fix(wecom): scope WECOM_WEBSOCKET_URL like its neighbours

Same class as #100627's WECOM_BOT_ID: the one remaining raw os.getenv in
WeComAdapter.__init__ let a secondary multiplex profile pick up the
default profile's bridged websocket URL. Route it through
_get_scoped_secret; folded into the existing scoped-miss test.
This commit is contained in:
Teknium
2026-09-02 03:35:35 -07:00
parent 2bcbdb61a7
commit 9be1168cd3
2 changed files with 4 additions and 2 deletions
+1 -1
View File
@@ -323,7 +323,7 @@ class WeComAdapter(BasePlatformAdapter):
self._ws_url = str(
extra.get("websocket_url")
or extra.get("websocketUrl")
or os.getenv("WECOM_WEBSOCKET_URL", DEFAULT_WS_URL)
or _get_scoped_secret("WECOM_WEBSOCKET_URL", DEFAULT_WS_URL)
).strip() or DEFAULT_WS_URL
self._dm_policy = str(extra.get("dm_policy") or _get_scoped_secret("WECOM_DM_POLICY", "pairing")).strip().lower()
+3 -1
View File
@@ -98,15 +98,17 @@ class TestWeComAdapterAuthzScope:
def test_scoped_miss_does_not_leak_default_profiles_bot_id(self, multiplex_on, monkeypatch):
from agent import secret_scope
from plugins.platforms.wecom.adapter import WeComAdapter
from plugins.platforms.wecom.adapter import DEFAULT_WS_URL, WeComAdapter
monkeypatch.setenv("WECOM_BOT_ID", "default-profile-bot-id")
monkeypatch.setenv("WECOM_WEBSOCKET_URL", "wss://default-profile.example/ws")
token = secret_scope.set_secret_scope({"SOMETHING_ELSE": "x"})
try:
adapter = WeComAdapter(PlatformConfig(enabled=True))
finally:
secret_scope.reset_secret_scope(token)
assert adapter._bot_id == ""
assert adapter._ws_url == DEFAULT_WS_URL
class TestWeComConnect: