Add Slack workspace assistant and Cloud integration-gateway client - #499
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 8b3273051e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 79f8dac975
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 5c04f68c93
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 248297f1b8
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…gration-gateway # Conflicts: # apps/web/src/lib/server/policy/authz-matrix/MATRIX.md # apps/web/src/lib/server/policy/dep-graph/GRAPH.md
|
Addressed the current review findings:
Also fixed CI findings: replay-safe migration guards, refusal of the older migration that downgrades the assistant default, schema constraint names, tool output gate envelopes, principal merge handling, queue registration wrappers, and generated policy documents. Merged current main and regenerated the two conflicting policy documents. Local validation: fresh migration and schema drift passed; the broad tenant run passed 14,664 tests, followed by 24 passing principal-merge tests after fixing their shared mock. Slack follow-up tests (15), policy merge tests (76), and TypeScript passed. The local cross-repo vendor comparison still reports the pre-existing servingVersion contract mismatch between app main and CP; the app contract is unchanged by this PR. GitHub CI will validate the merged head. @codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 8e749d277b
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…gration-gateway # Conflicts: # apps/web/src/lib/server/policy/module-state/MODULE-STATE.md
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 02ddd9b859
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Addressed the latest two findings in 19b16ec:
Validation: 20 focused Slack tests and TypeScript passed. The preceding merged head had all GitHub build, four test shards, smoke, live API and CodeQL checks green; this follow-up is running fresh CI. @codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 19b16ec015
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Addressed the six remaining findings in 2fe7b03:
Validation: 42 focused settings/source/fleet tests, 8 real-database retrieval/rollback tests, and TypeScript passed. CP's matching bootstrap contract tests passed (15, with 2 database tests skipped). @codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 2fe7b03670
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
c484bdd fixes the remaining runtime review findings:
Validation: 157 runtime/Slack/settings tests, 121 runtime/contract tests after the digest correction, and TypeScript passed. @codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c484bdd715
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Disconnect now takes the same provider lock as reconnect and refuses to delete a row that changed under it. Stale Slack revocations compare the full millisecond install timestamp, and Cloud settings cannot override control-database or cache URLs.
Main claimed 0091 for workspace activity; the gateway migrations moved.
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
Addressed the remaining review findings in 02c1dd0:
Also merged |
|
@codex review |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
Use first-party MCP tools for workspace Slack, run create/assign as the asking teammate, serialize chat streams, and abort on agent_session_stopped. Drop the Cloud settings overlay from the tenant image. Add thread sessions.
…gration-gateway # Conflicts: # apps/web/src/lib/server/jobs/runner.ts
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c5fb54fec5
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| function scopesFromActor(actor: Actor): ApiKeyScope[] { | ||
| if (!actor.permissions || actor.permissions.size === 0) { | ||
| return isTeamMember(actor.role) ? [...API_KEY_SCOPES] : [] | ||
| } | ||
| return orderScopes([...actor.permissions].map(scopeForPermission)) |
There was a problem hiding this comment.
Preserve exact permissions when opening workspace MCP
For a custom-role teammate whose resolved permissions contain copilot.use but not post.create, scopeForPermission maps that AI permission to write:feedback, so the MCP session exposes create_post, triage_post, and other feedback mutations. Those MCP handlers then reconstruct actors from the legacy member role without the resolved permission set, and the workspace path marks several writes autonomous, allowing Slack to perform actions the teammate cannot perform in the app. Preserve the actor's exact permissions through MCP authorization rather than widening them into category-level scopes.
Useful? React with 👍 / 👎.
| let { tools, activeSpecs } = await assembleAssistantToolset(toolContext, builtInSpecs, [ | ||
| ...workspaceMcpSpecs, | ||
| ...connectorSpecs, | ||
| ]) |
There was a problem hiding this comment.
Apply workspace action rules to MCP replacements
When an administrator disables capture_feedback or create_ticket on the workspace-assistant page, the saved rule is applied only to builtInSpecs, while all workspaceMcpSpecs are appended unfiltered here. The workspace role subsequently removes those built-ins anyway, but MCP still supplies create_post and create_ticket, so disabled feedback creation can execute autonomously and disabled ticket creation can still be proposed and approved. Filter the MCP catalogue using the workspace rules, including mapping capture_feedback to its create_post replacement.
Useful? React with 👍 / 👎.
| if (event?.type === 'agent_session_stopped') { | ||
| const channel = event.channel | ||
| const thread = event.thread_ts | ||
| const user = event.user | ||
| if (typeof channel === 'string' && typeof thread === 'string') { |
There was a problem hiding this comment.
Persist native Stop in the thread session
When a teammate presses Slack's native Stop button in an already-active assistant thread, this branch resets Slack's presentation status and returns without calling stopSlackThreadSession. The database session therefore remains active, and the next ordinary unmentioned reply in that thread satisfies the followUp predicate and invokes the assistant again despite the explicit Stop. Mark the persistent session stopped before returning from this event handler.
Useful? React with 👍 / 👎.
Ledger the in-flight Slack abort map, regenerate dep-graph/contract/schema goldens, and import the MCP server only when a workspace turn opens so mocked db tests do not pull search/sql at load time.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7f937c8ff2
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| const event = payload.event | ||
| // Abort before enqueue: slack-hook is serial, so a Stop job would otherwise | ||
| // wait until the in-flight turn finished. | ||
| if (kind === 'events') abortSlackTurnFromPayload(payload) |
There was a problem hiding this comment.
Route Stop cancellation to the worker process
In split-role deployments where the hook receiver runs with QUACKBACK_ROLE=web and turns run in a worker, this calls abortSlackTurnFromPayload against the web process's in-memory map, while beginSlackTurn registered the controller in a different process. The call therefore cannot cancel the active model request, and the queued Stop event waits behind that same slack-hook job; use an inter-process cancellation signal or handle Stop through worker-visible state rather than a process-local map.
Useful? React with 👍 / 👎.
| export function formatSlackAnswer(text: string): string { | ||
| return text.replace(/<@/g, '<@').trim() |
There was a problem hiding this comment.
Escape Slack broadcast mention syntax
When model or retrieved text contains Slack special mentions such as <!channel>, <!here>, <!everyone>, or <!subteam^…>, this sanitizer leaves them intact because it only rewrites <@. Those tokens then reach chatStream and can notify an entire channel or user group; neutralize all Slack mention forms before appending or posting generated text.
Useful? React with 👍 / 👎.
Adds a Slack workspace assistant. Linked teammates can ask in mentions, DMs, slash commands, and follow-up thread messages; they get cited answers, and writes (feedback posts or internal tickets) are proposed then approved by an authorized member.
/api/integrations/slack/hooks/*). Cloud uses the control-plane gateway (OAuth bounce and signed hook forwarder). Shared Cloud OAuth credentials are RailwayINTEGRATION_<PROVIDER>_*environment variables on CP and the fleet — not a CP JSON settings overlay.reply/ignore/stop) with a 45-minute idle session (migration0275_slack_thread_sessions).slack-hookjobs discard the payload atomically.0274_slack_agent_gatewayand0275_slack_thread_sessions. Slack manifest and rollout runbook included.Validation: focused unit tests for hooks/addressing, assistant settings, migrator gate, jobs, OAuth/installs, and related suites. Typecheck is clean on the worktree. Live Slack evals need a real model and database; they are not a substitute for the rollout gates.
Cloud rollout: apply CP migration
0092_integration_installs, setINTEGRATION_SLACK_*,REDIS_URL, andINTEGRATION_GATEWAY_FORWARD_SECRETon CP and the fleet, then followdocs/integrations/integration-gateway-rollout.md. Self-host does not need the CP gateway. Nothing has been deployed.Companion CP PR: https://github.com/QuackbackIO/quackback-cp/pull/198