ts
frontend/src/api/models/OpenClawWeixinQrStartOut.ts
frontend/src/api/models/OpenClawWeixinStatusOut.ts
frontend/src/api/services/ClawService.ts
frontend/src/api/services/QqService.ts
frontend/src/api/services/Service.ts
补充通知分发、平台能力和渠道协议的测试覆盖,并更新版本元数据。
  • 验证通知失败告警、二维码错误状态、凭据存储模式、并发绑定、长消息序列和访问令牌缓存。
  • 更新后端版本信息。
tests/core/test_notify.py
res/version.json

提示和命令

与 Sourcery 交互

  • 触发新的审查: 在 pull request 中评论 @sourcery-ai review
  • 继续讨论: 直接回复 Sourcery 的审查评论。
  • 根据审查评论生成 GitHub issue: 回复审查评论,请 Sourcery 根据该评论创建 issue。你也可以使用 @sourcery-ai issue 回复审查评论,以根据该评论创建 issue。
  • 生成 pull request 标题: 在 pull request 标题的任意位置写入 @sourcery-ai,即可随时生成标题。你也可以在 pull request 中评论 @sourcery-ai title,以随时生成或重新生成标题。
  • 生成 pull request 摘要: 在 pull request 正文中需要插入摘要的位置写入 @sourcery-ai summary,即可随时在指定位置生成 PR 摘要。你也可以在 pull request 中评论 @sourcery-ai summary,以随时生成或重新生成摘要。
  • 生成审查者指南: 在 pull request 中评论 @sourcery-ai guide,即可随时生成或重新生成审查者指南。
  • 解决所有 Sourcery 评论: 在 pull request 中评论 @sourcery-ai resolve,即可解决所有 Sourcery 评论。如果你已经处理完所有评论且不想再看到它们,这会非常有用。
  • 忽略所有 Sourcery 审查: 在 pull request 中评论 @sourcery-ai dismiss,即可忽略所有现有的 Sourcery 审查。如果你想从头开始进行新的审查,这尤其有用——别忘了评论 @sourcery-ai review 以触发新的审查!

自定义使用体验

访问你的控制面板以:

  • 启用或禁用审查功能,例如 Sourcery 生成的 pull request 摘要、审查者指南等。
  • 更改审查语言。
  • 添加、移除或编辑自定义审查指令。
  • 调整其他审查设置。

获取帮助

Original review guide in English

Reviewer's Guide

本 PR 通过新增微信 iLink 与 QQ 官方机器人管理器,将二维码绑定、凭据生命周期、安全存储回退、长消息发送和令牌/会话维护接入后端通知中心;同时扩展通知分发与失败提示、前端扫码配置界面、本地化文案、生成 API 客户端及相关测试。

Sequence diagram for WeChat Claw QR binding and notification delivery

sequenceDiagram
    actor User
    participant UI as NotificationSettings
    participant API as OpenClawWeixinAPI
    participant Manager as OpenClawWeixinManager
    participant WeChat as WeChat_iLink
    participant Storage as CredentialStorage

    User->>UI: start_login()
    UI->>API: POST /api/setting/openclaw-weixin/login/start
    API->>Manager: start_login()
    Manager->>WeChat: get_bot_qrcode()
    WeChat-->>Manager: qrcode and qr_url
    Manager-->>UI: sessionId and qrUrl
    User->>WeChat: Scan QR code
    UI->>API: POST /login/check(sessionId, verifyCode)
    API->>Manager: check_login(session_id, verify_code)
    Manager->>WeChat: get_qrcode_status()
    WeChat-->>Manager: confirmed credentials
    Manager->>Storage: Save encrypted credentials or runtime fallback
    Manager-->>UI: connected

    Note over Manager,WeChat: Notification dispatch uses send(title, content)
    Manager->>WeChat: sendmessage() for each text chunk
    WeChat-->>Manager: delivery result
Loading

Sequence diagram for notification dispatch through new channels

sequenceDiagram
    participant Task as TaskNotification
    participant Dispatch as NotifyDispatch
    participant Notify as NotificationService
    participant Weixin as OpenClawWeixinManager
    participant QQ as OpenClawQQManager
    participant WeChat as WeChat_iLink
    participant QQAPI as QQ_OfficialBotAPI
    participant UI as TaskActivityView

    Task->>Dispatch: dispatch_task_report()
    Dispatch->>Notify: send_openclaw_weixin(title, content)
    Notify->>Weixin: send(title, content)
    Weixin->>WeChat: sendmessage() per text chunk
    WeChat-->>Weixin: result
    Dispatch->>Notify: send_openclaw_qq(title, content)
    Notify->>QQ: send(title, content)
    QQ->>QQ: _ensure_access_token()
    QQ->>QQAPI: send C2C message per text chunk
    QQAPI-->>QQ: result
    Dispatch-->>UI: TASK_NOTICE warning when a channel fails
Loading

File-Level Changes

Change Details Files
新增微信 Claw/iLink 与 QQ 官方机器人通知渠道的扫码绑定、状态管理、解绑和出站消息能力。
  • 增加 FastAPI 状态、二维码登录轮询和解绑端点及对应响应模型。
  • 实现微信 iLink 与 QQ 官方机器人协议适配,包括二维码会话、凭据保存、消息发送、长文本拆分、微信会话状态及 QQ access token 管理。
  • 在应用启动和关闭流程中注册并清理渠道管理器。
app/api/__init__.py
app/api/openclaw_qq.py
app/api/openclaw_weixin.py
app/models/schema.py
app/services/openclaw_qq.py
app/services/openclaw_weixin.py
app/services/notification.py
main.py
将新通知渠道接入通知中心的配置、目标发现、分发和失败报告流程。
  • 增加微信和 QQ 通知开关及内部协议凭据配置,并在通知目标中识别和投递对应渠道。
  • 为通知正文提供渠道内容,并将投递失败通过 WebSocket 同步到任务活动页面。
app/core/notify.py
app/models/config.py
app/models/schema.py
app/tools/game_sign_notify.py
完善凭据安全策略,在支持的平台使用密文存储,否则仅以内存凭据运行。
  • 增加平台密钥存储能力探测和异常识别。
  • 避免在不支持安全存储的平台将 Bot Token 或客户端密钥写入明文配置。
  • 覆盖凭据保存、回退、解绑、令牌缓存和并发行为测试。
app/utils/platform/common/secret.py
app/utils/platform/windows/secret.py
tests/platform/test_entries.py
tests/services/test_openclaw_qq.py
tests/services/test_openclaw_weixin.py
在通知设置中提供微信和 QQ 的本地化扫码绑定 UI,并生成前端 API 类型与服务。
  • 新增绑定状态展示、二维码登录轮询、配对码输入、重新绑定、解绑和启用控制。
  • 添加中英文、日文和中文本地化文案及使用指引。
  • 生成新端点的 TypeScript 模型和 API 服务,并更新健康检查模型元数据。
  • 增加前端扫码轮询、过期处理和并发旧响应隔离测试。
frontend/src/views/setting/TabNotify.vue
frontend/src/views/setting/components/ClawBinding.vue
frontend/src/views/setting/useClawBinding.ts
frontend/src/views/setting/useClawBinding.test.ts
frontend/src/api/index.ts
frontend/src/api/models/GlobalConfig_Notify.ts
frontend/src/api/models/BackendHealthOut.ts
frontend/src/api/models/OpenClawQQQrCheckIn.ts
frontend/src/api/models/OpenClawQQQrCheckOut.ts
frontend/src/api/models/OpenClawQQQrStartOut.ts
frontend/src/api/models/OpenClawQQStatusOut.ts
frontend/src/api/models/OpenClawWeixinQrCheckIn.ts
frontend/src/api/models/OpenClawWeixinQrCheckOut.ts
frontend/src/api/models/OpenClawWeixinQrStartOut.ts
frontend/src/api/models/OpenClawWeixinStatusOut.ts
frontend/src/api/services/ClawService.ts
frontend/src/api/services/QqService.ts
frontend/src/api/services/Service.ts
补充通知分发、平台能力和渠道协议的测试覆盖,并更新版本元数据。
  • 验证通知失败告警、二维码错误状态、凭据存储模式、并发绑定、长消息序列和访问令牌缓存。
  • 更新后端版本信息。
tests/core/test_notify.py
res/version.json

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

你好——我发现了 2 个问题

AI 代理提示词
请处理此次代码审查中的评论:

## 单独评论

### 评论 1
<location path="app/services/notification.py" line_range="308-309" />
<code_context>
+            "AuthorizationType": "ilink_bot_token",
+            "Authorization": f"Bearer {bot_token}",
+            "X-WECHAT-UIN": base64.b64encode(
+                str(secrets.randbits(32)).encode("ascii")
+            ).decode("ascii"),
+            "iLink-App-Id": "bot",
+            "iLink-App-ClientVersion": OPENCLAW_WEIXIN_CLIENT_VERSION,
</code_context>
<issue_to_address>
**问题 (bug_risk):** `X-WECHAT-UIN` 请求头正在对随机数的 ASCII 十进制表示进行 Base64 编码,但 iLink 协议要求对 32 位无符号整数的二进制字节进行 Base64 编码。网关会拒绝该请求头或无法解析它,因此每个微信消息发送请求都会无法通过协议验证。

**触发条件:** 当 iLink 网关验证必需的 `X-WECHAT-UIN` 请求头时。

**建议修复:** 使用固定宽度的二进制表示来编码该值,例如 `base64.b64encode(struct.pack(">I", secrets.randbits(32))).decode("ascii")`。
</issue_to_address>

### 评论 2
<location path="app/services/notification.py" line_range="268" />
<code_context>
         else:
             raise Exception(f"ServerChan 推送通知失败: {response.text}")

+    async def send_openclaw_weixin(self, title: str, content: str) -> None:
+        """通过微信公开的 OpenClaw/iLink HTTP 协议推送一条文本通知。
+
+        这是通知渠道的最小单账号实现:账号登录与会话上下文由配置提供,
+        AUTO-MAS 不启动 OpenClaw 进程,也不负责二维码登录流程。
+
+        Args:
+            title: 通知标题。
+            content: 已渲染的通知正文。
+
+        Raises:
+            ValueError: 微信协议配置不完整时抛出。
+            RuntimeError: 网关返回 HTTP 或业务错误时抛出。
+        """
+
</code_context>
<issue_to_address>
**小问题:** `send_openclaw_weixin` 的文档字符串承诺网关发生 HTTP 错误时会抛出 `RuntimeError`,但对于非 2xx 响应,`response.raise_for_status()` 会直接抛出 `httpx.HTTPStatusError`。依赖文档所述异常契约的调用方无法按照说明处理 HTTP 失败。

**触发条件:** 当 iLink 网关返回非 2xx HTTP 状态码时。

**建议修复:** 要么按照文档中所述的契约,将 `raise_for_status()` 统一包装为 `RuntimeError`;要么记录实际抛出的 `httpx.HTTPStatusError` 异常。

```suggestion
            httpx.HTTPStatusError: 网关返回非 2xx HTTP 响应时抛出。
```
</issue_to_address>

Sourcery 评估

需要人工审查。 需要先处理 1 个发现的问题;此外,启用后,此更改会将配置的机器人凭据和通知内容发送到外部 iLink 端点,并可能将消息发送给配置的微信用户。回滚可以阻止后续发送,但如果端点或请求行为有误,则无法撤回已发送的消息,也无法恢复已经传输的凭据或内容。

阻塞性发现:app/services/notification.py:309


Sourcery 对开源项目免费——如果您喜欢我们的审查,请考虑分享它们 ✨
Original comment in English

Hey - I've found 2 issues

Prompt for AI Agents
Please address the comments from this code review:

## Individual Comments

### Comment 1
<location path="app/services/notification.py" line_range="308-309" />
<code_context>
+            "AuthorizationType": "ilink_bot_token",
+            "Authorization": f"Bearer {bot_token}",
+            "X-WECHAT-UIN": base64.b64encode(
+                str(secrets.randbits(32)).encode("ascii")
+            ).decode("ascii"),
+            "iLink-App-Id": "bot",
+            "iLink-App-ClientVersion": OPENCLAW_WEIXIN_CLIENT_VERSION,
</code_context>
<issue_to_address>
**issue (bug_risk):** The `X-WECHAT-UIN` header is base64-encoding the ASCII decimal representation of the random number, but the iLink protocol expects the base64 encoding of a 32-bit unsigned integer's binary bytes. The gateway rejects the header or cannot parse it, so every微信消息发送请求 fails protocol validation.

**Triggers:** When the iLink gateway validates the required `X-WECHAT-UIN` header.

**Suggested fix:** Encode the value with a fixed-width binary representation, such as `base64.b64encode(struct.pack(">I", secrets.randbits(32))).decode("ascii")`.
</issue_to_address>

### Comment 2
<location path="app/services/notification.py" line_range="268" />
<code_context>
         else:
             raise Exception(f"ServerChan 推送通知失败: {response.text}")

+    async def send_openclaw_weixin(self, title: str, content: str) -> None:
+        """通过微信公开的 OpenClaw/iLink HTTP 协议推送一条文本通知。
+
+        这是通知渠道的最小单账号实现:账号登录与会话上下文由配置提供,
+        AUTO-MAS 不启动 OpenClaw 进程,也不负责二维码登录流程。
+
+        Args:
+            title: 通知标题。
+            content: 已渲染的通知正文。
+
+        Raises:
+            ValueError: 微信协议配置不完整时抛出。
+            RuntimeError: 网关返回 HTTP 或业务错误时抛出。
+        """
+
</code_context>
<issue_to_address>
**nitpick:** The `send_openclaw_weixin` docstring promises `RuntimeError` for gateway HTTP errors, but `response.raise_for_status()` raises `httpx.HTTPStatusError` directly for non-2xx responses. Callers relying on the documented exception contract cannot handle HTTP failures as specified.

**Triggers:** When the iLink gateway returns a non-2xx HTTP status.

**Suggested fix:** Either wrap `raise_for_status()` in `RuntimeError` consistently with the documented contract, or document the actual `httpx.HTTPStatusError` exception.

```suggestion
            httpx.HTTPStatusError: 网关返回非 2xx HTTP 响应时抛出。
```
</issue_to_address>

Sourcery assessment

Needs a human reviewer. 1 finding to address first, and when enabled, this change sends configured bot credentials and notification content to an external iLink endpoint and can deliver messages to the configured WeChat user. Reverting stops future sends but cannot retract messages or recover credentials or content already transmitted if the endpoint or request behavior is wrong.

Blocking findings: app/services/notification.py:309


Sourcery is free for open source - if you like our reviews please consider sharing them ✨

Comment thread app/services/notification.py Outdated
Comment on lines +308 to +309
str(secrets.randbits(32)).encode("ascii")
).decode("ascii"),

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

问题 (bug_risk): X-WECHAT-UIN 请求头正在对随机数的 ASCII 十进制表示进行 Base64 编码,但 iLink 协议要求对 32 位无符号整数的二进制字节进行 Base64 编码。网关会拒绝该请求头或无法解析它,因此每个微信消息发送请求都会无法通过协议验证。

触发条件: 当 iLink 网关验证必需的 X-WECHAT-UIN 请求头时。

建议修复: 使用固定宽度的二进制表示来编码该值,例如 base64.b64encode(struct.pack(">I", secrets.randbits(32))).decode("ascii")

Original comment in English

issue (bug_risk): The X-WECHAT-UIN header is base64-encoding the ASCII decimal representation of the random number, but the iLink protocol expects the base64 encoding of a 32-bit unsigned integer's binary bytes. The gateway rejects the header or cannot parse it, so every微信消息发送请求 fails protocol validation.

Triggers: When the iLink gateway validates the required X-WECHAT-UIN header.

Suggested fix: Encode the value with a fixed-width binary representation, such as base64.b64encode(struct.pack(">I", secrets.randbits(32))).decode("ascii").

Comment thread app/services/notification.py
@HarcoChen
HarcoChen marked this pull request as draft September 5, 2026 04:53
@HarcoChen
HarcoChen marked this pull request as ready for review September 5, 2026 08:15

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

您好——我发现了 1 个问题

面向 AI 代理的提示
请处理本次代码审查中的评论:

## 各项评论

### 评论 1
<location path="app/services/openclaw_qq.py" line_range="463-466" />
<code_context>
+                "OpenClawQQAppId": "",
+                "OpenClawQQTargetOpenId": "",
+            }
+            if self._can_persist_secrets():
+                values["OpenClawQQClientSecret"] = ""
+            async with self._config_lock:
+                await Config.update({"Notify": values})
+
+    async def send(self, title: str, content: str) -> None:
</code_context>
<issue_to_address>
**issue (bug_risk):** 当密钥存储不可用时,解绑操作会清除启用标志和非敏感字段,但会有意忽略加密凭据字段。如果之后安全存储恢复可用,旧令牌或客户端密钥仍会从配置中加载,导致即使用户已经解绑,通道仍会显示为已绑定。

**触发条件:** 当一个之前持久化的绑定在平台安全存储探测不可用期间被解绑,并且安全存储在下一次状态或通知操作之前恢复可用时。

**建议修复:** 只要配置层仍能更新加密凭据字段,就应在解绑过程中将其清除;或者记录一个持久化的墓碑标记,以防止重新使用过期的加密凭据。
</issue_to_address>

Sourcery 评估

需要人工审查。 首先需要处理 1 个发现项;此外,此变更增加了基于二维码的账户绑定、凭据存储、后台会话轮询,以及向外部微信和 QQ 端点发送通知的功能。如果收件人或身份验证流程有误,消息或访问凭据可能会被发送到错误的外部账户,或继续留存在错误的外部账户中。回滚可以停止后续发送并移除本地行为,但无法撤回已经送达的通知,也无法撤销已在外部服务中建立的凭据和访问权限。

阻塞性发现:app/services/openclaw_qq.py:466


Sourcery 对开源项目免费——如果您喜欢我们的审查结果,欢迎分享 ✨
Original comment in English

Hey - I've found 1 issue

Prompt for AI Agents
Please address the comments from this code review:

## Individual Comments

### Comment 1
<location path="app/services/openclaw_qq.py" line_range="463-466" />
<code_context>
+                "OpenClawQQAppId": "",
+                "OpenClawQQTargetOpenId": "",
+            }
+            if self._can_persist_secrets():
+                values["OpenClawQQClientSecret"] = ""
+            async with self._config_lock:
+                await Config.update({"Notify": values})
+
+    async def send(self, title: str, content: str) -> None:
</code_context>
<issue_to_address>
**issue (bug_risk):** When secret storage is unavailable, unbind clears the enable flag and non-secret fields but deliberately omits the encrypted credential fields. If secure storage becomes available again later, the old token or client secret is still loaded from configuration and the channel appears bound again despite the user having unbound it.

**Triggers:** When a previously persisted binding is unbound while the platform secure-storage probe is unavailable, then secure storage becomes available before the next status or notification operation.

**Suggested fix:** Clear encrypted credential fields as part of unbind whenever the configuration layer can still update them, or record a durable tombstone that prevents stale encrypted credentials from being reused.
</issue_to_address>

Sourcery assessment

Needs a human reviewer. 1 finding to address first, and this adds QR-based account binding, credential storage, background session polling, and outbound notifications to external WeChat and QQ endpoints; if the recipient or authentication flow is wrong, messages or access credentials could reach or remain with the wrong external account. Reverting stops future sends and removes the local behavior, but it cannot unsend notifications already delivered or revoke credentials and access established with the external services.

Blocking findings: app/services/openclaw_qq.py:466


Sourcery is free for open source - if you like our reviews please consider sharing them ✨

Comment thread app/services/openclaw_qq.py
@HarcoChen

Copy link
Copy Markdown
Contributor Author

@sourcery-ai Review

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

您好——我已经审阅了您所做的更改,整体看起来很棒!

Sourcery 评估

需要人工审阅。 此更改增加了基于二维码的凭据获取与存储功能,以及向外部微信和 QQ 账户发送的出站消息,因此,错误的账户映射或凭据处理流程可能会暴露访问权限,或将通知发送给错误的收件人。回滚可以阻止后续请求,但无法撤回已经发送的消息,也不会自动删除已经持久化的凭据。


Sourcery 对开源项目免费——如果您喜欢我们的审阅结果,欢迎考虑分享 ✨
Original comment in English

Hey - I've reviewed your changes and they look great!

Sourcery assessment

Needs a human reviewer. This adds QR-based credential acquisition and storage plus outbound messages to external WeChat and QQ accounts, so a faulty account mapping or credential-handling path could expose access or send notifications to the wrong recipient. Reverting stops future requests but cannot recall messages already sent or automatically remove credentials already persisted.


Sourcery is free for open source - if you like our reviews please consider sharing them ✨

@qiyinxi

qiyinxi commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

send() 里把 -2-14 一起当成登录失效,一次推送撞上就会清掉 Bot Token 并关掉开关,用户得重新扫码:

if error_code in {-2, -14}:
    await self._invalidate_binding(reason="微信登录状态已失效")

官方 Tencent/openclaw-weixin 只定义了 STALE_TOKEN_ERRCODE = -14src/api/session-guard.ts:6),全仓没有对 -2 的处理;这个 PR 上一版对 -2 的注释也是「上下文过期」。现在 context_token 已经不发了,建议只保留 -14-2 按普通失败报错。

另外 Sourcery 那条 X-WECHAT-UIN 是误报,官方 src/api/api.ts:221 的注释就是 random uint32 -> decimal string -> base64,和当前实现一致,不用按建议改成 struct.pack

小问题:i18n 有 5 个键没有任何引用 —— openclawWeixinTipopenclawQqTipopenclawWeixinBindSuccessopenclawQqBindSuccessopenclawWeixinUnbindFailed

还想问一下 QQ 那边:/v2/users/{openid}/messages 不带 msg_id 走的是主动消息,官方有权限和频次配额,实际跑通过吗?

@HarcoChen

HarcoChen commented Sep 5, 2026 via email

Copy link
Copy Markdown
Contributor Author

@HarcoChen
HarcoChen merged commit 9ca42ee into AUTO-MAS-Project:dev Sep 5, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants