chore(sync): mirror docs from openclaw/openclaw@c3f5c20f2c

This commit is contained in:
openclaw-docs-sync[bot] 2026-05-03 23:45:31 +00:00
parent 5f243fe747
commit 7250f9ef67
3 changed files with 12 additions and 4 deletions

View File

@ -1,5 +1,5 @@
{
"repository": "openclaw/openclaw",
"sha": "baadd74b6bb515f4a20aadf10ccadbec156e4f28",
"syncedAt": "2026-05-03T23:42:43.411Z"
"sha": "c3f5c20f2cc0ed7a5d7a8f45fd0df3a4ddc6b5ce",
"syncedAt": "2026-05-03T23:43:21.968Z"
}

View File

@ -142,6 +142,13 @@ openclaw devices approve <requestId>
openclaw devices reject <requestId>
```
When an explicit approval is denied because the approving paired-device session
was opened with pairing-only scope, the CLI retries the same request with
`operator.admin`. This lets an existing admin-capable paired device recover a new
Control UI/browser pairing without editing `devices/paired.json` by hand. The
Gateway still validates the retried connection; tokens that cannot authenticate
with `operator.admin` remain blocked.
If the same device retries with different auth details (for example different
role/scopes/public key), the previous pending request is superseded and a new
`requestId` is created.

View File

@ -78,8 +78,9 @@ When approving a device request:
`operator.admin`.
For paired-device token sessions, management is self-scoped unless the caller
also has `operator.admin`: non-admin callers can rotate, revoke, or remove only
their own device entry.
also has `operator.admin`: non-admin callers see only their own pairing entries,
can approve or reject only their own pending request, and can rotate, revoke, or
remove only their own device entry.
## Node pairing approvals