v4.3.20: 미커밋 자산 일괄 정리 + 유저 워크스페이스/세션토큰 gitignore
그동안 쌓여 있던 미커밋 파일들을 정리. 소스·자산만 올리고, 개인 데이터와 런타임 상태는 gitignore로 차단. 추가된 자산: - web-ui/audiomass, web-ui/wavacity — 자체 호스팅 오디오 에디터 - web-ui/drums — 드럼 샘플 - wol-gate — WOL 프록시 컨테이너(Dockerfile + server.js) - glm-1m-fix — GLM 1M 컨텍스트 설치 스크립트(linux/windows) - RENODE_FIXES_SUMMARY*.md, CCTV정보_서울특별시.csv, .claude/plans 수정: - edge_tts_synth.py: rate 인자 추가(말하기 속도 조절) - .smallclaw/config.json: google(gemini) provider 등록 — 키는 vault 참조 - assets/SmallClaw*.png 삭제분 반영 gitignore (중요): - .smallclaw/users/*/workspace/ 전체 차단. 기존 패턴이 memory/uploads와 일부 확장자만 막아서 detective/(고소장·통화녹취·의사소견서·가족관계증명서), generated-media/, music/, pptx/ 등 앱 생성 개인 데이터 403MB가 노출돼 있었음 - .smallclaw/active-sessions.json 차단 — 살아있는 bearer 토큰과 admin 역할이 평문으로 들어있어 커밋 시 게이트웨이 관리자 자격증명이 그대로 공개됨 - google-usage.json, config.json.bak-*, workspace/memory·weather-maps· task_result_*, voice/ 등 런타임 상태도 함께 차단 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
+23
@@ -89,6 +89,29 @@ chatbot*.png
|
||||
.smallclaw/users/*/workspace/*.bat
|
||||
.smallclaw/users/*/workspace/*.txt
|
||||
|
||||
# --- PER-USER WORKSPACE: BLANKET IGNORE (2026-07-29) ---
|
||||
# The per-user patterns above only covered memory/uploads/attachments and a handful of
|
||||
# file extensions, which left every app-generated content directory exposed — detective/
|
||||
# (case evidence: 고소장, 통화녹취 m4a, 정신과 소견서, 가족관계증명서), generated-media/,
|
||||
# music/, pptx/, satellite-images/, writer/, code/ and more. That is private user data
|
||||
# (403MB of it) that must never reach the remote, so ignore the whole subtree instead of
|
||||
# chasing each new app's output folder. Files already tracked here (prompts/*.md and other
|
||||
# shipped templates) are unaffected — gitignore does not untrack them, and their edits
|
||||
# still show up in git status. Use `git add -f` to track a genuinely new template.
|
||||
.smallclaw/users/*/workspace/
|
||||
|
||||
# --- GATEWAY RUNTIME STATE / SECRETS (2026-07-29) ---
|
||||
# active-sessions.json maps live bearer tokens -> {username, role:"admin"}; committing it
|
||||
# would publish working admin credentials for the gateway. The rest is per-machine runtime
|
||||
# state or a stale pre-vault config backup — none of it belongs in the repo.
|
||||
.smallclaw/active-sessions.json
|
||||
.smallclaw/google-usage.json
|
||||
.smallclaw/config.json.bak-*
|
||||
.smallclaw/workspace/memory/
|
||||
.smallclaw/workspace/weather-maps/
|
||||
.smallclaw/workspace/task_result_*.txt
|
||||
.smallclaw/voice/
|
||||
|
||||
# --- ROOT WORKSPACE RUNTIME FILES ---
|
||||
# Keep: SOUL.md, SELF.md, IDENTITY.md, USER.md, MEMORY.md, AGENTS.md, TOOLS.md, BOOT.md, README.md
|
||||
# These are default templates that ship with SmallClaw — new users need them.
|
||||
|
||||
Reference in New Issue
Block a user