hermes-agent/gateway
Teknium f98e214682
fix(gateway): reject known-weak placeholder credentials at startup
Port from openclaw/openclaw#64586: users who copy .env.example without
changing placeholder values (***,changeme,your_api_key,etc.) now get a
clear error message at startup instead of a confusing authentication
failure from the platform API.

Changes:
- Extract _validate_gateway_config() from load_gateway_config() for
  testability
- Check enabled platform tokens against has_usable_secret() from
  hermes_cli.auth — disabled platforms with placeholder tokens get a
  clear error log and are auto-disabled
- Check API_SERVER_KEY against has_usable_secret() when binding to a
  network-accessible address — placeholder keys are rejected with a
  helpful error suggesting openssl rand

The existing _PLACEHOLDER_SECRET_VALUES set in hermes_cli/auth.py
already contains the right patterns (*,**,***,changeme,your_api_key,
placeholder,example,dummy,null,none); this PR extends their use from
LLM provider credentials to gateway platform tokens.
2026-04-12 17:11:37 -07:00
..
builtin_hooks refactor: replace inline HERMES_HOME re-implementations with get_hermes_home() 2026-04-07 10:40:34 -07:00
platforms fix(gateway): reject known-weak placeholder credentials at startup 2026-04-12 17:11:37 -07:00
__init__.py Enhance CLI with multi-platform messaging integration and configuration management 2026-02-02 19:01:51 -08:00
channel_directory.py fix(gateway): derive channel directory platforms from enum instead of hardcoded list (#7450) 2026-04-10 17:27:32 -07:00
config.py fix(gateway): reject known-weak placeholder credentials at startup 2026-04-12 17:11:37 -07:00
delivery.py fix: remove 115 verified dead code symbols across 46 production files 2026-04-10 03:44:43 -07:00
display_config.py feat: per-platform display verbosity configuration (#8006) 2026-04-11 17:20:34 -07:00
hooks.py feat: built-in boot-md hook — run BOOT.md on gateway startup (#3733) 2026-03-29 10:19:54 -07:00
mirror.py chore: remove ~100 unused imports across 55 files (#3016) 2026-03-25 15:02:03 -07:00
pairing.py fix: multiple platform adaptors concurrency 2026-04-06 16:49:54 -07:00
restart.py fix(gateway): address restart review feedback 2026-04-10 21:18:34 -07:00
run.py fix(weixin): streaming cursor, media uploads, markdown links, blank messages (#8665) 2026-04-12 16:43:25 -07:00
session.py fix(matrix): replace pickle crypto store with SQLite, fix E2EE decryption (#7981) 2026-04-12 07:24:46 +05:30
session_context.py fix(gateway): add HERMES_SESSION_KEY to session_context contextvars 2026-04-11 15:35:04 -07:00
status.py fix(discord): decouple readiness from slash sync 2026-04-11 19:22:14 -07:00
sticker_cache.py chore: remove ~100 unused imports across 55 files (#3016) 2026-03-25 15:02:03 -07:00
stream_consumer.py feat(gateway): surface natural mid-turn assistant messages in chat platforms 2026-04-11 16:21:39 -07:00