open-swe/agent
Johannes du Plessis c8a997c125
fix: reliable, safe Slack account-connect prompt + first-login Slack dialog (#1383)
* fix: deliver Slack account-link prompt as a visible threaded reply

Blocked Slack users got no prompt at all. Prod logs show chat.postEphemeral
returns ok, but ephemeral messages are silently dropped in Slack's assistant
threads (where Open SWE runs), so the user sees nothing. Post the prompt as a
normal threaded reply instead — the same channel the agent uses to reply.

* fix: deliver Slack auth-failure prompt as a visible threaded reply

leave_failure_comment() tried an ephemeral message first and only fell back
to a thread reply on failure. Ephemeral messages succeed (ok) but are dropped
in Slack's assistant threads, so the fallback never fired and the user saw no
auth-failure prompt. Post the visible threaded reply directly, matching the
account-link prompt fix.

* fix: prompt blocked Slack users with a generic, token-free dashboard link

Addresses the review findings that posting the per-user account-link token /
auth URL in a visible thread lets any channel member bind their GitHub account
to the triggering user's Slack identity.

Drop the per-user signed link entirely. Both the account-link prompt
(_post_account_link_prompt) and the runtime auth-failure prompt
(leave_failure_comment) now post a plain dashboard settings link
(build_settings_url) as a visible threaded reply. The user signs in with GitHub
from their own session and connects Slack via verified OIDC on the settings
page — no secret in the thread, nothing to hijack, and no DM machinery.

* feat: nudge first-time users to connect Slack from the dashboard home

Show a Connect Slack banner on the agents landing page whenever Slack OAuth is
enabled and the user hasn't linked Slack yet. A first-time user (no Slack
mapping) sees it immediately after signing in; it disappears once connected.

* feat: prompt first-time users to connect Slack via a dialog

Replace the inline Connect Slack card on the agents home with a modal dialog
(Base UI). It opens automatically once the mapping query resolves to
"not connected" and closes itself once Slack is linked; "Maybe later" dismisses
it for the session. No new dependency — uses the design system's Base UI.

* copy: frame Slack connect as resolving the user's GitHub account

Drop 'act/reply on your behalf' wording across the connect-Slack dialog, the
Slack thread prompts (blocked + auth-failure), and the settings description.
Connecting Slack lets Open SWE resolve the user's GitHub account when they tag
it in Slack.
2026-06-02 20:55:07 -07:00
..
dashboard fix: reliable, safe Slack account-connect prompt + first-login Slack dialog (#1383) 2026-06-02 20:55:07 -07:00
integrations feat: add idle TTL and delete-after-stop sandbox lifecycle controls (#1265) 2026-05-08 00:30:14 -04:00
middleware fix: sanitize malformed Anthropic thinking blocks (#1357) 2026-05-28 16:15:13 -07:00
skills feat: outcomes dataset + bootstrap/continual split via skills (#1365) 2026-06-01 13:25:12 -07:00
tools feat: open PRs as the triggering user via dedicated tool (#1378) 2026-06-02 16:01:54 -07:00
utils fix: reliable, safe Slack account-connect prompt + first-login Slack dialog (#1383) 2026-06-02 20:55:07 -07:00
analyzer.py feat: outcomes dataset + bootstrap/continual split via skills (#1365) 2026-06-01 13:25:12 -07:00
encryption.py feat: support TOKEN_ENCRYPTION_KEY rotation via MultiFernet [closes AB-2323] (#1275) 2026-05-08 14:29:23 -07:00
prompt.py feat: simplify PR attribution footer to "Made by Open SWE" (#1382) 2026-06-02 19:52:27 -07:00
review_style_collector.py feat: tune reviewer for precision — web/wiki tools + recalibrated prompt (#1312) 2026-05-20 18:35:00 +00:00
review_style_guidance.py feat: tune reviewer for precision — web/wiki tools + recalibrated prompt (#1312) 2026-05-20 18:35:00 +00:00
reviewer.py feat: Inject PR title and body into reviewer context (#1368) 2026-06-01 21:06:19 +00:00
reviewer_diff.py feat: Inject PR title and body into reviewer context (#1368) 2026-06-01 21:06:19 +00:00
reviewer_findings.py feat: let reviewer set comment titles (#1356) 2026-05-28 16:04:38 -07:00
reviewer_publish.py feat: let reviewer set comment titles (#1356) 2026-05-28 16:04:38 -07:00
reviewer_reconcile.py feat: let reviewer set comment titles (#1356) 2026-05-28 16:04:38 -07:00
server.py feat: open PRs as the triggering user via dedicated tool (#1378) 2026-06-02 16:01:54 -07:00
webapp.py fix: reliable, safe Slack account-connect prompt + first-login Slack dialog (#1383) 2026-06-02 20:55:07 -07:00