Fix Slack admin setup visibility for WebUI operator tokens - #5185
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (11)
📝 WalkthroughSummary by CodeRabbit
Walkthrough
Changesoperator_webui_config capability gate
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~25 minutes Suggested reviewers
Poem
🚥 Pre-merge checks | ✅ 3 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (3 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. Comment |
There was a problem hiding this comment.
Code Review
This pull request introduces an operator_webui_config capability flag to the WebUiAuthenticatedCaller struct, integrating it into authorization checks for Slack channel routes and connectable channel visibility. It ensures that operator-specific configurations and routes are restricted to callers with this capability enabled. The changes are well-supported by new and updated unit tests, and there is no additional feedback to provide.
Important
The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.
cc5e75e to
6337e50
Compare
6337e50 to
1216556
Compare
|
🚅 Deployed to the ironclaw-pr-5185 environment in ironclaw-ci-preview
|
…nfig capability #5185 restricted the Slack admin routes to callers carrying the operator webui-config capability (only the admin webui-v2 token may mutate admin routes — intended, confirmed by the PR author). The four slack_host_beta admin-route tests predate that gate and use operator_caller(), which never set the flag, so they began returning 403 instead of 200. The forbidden path already has dedicated coverage (route_admin_rejects_operator_user_without_operator_capability); these four verify admin-route *logic* for an authorized admin, so give operator_caller the capability. Surfaced once reborn-tests resumed running (dead since #5081). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Summary
Railway notes
Tests