Skip to content

fix(slack): honor implicit Search approval during authorization - #8548

Merged
waleedlatif1 merged 2 commits into
stagingfrom
codex/fix-slack-implicit-search-approval
Oct 1, 2026
Merged

waleedlatif1 merged 2 commits into
stagingfrom
codex/fix-slack-implicit-search-approval

Conversation

@waleedlatif1

@waleedlatif1 waleedlatif1 commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Use the shared Search approval policy when choosing and verifying Slack OAuth scopes. Existing live sources retain implicit approval; explicit denial stays authoritative and detached sources no longer grant approval.
  • Serialize OAuth completion with explicit approval decisions, source creation/removal, and index archive/restore using the existing transaction advisory-lock helper. Acquire the organization lock before resource row locks.

Type of Change

  • Bug fix

Testing

  • 38 real PostgreSQL/Redis integration tests pass. Regressions reproduce stale implicit approval, retained-document removal, and concurrent source/index/approval changes; independent negative controls verify the new guards. JSON reports generated.
  • 172 focused tests pass across Slack authorization, connector/index lifecycle, Search approvals, and account access.
  • Type-check, lint, all 54 audits, block-registry audit, and docs-manifest check pass. Committed-artifact generators completed.

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing (new tests pass the test-audit authoring gate)
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

@vercel

vercel Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
docs Skipped Skipped Oct 1, 2026 10:53pm UTC

Request Review

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 3 files

Reply with feedback, questions, or to request a fix.

Fix all with cubic | Re-trigger cubic

Comment thread apps/sim/lib/credential-groups/slack-managed-users.ts
@greptile-apps

greptile-apps Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[High risk] Adds locking around organization search approval state.

The PR appears safe to merge; no outstanding findings remain.

Summary

The PR aligns Slack authorization scopes with the shared Search approval policy and rechecks approval before saving consent. The follow-up changes exclude detached connectors and serialize consent with connector, index, and explicit-approval changes.

  • Adds integration coverage for implicit approval, removal, and concurrent lifecycle changes.
Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart LR
  A[Start Slack authorization] --> B[Read Search approval and choose scopes]
  B --> C[Slack consent]
  C --> D[Acquire organization approval lock]
  D --> E[Recheck approval in transaction]
  E -->|unchanged| F[Save credential group configuration]
  E -->|changed| G[Reject stale consent]
  H[Connector, index, or approval change] --> D
Loading

Reviews (2) · Last reviewed commit: "fix(slack): serialize Search approval ch..."

Comment thread apps/sim/lib/credential-groups/slack-managed-users.ts
Comment thread apps/sim/lib/credential-groups/slack-managed-users.ts
@waleedlatif1
waleedlatif1 force-pushed the codex/fix-slack-implicit-search-approval branch from 0864b1b to d424921 Compare October 1, 2026 22:53
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 7 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@waleedlatif1
waleedlatif1 merged commit d3f0d26 into staging Oct 1, 2026
25 checks passed
@waleedlatif1
waleedlatif1 deleted the codex/fix-slack-implicit-search-approval branch October 1, 2026 22:58

This branch was previously deployed

1 inactive deployment
Preview — d4249215 Deployed Oct 1, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant