From 9be1168cd329defa6ccac840bf0592c30accb570 Mon Sep 17 00:00:00 2001 From: Teknium <127238744+teknium1@users.noreply.github.com> Date: Wed, 2 Sep 2026 03:35:35 -0700 Subject: [PATCH] fix(wecom): scope WECOM_WEBSOCKET_URL like its neighbours Same class as #100627's WECOM_BOT_ID: the one remaining raw os.getenv in WeComAdapter.__init__ let a secondary multiplex profile pick up the default profile's bridged websocket URL. Route it through _get_scoped_secret; folded into the existing scoped-miss test. --- plugins/platforms/wecom/adapter.py | 2 +- tests/gateway/test_wecom.py | 4 +++- 2 files changed, 4 insertions(+), 2 deletions(-) diff --git a/plugins/platforms/wecom/adapter.py b/plugins/platforms/wecom/adapter.py index 1e05a2f761..27fbf52e2b 100644 --- a/plugins/platforms/wecom/adapter.py +++ b/plugins/platforms/wecom/adapter.py @@ -323,7 +323,7 @@ class WeComAdapter(BasePlatformAdapter): self._ws_url = str( extra.get("websocket_url") or extra.get("websocketUrl") - or os.getenv("WECOM_WEBSOCKET_URL", DEFAULT_WS_URL) + or _get_scoped_secret("WECOM_WEBSOCKET_URL", DEFAULT_WS_URL) ).strip() or DEFAULT_WS_URL self._dm_policy = str(extra.get("dm_policy") or _get_scoped_secret("WECOM_DM_POLICY", "pairing")).strip().lower() diff --git a/tests/gateway/test_wecom.py b/tests/gateway/test_wecom.py index c167524511..96886df995 100644 --- a/tests/gateway/test_wecom.py +++ b/tests/gateway/test_wecom.py @@ -98,15 +98,17 @@ class TestWeComAdapterAuthzScope: def test_scoped_miss_does_not_leak_default_profiles_bot_id(self, multiplex_on, monkeypatch): from agent import secret_scope - from plugins.platforms.wecom.adapter import WeComAdapter + from plugins.platforms.wecom.adapter import DEFAULT_WS_URL, WeComAdapter monkeypatch.setenv("WECOM_BOT_ID", "default-profile-bot-id") + monkeypatch.setenv("WECOM_WEBSOCKET_URL", "wss://default-profile.example/ws") token = secret_scope.set_secret_scope({"SOMETHING_ELSE": "x"}) try: adapter = WeComAdapter(PlatformConfig(enabled=True)) finally: secret_scope.reset_secret_scope(token) assert adapter._bot_id == "" + assert adapter._ws_url == DEFAULT_WS_URL class TestWeComConnect: