Skip to content

Commit 2071b46

Browse files
fix(slack): restrict list ownership to user recipients
1 parent 574b0e2 commit 2071b46

3 files changed

Lines changed: 25 additions & 3 deletions

File tree

‎apps/sim/blocks/blocks/slack-resources.test.ts‎

Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,7 @@
22
import { describe, expect, it } from 'vitest'
33
import { SLACK_MANAGED_USER_SCOPES } from '@/lib/credential-groups/slack-managed-user-scopes'
44
import { getScopesForService } from '@/lib/oauth/utils'
5+
import { getSubBlocksDependingOnChange } from '@/lib/workflows/subblocks/dependencies'
56
import { evaluateSubBlockCondition } from '@/lib/workflows/subblocks/visibility'
67
import { getSlackV2ActionSubBlocks, SlackBlock, SlackV2Block } from '@/blocks/blocks/slack'
78
import { buildSlackManifest } from '@/triggers/slack/capabilities'
@@ -28,6 +29,24 @@ function mapParams(params: Record<string, unknown>) {
2829
}
2930

3031
describe('Slack List and Canvas operations', () => {
32+
it('only offers List ownership for user recipients', () => {
33+
const options = SlackV2Block.subBlocks.find((field) => field.id === 'listAccessLevel')!.options
34+
if (typeof options !== 'function') throw new Error('Expected recipient-aware access levels')
35+
expect(options({ values: { listShareTarget: 'channels' } }).map(({ id }) => id)).toEqual([
36+
'read',
37+
'write',
38+
])
39+
expect(options({ values: { listShareTarget: 'users' } }).map(({ id }) => id)).toEqual([
40+
'read',
41+
'write',
42+
'owner',
43+
])
44+
expect(options().map(({ id }) => id)).toContain('owner')
45+
expect(
46+
getSubBlocksDependingOnChange(SlackV2Block.subBlocks, 'listShareTarget').map(({ id }) => id)
47+
).toContain('listAccessLevel')
48+
})
49+
3150
it('shares with only the selected recipient kind and defaults to view access', () => {
3251
expect(
3352
mapParams({

‎apps/sim/blocks/blocks/slack.ts‎

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3349,10 +3349,13 @@ function getSlackV2ListSubBlocks(): SubBlockConfig[] {
33493349
id: 'listAccessLevel',
33503350
title: 'Access Level',
33513351
type: 'dropdown',
3352-
options: [
3352+
dependsOn: ['listShareTarget'],
3353+
options: ({ values } = { values: {} }) => [
33533354
{ label: 'Can view', id: 'read' },
33543355
{ label: 'Can edit', id: 'write' },
3355-
{ label: 'Owner (users only)', id: 'owner' },
3356+
...(values.listShareTarget === 'channels'
3357+
? []
3358+
: [{ label: 'Owner (users only)', id: 'owner' }]),
33563359
],
33573360
value: () => 'read',
33583361
required: true,

‎apps/sim/ee/credential-groups/components/slack-managed-users-access.test.tsx‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -357,7 +357,7 @@ describe('Slack member access selection', () => {
357357
expect(dialog).toBeDefined()
358358
expect(dialog?.querySelector('input[placeholder="Sim Bot"]')).not.toBeNull()
359359
expect(dialog?.textContent).toContain('Additional permissions')
360-
expect(dialog?.textContent).toContain('18 selected')
360+
expect(dialog?.textContent).toContain('All additional permissions enabled')
361361
expect(dialog?.textContent).not.toContain('Member access')
362362
expect(dialog?.textContent).toContain('Slash commands')
363363
await clickButton('Close', dialog)

0 commit comments

Comments
 (0)