Skip to content

[codex] Fix Reborn WebUI v2 Slack connect canary - #5485

Merged
serrrfirat merged 1 commit into
mainfrom
codex/reborn-webui-v2-canary-slack-connect
Jul 1, 2026
Merged

serrrfirat merged 1 commit into
mainfrom
codex/reborn-webui-v2-canary-slack-connect

Conversation

@serrrfirat

Copy link
Copy Markdown
Collaborator

Summary

  • changes Slack connect live QA cases to use the real WebUI v2 Extensions > Channels surface
  • validates /api/webchat/v2/channels/connectable exposes Slack inbound proof-code metadata
  • adds a regression test so the canary does not return to the removed chat Connect Slack card flow

Root cause

The canary still drove the old chat-triggered Slack connect prompt and waited for Connect Slack. WebUI v2 now exposes Slack connect through Extensions > Channels, so the scheduled canary could send the prompt to the model and fail waiting for the obsolete card.

Validation

  • python3 -m py_compile scripts/reborn_webui_v2_live_qa/run_live_qa.py scripts/reborn_webui_v2_live_qa/test_run_live_qa.py
  • python3 scripts/reborn_webui_v2_live_qa/test_run_live_qa.py

@coderabbitai

coderabbitai Bot commented Jul 1, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Summary by CodeRabbit

  • Bug Fixes

    • Updated the Slack connection QA flow to use the extensions channel selection experience, with clearer validation of available Slack connection options and related on-screen details.
  • Tests

    • Added coverage to ensure the Slack connection path opens the correct surface and displays the expected channel and account connection text.

Walkthrough

The Slack connect QA case in the Live QA runner was rewritten to validate the extensions "connectable channels" page and API instead of the chat composer flow, checking for the Slack inbound_proof_code strategy UI fields. A corresponding unit test was added to verify the new navigation and detail assertions.

Changes

Slack Connect Extensions Channels QA

Layer / File(s) Summary
Slack connect action rewritten
scripts/reborn_webui_v2_live_qa/run_live_qa.py
_slack_connect_case now navigates to /v2/extensions/channels, fetches /api/webchat/v2/channels/connectable, filters Slack entries, asserts inbound_proof_code strategy title/instructions, and records new observed telemetry replacing the old chat-composer flow.
New unit test for extensions channels flow
scripts/reborn_webui_v2_live_qa/test_run_live_qa.py
Adds test_slack_connect_case_uses_extensions_channels_surface, stubbing navigation and API responses to assert correct navigation target, endpoint fetch, expected UI text, absence of /v2/chat navigation, and ProbeResult.details fields.

Estimated code review effort: 2 (Simple) | ~15 minutes

Possibly related PRs

  • nearai/ironclaw#5463: Removes chat-triggered Slack connect components and command parsing, complementing this PR's shift to the extensions channels connect flow.

Review flags (Rust invariants n/a): This diff touches Python QA scripts only; no Rust sandbox/trust/secrets/egress/migration surfaces are implicated. No CLAUDE.md/AGENTS.md rule violations observed in scope.

🚥 Pre-merge checks | ✅ 3 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description covers summary, root cause, and validation, but omits required template sections like Change Type, Linked Issue, Security, Blast Radius, Rollback Plan, and Review track. Fill the missing template sections, or mark non-applicable ones as N/A, and add the review track plus security/database/trust-boundary details.
✅ Passed checks (3 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly matches the Slack connect canary change, though it does not follow the preferred Conventional Commits style.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5485 July 1, 2026 07:23 Destroyed
@github-actions github-actions Bot added size: M 50-199 changed lines risk: low Changes to docs, tests, or low-risk modules contributor: core 20+ merged PRs labels Jul 1, 2026
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Warning

Gemini encountered an error creating the review. You can try again by commenting /gemini review.

@serrrfirat
serrrfirat marked this pull request as ready for review July 1, 2026 07:25

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@scripts/reborn_webui_v2_live_qa/test_run_live_qa.py`:
- Around line 89-227: Add a negative-path test for `_slack_connect_case` to
cover the new failure branch when the connectable channels API does not return
an `inbound_proof_code` Slack entry. Reuse the existing test scaffolding in
`test_slack_connect_case_uses_extensions_channels_surface` with `FakePage`,
`fake_fetch_webui_json`, and `LiveQaContext`, but have the fake API response
omit that strategy and assert the case returns `success=False` with the expected
missing-entry AssertionError in `result.details`.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: df33982c-de2b-449c-b441-b5a4781cdb7e

📥 Commits

Reviewing files that changed from the base of the PR and between 940ca7a and b8548f3.

📒 Files selected for processing (2)
  • scripts/reborn_webui_v2_live_qa/run_live_qa.py
  • scripts/reborn_webui_v2_live_qa/test_run_live_qa.py

Comment on lines +89 to +227
def test_slack_connect_case_uses_extensions_channels_surface(self):
class FakePage:
def __init__(self) -> None:
self.gotos: list[tuple[str, str | None]] = []

async def goto(self, url: str, wait_until: str | None = None) -> None:
self.gotos.append((url, wait_until))

def locator(self, selector: str) -> str:
return selector

class FakeExpectation:
def __init__(self, selector: str) -> None:
self.selector = selector

async def to_contain_text(
self,
text: str,
timeout: int | None = None,
) -> None:
expected_texts.append((self.selector, text, timeout))

def fake_expect(selector: str) -> FakeExpectation:
return FakeExpectation(selector)

async def fake_with_page(
_output_dir: Path,
_case_name: str,
action,
) -> None:
await action(fake_page)

async def fake_fetch_webui_json(_page: object, path: str) -> dict[str, object]:
fetched_paths.append(path)
return {
"channels": [
{
"channel": "slack",
"display_name": "Slack",
"strategy": "admin_managed_channels",
"action": {"title": "Choose Slack channel"},
},
{
"channel": "slack",
"display_name": "Slack",
"strategy": "inbound_proof_code",
"action": {
"title": "Slack account connection",
"instructions": "Message the Slack app, then enter the code here.",
},
},
]
}

with tempfile.TemporaryDirectory() as tmpdir:
output_dir = Path(tmpdir)
(output_dir / "preflight.json").write_text(
json.dumps(
{
"checks": {
"slack": {
"enabled_in_config": True,
"env_present": True,
"auth_test": {
"ok": True,
"team_id": "T123",
"user_id": "U123",
},
}
}
}
),
encoding="utf-8",
)
fake_page = FakePage()
fetched_paths: list[str] = []
expected_texts: list[tuple[str, str, int | None]] = []
playwright_module = types.ModuleType("playwright")
playwright_async_api = types.ModuleType("playwright.async_api")
playwright_async_api.expect = fake_expect
ctx = run_live_qa.LiveQaContext(
base_url="http://127.0.0.1:3000",
output_dir=output_dir,
reborn_home=output_dir / "reborn-home",
env={},
)

with (
patch.dict(
sys.modules,
{
"playwright": playwright_module,
"playwright.async_api": playwright_async_api,
},
),
patch.object(run_live_qa, "_with_page", new=fake_with_page),
patch.object(
run_live_qa,
"_fetch_webui_json",
new=fake_fetch_webui_json,
),
):
result = asyncio.run(
run_live_qa._slack_connect_case(
ctx,
case_name="qa_3a_slack_connect",
)
)

self.assertTrue(result.success, result.details)
self.assertEqual(
fake_page.gotos,
[
(
"http://127.0.0.1:3000/v2/extensions/channels?"
f"token={run_live_qa.AUTH_TOKEN}",
"domcontentloaded",
)
],
)
self.assertEqual(
fetched_paths,
["/api/webchat/v2/channels/connectable"],
)
observed_expectations = [text for _selector, text, _timeout in expected_texts]
self.assertIn("Channels", observed_expectations)
self.assertIn("Slack account connection", observed_expectations)
self.assertIn("Message the Slack app", observed_expectations)
self.assertNotIn("Connect Slack", observed_expectations)
self.assertFalse(any("/v2/chat" in url for url, _wait in fake_page.gotos))
self.assertEqual(
result.details["slack_connect_surface"],
"/v2/extensions/channels",
)
self.assertEqual(
result.details["slack_connect_title"],
"Slack account connection",
)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🔵 Trivial | ⚡ Quick win

LGTM! Solid regression coverage for the extensions-channels rewrite; the assertNotIn("Connect Slack", ...) check directly guards against reverting to the removed chat flow.

Optional: a companion case where the fake API omits the inbound_proof_code strategy (verifying _slack_connect_case returns success=False with the "missing" AssertionError) would round out coverage for the new failure branch, but not blocking.

🧰 Tools
🪛 ast-grep (0.44.0)

[info] 145-159: use jsonify instead of json.dumps for JSON output
Context: json.dumps(
{
"checks": {
"slack": {
"enabled_in_config": True,
"env_present": True,
"auth_test": {
"ok": True,
"team_id": "T123",
"user_id": "U123",
},
}
}
}
)
Note: [CWE-116] Improper Encoding or Escaping of Output.

(use-jsonify)


[warning] 169-169: Configuring an LLM/agent client endpoint over http:// sends prompts and responses (and often API keys) in cleartext, exposing them to interception. Use https for the base_url.
Context: base_url="http://127.0.0.1:3000"
Note: [CWE-319] Cleartext Transmission of Sensitive Information.

(llm-client-insecure-http-python)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@scripts/reborn_webui_v2_live_qa/test_run_live_qa.py` around lines 89 - 227,
Add a negative-path test for `_slack_connect_case` to cover the new failure
branch when the connectable channels API does not return an `inbound_proof_code`
Slack entry. Reuse the existing test scaffolding in
`test_slack_connect_case_uses_extensions_channels_surface` with `FakePage`,
`fake_fetch_webui_json`, and `LiveQaContext`, but have the fake API response
omit that strategy and assert the case returns `success=False` with the expected
missing-entry AssertionError in `result.details`.

@railway-app

railway-app Bot commented Jul 1, 2026

Copy link
Copy Markdown

🚅 Deployed to the ironclaw-pr-5485 environment in ironclaw-ci-preview

Service Status Web Updated (UTC)
ironclaw ✅ Success (View Logs) Web Jul 1, 2026 at 7:23 am

@serrrfirat
serrrfirat merged commit 9e69f86 into main Jul 1, 2026
33 checks passed
@serrrfirat
serrrfirat deleted the codex/reborn-webui-v2-canary-slack-connect branch July 1, 2026 07:41

This branch was successfully deployed

No deployments
ironclaw-ci-preview / ironclaw-pr-5485 — b8548f30 Deployed Jul 1, 2026 by railway-app[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: low Changes to docs, tests, or low-risk modules size: M 50-199 changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant