auth-store-debug
द्वारा vercel
वर्सेल-ओपनक्लॉ के लिए प्रमाणीकरण और स्टोर डिबगिंग: एडमिन-सीक्रेट मोड, वर्सेल के साथ साइन इन, सत्र कुकीज़, CSRF, LOCAL_READ_ONLY, Redis बनाम मेमोरी स्टोर, कीस्पेस…
npx skills add https://github.com/vercel-labs/vercel-openclaw --skill auth-store-debugAuth Store Debug
Use this skill when request authorization, session behavior, store persistence, or metadata shape is the likely problem.
Evidence First
Collect:
- Auth mode and Vercel/local environment from admin/preflight surfaces.
- Request method, route, status, and whether bearer or cookie auth was used.
GET /api/admin/logsfiltered forauth.,store.,session.,preflight..- Store backend reported by deployment contract.
- Sanitized metadata shape when needed. Never print secrets, session keys, Redis URLs, or cookies.
Critical Splits
- Deployment Protection auth vs app auth.
- Bearer admin-secret auth vs encrypted session cookie auth.
- CSRF applies to cookie-based mutations, not bearer mutations.
LOCAL_READ_ONLY=1intentionally blocks admin mutations locally.- Redis connects only on deployed Vercel runtimes; local/CI use memory store even if Redis envs exist.
OPENCLAW_INSTANCE_IDchanges namespace and does not migrate old state.
Fix Boundaries
- Auth:
src/server/auth/{admin-auth,admin-secret,session,vercel-auth,route-auth}.ts. - Store:
src/server/store/{store,redis-store,memory-store,keyspace}.ts,src/shared/types.ts. - Routes: only the affected route handler.
- Docs/env contract:
.env.example,README.md,CONTRIBUTING.md,CLAUDE.md.
Verification
node scripts/verify.mjs --steps=test,typecheck
pnpm check:verify-contract
lat check
Run pnpm check:verify-contract when env vars, auth mode docs, or operator instructions change.