mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-09-30 20:53:15 +00:00
* feat: open Slack-triggered PRs as the triggering user Route the Slack per-user GitHub token through the dashboard OAuth store (the backend the self-service link prompt populates) and block runs that lack a valid user token, prompting the user to (re-)link. Per-user OAuth now wins over bot-token-only mode for mapped Slack/dashboard users. Flip commit/PR authorship across all sources: the triggering user is the commit author (via repo-local git identity using their resolvable GitHub noreply email) and open-swe[bot] is the Co-authored-by collaborator. * fix: address PR review — shell-escape commit identity, fix token cache impersonation - Shell-escape the triggering user's name/email with shlex.quote before embedding them in the repo-setup `git config` command, so a name like O'Connor (or a crafted one) can't break or inject into the command. - Stop consulting the shared thread-metadata token cache in _resolve_dashboard_user_token. Slack thread ids are shared across the conversation, so a cached token from a prior triggering user could be returned for the current github_login. Always resolve by login from the dashboard OAuth store instead. * feat: dashboard self-service user mapping + UI cleanup - Add session-scoped GET/PUT /dashboard/api/my-mapping so users can set their own work email / Slack member ID (keyed by their GitHub login, source=self). - Slack account-link prompt now redirects to Profile Settings after auth. - Rename "My Settings" -> "Profile Settings" and "Cloud Agents" -> "Open SWE Agent"; remove the Integrations tab/section (folded out, low value for now) and redirect /integrations to Profile Settings. - Add a "User mapping" section to Profile Settings (work email used by Slack and Linear, optional Slack member ID). - Make dashboard auth cookies scheme-aware: Secure;SameSite=None over HTTPS, non-Secure;SameSite=Lax over http://localhost so local login works. * feat: self-service Slack account linking via Sign in with Slack (OIDC) Replace the spoofable manual work-email/Slack-ID form with a verified "Sign in with Slack" flow so a logged-in GitHub user can only ever link their own Slack identity. - New agent/dashboard/slack_oauth.py: OIDC authorize URL, code exchange, userInfo identity parse, optional workspace gate, configured check. - routes.py: session-gated GET /slack/login and /slack/callback that upsert the mapping from Slack-verified user_id + email (source=slack_oauth). Remove the spoofable PUT /my-mapping; expose slack_oauth_enabled on /me. - UI: drop the editable inputs; add a Connect Slack button + status to the User mapping section. Admin-managed mappings are unaffected and still resolve at trigger time. |
||
|---|---|---|
| .. | ||
| middleware | ||
| conftest.py | ||
| test_account_link.py | ||
| test_account_link_completion.py | ||
| test_agent_subagent_models.py | ||
| test_analyzer_cron.py | ||
| test_analyzer_skills.py | ||
| test_anthropic_effort.py | ||
| test_auth_sources.py | ||
| test_authorship.py | ||
| test_dashboard_message_adapter.py | ||
| test_dashboard_org_login_gate.py | ||
| test_dashboard_run_email.py | ||
| test_daytona_integration.py | ||
| test_encryption.py | ||
| test_ensure_no_empty_msg.py | ||
| test_github_comment_prompts.py | ||
| test_github_feedback.py | ||
| test_github_issue_webhook.py | ||
| test_github_oauth_refresh.py | ||
| test_github_token_ttl.py | ||
| test_google_model.py | ||
| test_http_security.py | ||
| test_langsmith_sandbox_config.py | ||
| test_model_fallback_middleware.py | ||
| test_model_fallback_resolution.py | ||
| test_multimodal.py | ||
| test_normalize_repo.py | ||
| test_notify_step_limit_middleware.py | ||
| test_pr_ready_auto_review.py | ||
| test_proxy_auth.py | ||
| test_public_repo_org_gate.py | ||
| test_recent_comments.py | ||
| test_refresh_slack_status_middleware.py | ||
| test_repo_extraction.py | ||
| test_review_style_collector.py | ||
| test_review_style_sync.py | ||
| test_review_styles_store.py | ||
| test_reviewer.py | ||
| test_reviewer_diff.py | ||
| test_reviewer_eval_run.py | ||
| test_reviewer_eval_target.py | ||
| test_reviewer_findings.py | ||
| test_reviewer_outcomes.py | ||
| test_reviewer_publish.py | ||
| test_reviewer_reconcile.py | ||
| test_reviewer_tools.py | ||
| test_reviewer_watch.py | ||
| test_sandbox_paths.py | ||
| test_sanitize_thinking_blocks.py | ||
| test_sanitize_tool_inputs.py | ||
| test_slack_assistants_status.py | ||
| test_slack_context.py | ||
| test_slack_feedback.py | ||
| test_slack_oauth.py | ||
| test_slack_thread_reply_tool.py | ||
| test_stale_sandbox_creating.py | ||
| test_user_mappings.py | ||