Skip to content

Fix Slack admin setup visibility for WebUI operator tokens - #5185

Merged
serrrfirat merged 1 commit into
mainfrom
codex/slack-admin-token-visibility
Jun 24, 2026
Merged

serrrfirat merged 1 commit into
mainfrom
codex/slack-admin-token-visibility

Conversation

@serrrfirat

Copy link
Copy Markdown
Collaborator

Summary

  • expose Slack admin setup metadata based on the operator WebUI authenticator instead of hiding it whenever SSO is configured
  • carry the matched token's operator_webui_config capability into WebUI product callers
  • gate Slack admin route listings and mutations on the per-request operator capability

Railway notes

  • hosted Reborn should use railway.reborn.toml / Dockerfile.reborn
  • Dockerfile.reborn builds ironclaw_reborn_cli with webui-v2-beta, slack-v2-host-beta, and postgres
  • config.hosted-single-tenant.toml intentionally seeds [slack].enabled=false; IRONCLAW_REBORN_SLACK_ENABLED=true overrides it at runtime

Tests

  • cargo test -p ironclaw_reborn_composition --features webui-v2-beta,slack-v2-host-beta slack_connectable_channels_advertise_admin_action_to_operator_token -j1
  • cargo test -p ironclaw_reborn_composition --features webui-v2-beta,slack-v2-host-beta operator_capability -j1
  • cargo test -p ironclaw_reborn_cli --features webui-v2-beta,slack-v2-host-beta,postgres slack_operator_route_visibility_follows_authenticator_route_mount_capability -j1
  • cargo test -p ironclaw_webui_v2 operator_capability -j1
  • git diff --check

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5185 June 24, 2026 11:03 Destroyed
@github-actions github-actions Bot added size: L 200-499 changed lines risk: low Changes to docs, tests, or low-risk modules labels Jun 24, 2026
@coderabbitai

coderabbitai Bot commented Jun 24, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: cee1ad5d-75dd-459f-b5a3-7411932bc7ab

📥 Commits

Reviewing files that changed from the base of the PR and between 6337e50 and 1216556.

⛔ Files ignored due to path filters (1)
  • crates/ironclaw_webui_v2_static/static/dist/app.js is excluded by !**/dist/**
📒 Files selected for processing (11)
  • crates/ironclaw_product_workflow/src/webui_inbound.rs
  • crates/ironclaw_reborn_cli/src/commands/serve.rs
  • crates/ironclaw_reborn_composition/src/slack_channel_routes.rs
  • crates/ironclaw_reborn_composition/src/slack_channel_routes/allowed/tests.rs
  • crates/ironclaw_reborn_composition/src/slack_connectable_channel.rs
  • crates/ironclaw_reborn_composition/src/slack_host_beta.rs
  • crates/ironclaw_reborn_composition/src/slack_personal_binding_pairing_serve.rs
  • crates/ironclaw_reborn_composition/src/webui_serve.rs
  • crates/ironclaw_webui_v2_static/src/assets.rs
  • crates/ironclaw_webui_v2_static/static/js/pages/extensions/components/channels-tab.js
  • crates/ironclaw_webui_v2_static/static/js/pages/extensions/components/channels-tab.test.mjs

📝 Walkthrough

Summary by CodeRabbit

  • New Features

    • Added propagation of an operator WebUI configuration capability into authenticated WebUI sessions.
    • Operator WebUI configuration now controls visibility for Slack route-admin and admin-managed connectable channel experiences.
  • Bug Fixes

    • Tightened authorization so operator-only Slack admin endpoints and admin-managed connectable channels are blocked/hidden when the capability is missing.
    • Updated route-visibility behavior to align with the capability model.
  • Tests

    • Expanded unit and WebUI integration coverage for capability-enabled vs capability-disabled callers.
  • Documentation

    • Updated static asset/UI expectations for the Channels tab Slack setup label and tests.

Walkthrough

WebUiAuthenticatedCaller gains an operator_webui_config capability, which is propagated from auth claims and enforced on operator-only Slack routes. CLI route visibility now keys off authenticator capability instead of SSO presence.

Changes

operator_webui_config capability gate

Layer / File(s) Summary
Caller capability field and builder
crates/ironclaw_product_workflow/src/webui_inbound.rs
Adds operator_webui_config: bool with Serde default/skip-if-false, initializes it to false, and adds with_operator_webui_config(self, bool) -> Self.
Auth propagation and CLI visibility
crates/ironclaw_reborn_composition/src/webui_serve.rs, crates/ironclaw_reborn_cli/src/commands/serve.rs
authenticate_request forwards auth.capabilities.operator_webui_config; ServeCommand::execute now derives operator route visibility from mounts_operator_webui_config_routes() via a helper.
Operator route authorization gates
crates/ironclaw_reborn_composition/src/slack_channel_routes.rs, crates/ironclaw_reborn_composition/src/slack_connectable_channel.rs
ensure_authorized_operator rejects callers without the capability, and connectable-channel listing only includes the admin-managed channel when it is set.
Test helpers and integration coverage
crates/ironclaw_reborn_composition/src/slack_channel_routes.rs, crates/ironclaw_reborn_composition/src/slack_channel_routes/allowed/tests.rs, crates/ironclaw_reborn_composition/src/slack_connectable_channel.rs, crates/ironclaw_reborn_composition/src/slack_host_beta.rs, crates/ironclaw_reborn_composition/src/slack_personal_binding_pairing_serve.rs, crates/ironclaw_webui_v2_static/src/assets.rs, crates/ironclaw_webui_v2_static/static/js/pages/extensions/components/channels-tab.js, crates/ironclaw_webui_v2_static/static/js/pages/extensions/components/channels-tab.test.mjs
Request builders now set explicit capability values; tests cover the forbidden operator-route path, operator-token connectable-channel responses, and the Slack built-in connect actions selector rename.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

Suggested reviewers

  • aiworkbot

Poem

A tiny flag on a caller’s sleeve,
Decides what routes may speak or leave.
Hidden channels, visible light,
The authenticator sets it right. 🦀

🚥 Pre-merge checks | ✅ 3 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description covers summary and tests, but omits most required template sections like Change Type, Linked Issue, Validation, and rollout details. Add the missing template sections: Change Type, Linked Issue, full Validation checklist, Security Impact, Trust-Boundary, Database Impact, Blast Radius, Rollback Plan, Review Follow-Through, and Review track.
✅ Passed checks (3 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly matches the main change: Slack admin setup visibility for WebUI operator tokens.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added the contributor: core 20+ merged PRs label Jun 24, 2026

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces an operator_webui_config capability flag to the WebUiAuthenticatedCaller struct, integrating it into authorization checks for Slack channel routes and connectable channel visibility. It ensures that operator-specific configurations and routes are restricted to callers with this capability enabled. The changes are well-supported by new and updated unit tests, and there is no additional feedback to provide.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

@serrrfirat
serrrfirat force-pushed the codex/slack-admin-token-visibility branch from cc5e75e to 6337e50 Compare June 24, 2026 11:09
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5185 June 24, 2026 11:09 Destroyed
@serrrfirat
serrrfirat force-pushed the codex/slack-admin-token-visibility branch from 6337e50 to 1216556 Compare June 24, 2026 11:20
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5185 June 24, 2026 11:20 Destroyed
@railway-app

railway-app Bot commented Jun 24, 2026

Copy link
Copy Markdown

🚅 Deployed to the ironclaw-pr-5185 environment in ironclaw-ci-preview

Service Status Web Updated (UTC)
ironclaw 🕒 Building (View Logs) Web Jun 24, 2026 at 11:20 am

@serrrfirat
serrrfirat merged commit f08f092 into main Jun 24, 2026
44 checks passed
@serrrfirat
serrrfirat deleted the codex/slack-admin-token-visibility branch June 24, 2026 11:40
BenKurrek added a commit that referenced this pull request Jun 24, 2026
…nfig capability

#5185 restricted the Slack admin routes to callers carrying the operator
webui-config capability (only the admin webui-v2 token may mutate admin
routes — intended, confirmed by the PR author). The four slack_host_beta
admin-route tests predate that gate and use operator_caller(), which never
set the flag, so they began returning 403 instead of 200. The forbidden
path already has dedicated coverage
(route_admin_rejects_operator_user_without_operator_capability); these four
verify admin-route *logic* for an authorized admin, so give operator_caller
the capability. Surfaced once reborn-tests resumed running (dead since #5081).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

This branch was successfully deployed

No deployments
ironclaw-ci-preview / ironclaw-pr-5185 — 1216556b Deployed Jun 24, 2026 by railway-app[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: low Changes to docs, tests, or low-risk modules size: L 200-499 changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant