Skip to content

fix(slack): verify Search permissions before changing active grants - #8545

Merged
waleedlatif1 merged 3 commits into
stagingfrom
codex/fix-slack-search-permission-upgrade
Oct 1, 2026
Merged

waleedlatif1 merged 3 commits into
stagingfrom
codex/fix-slack-search-permission-upgrade

Conversation

@waleedlatif1

@waleedlatif1 waleedlatif1 commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Preserve active Slack connections while Search permissions await verification, including cancellation and incomplete consent.
  • Commit verified permissions atomically and reject callbacks after approval changes in either direction without dropping existing workflow or custom scopes.
  • Show when Search permissions still need verification and keep workflow-only setup usable.

Type of Change

  • Bug fix

Testing

  • search-mcp-setup.integration.ts: 29 tests passed against disposable PostgreSQL and Redis with Slack HTTP fixtures; JSON integration report generated. Regression cases fail before the fix, and each new guard was independently disabled to verify its regression.
  • 75 tests passed across service.test.ts, slack-managed-users.test.ts (manager and application), organization-provider-setup.test.ts, slack-provider.test.ts, live-search-settings.test.tsx, and live-member-integrations.test.tsx.
  • bun run type-check, bun run lint, all 54 check:audits, block registry audit, and docs-manifest:check passed. Committed-artifact generators ran successfully.

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing (new tests pass the test-audit authoring gate)
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

@vercel

vercel Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
docs Skipped Skipped Oct 1, 2026 10:06pm UTC

Request Review

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@greptile-apps

greptile-apps Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 4/5

[Critical risk] Adds permission checks to Slack Search credential grants.

The PR should not merge until verification requests Search scopes for organizations whose existing Slack connector supplies implicit approval.

Findings

  1. P1 Implicit approval omits Search scopes ▶

Summary

This PR preserves existing Slack connections while Search permissions await verified consent, then updates the scope policy after verification. It also adds approval-state checks, setup indicators, and integration coverage.

Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart LR
  A[Start Slack authorization] --> B[Read approval and request scopes]
  B --> C[Slack consent]
  C --> D{Consent verified and approval unchanged?}
  D -- No --> E[Keep existing grants]
  D -- Yes --> F[Commit scopes and mark affected grants for reauthorization]
Loading

Reviews (4) · Last reviewed commit: "chore(tests): require Redis for Slack au..."

Comment thread apps/sim/lib/credential-groups/slack-managed-users.ts Outdated

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 9 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 9 files

Reply with feedback, questions, or to request a fix.

Fix all with cubic | Re-trigger cubic

Comment thread apps/sim/lib/credential-groups/slack-managed-users.ts
Comment thread apps/sim/lib/knowledge/__integration__/search-mcp-setup.integration.ts Outdated
@waleedlatif1
waleedlatif1 force-pushed the codex/fix-slack-search-permission-upgrade branch from e93c56c to 6d51c0e Compare October 1, 2026 21:58
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 9 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@waleedlatif1
waleedlatif1 force-pushed the codex/fix-slack-search-permission-upgrade branch from 6d51c0e to f66dd3f Compare October 1, 2026 22:06
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@waleedlatif1
waleedlatif1 merged commit a1ef625 into staging Oct 1, 2026
4 of 5 checks passed
@cubic-dev-ai

cubic-dev-ai Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@waleedlatif1
waleedlatif1 deleted the codex/fix-slack-search-permission-upgrade branch October 1, 2026 22:07

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 9 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

Comment thread apps/sim/lib/credential-groups/slack-managed-users.ts

This branch was previously deployed

1 inactive deployment
Preview — f66dd3fe Deployed Oct 1, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant