Part of #903.
Problem
Slack integration needs a provider-neutral contract before worker code so it does not become a second orchestrator or duplicate Devin-specific lifecycle logic.
Scope
Define command/modal surfaces, normalized remote-session mapping, installation/actor/repository/channel identities, visibility, authorization, idempotency keys, inbox/outbox transitions, private/public data split, retention, safe error taxonomy, and closed Board/cloud event schemas. Use official Slack signed-request, three-second acknowledgement, retry, OAuth, and rate-limit contracts.
Dependencies
Acceptance criteria
Code Mower delivery
Produce exactly one independently reviewable PR for this issue. Record the named builder, keep one writer on the branch, run focused tests and applicable full checks, obtain an independent Code Mower review against the exact current head, resolve every P0/P1/P2 finding, and pass normal CI plus code-mower/gate. Update the parent epic with PR/head, review, validation, outcome, and safe metadata-only upload evidence. Do not put credentials, source, diffs, prompts, transcripts, private context, task/message prose, or raw provider output in cloud data.
Part of #903.
Problem
Slack integration needs a provider-neutral contract before worker code so it does not become a second orchestrator or duplicate Devin-specific lifecycle logic.
Scope
Define command/modal surfaces, normalized remote-session mapping, installation/actor/repository/channel identities, visibility, authorization, idempotency keys, inbox/outbox transitions, private/public data split, retention, safe error taxonomy, and closed Board/cloud event schemas. Use official Slack signed-request, three-second acknowledgement, retry, OAuth, and rate-limit contracts.
Dependencies
Acceptance criteria
Code Mower delivery
Produce exactly one independently reviewable PR for this issue. Record the named builder, keep one writer on the branch, run focused tests and applicable full checks, obtain an independent Code Mower review against the exact current head, resolve every P0/P1/P2 finding, and pass normal CI plus
code-mower/gate. Update the parent epic with PR/head, review, validation, outcome, and safe metadata-only upload evidence. Do not put credentials, source, diffs, prompts, transcripts, private context, task/message prose, or raw provider output in cloud data.