Skip to content

CodeMower.com: Slack OAuth installation binding and policy store #918

Description

@jeffhuber

Part of #903.

Problem

Slack installations, organization membership, repository aliases, users, channels, and token lifecycle need an explicit hosted trust boundary.

Scope

Implement OAuth v2 state validation and HTTPS redirect handling, encrypted bot/refresh/signing-secret storage, one-organization installation binding, explicit member mapping, repository aliases, per-user action roles, channel allowlists, Slack Connect policy, disable/uninstall, and rotation. Provide an administrator setup/disable surface.

Dependencies

Acceptance criteria

  • Authorization uses immutable enterprise/team/app/user IDs, never names or email.
  • Cross-organization, unbound user, arbitrary repository, disallowed channel, and revoked installation requests fail closed.
  • Secrets are encrypted and absent from logs, exports, diagnostics, and OSS state.
  • Admin setup, rotation, disable, and deletion are exercised in a private test organization.

Code Mower delivery

Produce exactly one independently reviewable PR for this issue. Record the named builder, keep one writer on the branch, run focused tests and applicable full checks, obtain an independent Code Mower review against the exact current head, resolve every P0/P1/P2 finding, and pass normal CI plus code-mower/gate. Update the parent epic with PR/head, review, validation, outcome, and safe metadata-only upload evidence. Do not put credentials, source, diffs, prompts, transcripts, private context, task/message prose, or raw provider output in cloud data.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions