picoclaw/web/backend/api
Kristjan Kruus 1f9d390a64 fix: apply security credentials before config validation in web handlers
- Move SecurityCopyFrom() before validateConfig() in PUT and PATCH handlers
- Make SecurityCopyFrom() call applySecurityConfig() to populate private fields
- Add tests for config save with security-only channel tokens

Without this fix, saving config via the web UI fails with 'channels.pico.token
is required' (and similar for Telegram/Discord) when tokens are stored in
.security.yml, because the validation ran before security credentials were
copied to the config struct.
2026-03-23 14:26:51 +02:00
..
channels.go feat(web): migrate launcher to modular web frontend/backend and improve management UX (#1275) 2026-03-09 19:42:03 +08:00
config.go fix: apply security credentials before config validation in web handlers 2026-03-23 14:26:51 +02:00
config_test.go fix: apply security credentials before config validation in web handlers 2026-03-23 14:26:51 +02:00
gateway.go refactor: seperate security.yml for store keys 2026-03-22 01:55:00 +08:00
gateway_host.go feat: add web gateway hot reload and polling state sync (#1684) 2026-03-17 18:46:00 +08:00
gateway_host_test.go feat: add web gateway hot reload and polling state sync (#1684) 2026-03-17 18:46:00 +08:00
gateway_test.go Merge branch 'main' into version 2026-03-23 15:00:18 +08:00
launcher_config.go feat(web): migrate launcher to modular web frontend/backend and improve management UX (#1275) 2026-03-09 19:42:03 +08:00
launcher_config_test.go refactor Config to add Version and migratable 2026-03-12 13:52:55 +08:00
log.go refactor Config to add Version and migratable 2026-03-12 13:52:55 +08:00
model_status.go Merge branch 'main' into version 2026-03-23 15:00:18 +08:00
model_status_test.go Merge branch 'main' into version 2026-03-23 15:00:18 +08:00
models.go feat(providers): add extra_body config to inject custom fields into request body 2026-03-23 16:39:42 +08:00
models_test.go Merge branch 'main' into version 2026-03-23 15:00:18 +08:00
oauth.go refactor: seperate security.yml for store keys 2026-03-22 01:55:00 +08:00
oauth_test.go refactor: seperate security.yml for store keys 2026-03-22 01:55:00 +08:00
pico.go refactor: seperate security.yml for store keys 2026-03-22 01:55:00 +08:00
pico_test.go refactor: seperate security.yml for store keys 2026-03-22 01:55:00 +08:00
router.go feat(web): implement macOS app feature and file logger (#1723) 2026-03-18 14:43:58 +08:00
session.go refactor Config to add Version and migratable 2026-03-12 13:52:55 +08:00
session_test.go refactor Config to add Version and migratable 2026-03-12 13:52:55 +08:00
skills.go refactor: centralize environment variable key constants (#1730) 2026-03-18 18:03:24 +08:00
skills_test.go refactor Config to add Version and migratable 2026-03-12 13:52:55 +08:00
startup.go feat(web): migrate launcher to modular web frontend/backend and improve management UX (#1275) 2026-03-09 19:42:03 +08:00
startup_test.go feat(web): migrate launcher to modular web frontend/backend and improve management UX (#1275) 2026-03-09 19:42:03 +08:00
tools.go feat(tools): add SpawnStatusTool for reporting subagent statuses (#1540) 2026-03-17 14:41:43 +08:00
tools_test.go refactor Config to add Version and migratable 2026-03-12 13:52:55 +08:00