open-swe/agent/dashboard/slack_oauth.py
Johannes du Plessis 209132d355
refactor: durable interrupt dispatch + completion webhook (#1621)
* wip(rebuild): core reliability spine

- remove PR-babysitting (ci_autofix + ci_monitor graph + webhook wiring)
- dispatch core: agent/dispatch.py with multitask_strategy=interrupt +
  durability=sync + completion webhook; reroute all webhook + plan triggers;
  drop the racy in-process lock + is_thread_active busy-check
- completion webhook: agent/completion.py + /webhooks/run-complete loopback
  route for failure/timeout replies (idempotent)

Co-authored-by: open-swe[bot]

* feat(rebuild): async tools, reconcile, shared http timeouts, assembly tuning

Parallel batch on top of the reliability spine:
- async-ify all 24 tools (drop asyncio.run; requests->httpx); re-implement the
  http_request/fetch_url SSRF + DNS-rebinding defense httpx-natively and harden
  the IP check to 'not is_global' (+ IPv4-mapped unwrap)
- reconcile.py: stale pending-run sweep (threads.search -> per-thread runs.list
  -> cancel_many), wired into the scheduler graph via task='reconcile'
- shared DEFAULT_HTTP_TIMEOUT (agent/utils/http.py) on every bare
  httpx.AsyncClient() across utils/dashboard/webapp/middleware
- run budget: MODEL_CALL_RECURSION_LIMIT 5000->250
- fix stale OpenAI->Anthropic fallback id (claude-opus-4-5 -> 4-8)
- drop redundant custom repair middleware (deepagents auto-adds PatchToolCalls)
- confirm tool-result eviction + summarization auto-wired via backend
- slim system prompt ~8% (full harness-profile rewrite deferred)

Co-authored-by: open-swe[bot]

* feat(rebuild): harness-profile prompt + split webhooks out of webapp

- prompt.py: own the system prompt via a registered harness profile
  (OPEN_SWE_SHARED_BASE, kept neutral so the read-only reviewer/analyzer that
  share it stay safe), registered across all 4 providers; per-thread values
  stay in construct_system_prompt. Assembled main-agent prompt ~6.8k -> ~3.1k
  tokens (~55% smaller); de-duped PR/commit/suite/force-push guidance; dropped
  ALL-CAPS markers.
- webapp.py 3325 -> 1890 LOC: moved 14 per-source handlers into
  agent/webhooks/{linear,slack,github}.py; webapp re-exports them for the
  routes + tests; moved handlers reach shared helpers via the webapp namespace
  to preserve the test suite's monkeypatch targets.

Full suite: 1168 passing, lint clean.

Co-authored-by: open-swe[bot]

* Restore MODEL_CALL_RECURSION_LIMIT to 5000 for long-running tasks

Reverts the 250 cap from the run-budget change — long-running tasks legitimately
need many model calls. The notify_step_limit_reached safety net still fires if a
run does hit the cap, so runs end with a signal either way.

Co-authored-by: open-swe[bot]

* fix: address PR review (auth, SSRF, interrupted status, redirect headers)

- completion.py: drop `interrupted` from failure statuses — with
  multitask_strategy=interrupt a follow-up ends the prior run as interrupted,
  which is healthy, not a failure to report. [open-swe]
- /webhooks/run-complete: shared-secret auth — dispatch appends ?token= when
  RUN_COMPLETE_WEBHOOK_SECRET is set; route verifies via hmac.compare_digest.
  [corridor-security]
- SSRF: extract the URL validator to agent/utils/url_safety.py and apply it
  before server-side image fetches in multimodal.fetch_image_block.
  [corridor-security]
- http_request: preserve caller headers/extensions across redirect hops instead
  of dropping them on the first hop. [open-swe]

Co-authored-by: open-swe[bot]

* chore: remove REBUILD_PLAN.md (planning doc, not needed in the repo)

Co-authored-by: open-swe[bot]

* fix: fail closed on run-complete webhook auth when secret unset

Corridor follow-up: verify_run_complete_token returns False (not True) when
RUN_COMPLETE_WEBHOOK_SECRET is unset, so the public route is never
unauthenticated. Logs a startup warning when the secret is absent, and dispatch
skips registering the webhook when there's no secret (no rejected callbacks).

Co-authored-by: open-swe[bot]

---------

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-06-26 13:48:38 -07:00

119 lines
4.3 KiB
Python

"""Sign in with Slack (OpenID Connect) for self-service GitHub ⇄ Slack linking.
Reuses the existing Slack app — Sign in with Slack is a capability on the same
app that owns the bot token, so it only needs the ``openid email profile`` user
scopes, a redirect URL, and the app's client id/secret. The id_token/userInfo
claims give us a Slack-*verified* member id and email, so a logged-in GitHub
user can only ever link their own Slack identity (no self-asserted spoofing).
"""
from __future__ import annotations
import logging
import os
from dataclasses import dataclass
from typing import Any
from urllib.parse import urlencode
import httpx
from fastapi import HTTPException
from ..utils.http import DEFAULT_HTTP_TIMEOUT
logger = logging.getLogger(__name__)
SLACK_CLIENT_ID = os.environ.get("SLACK_CLIENT_ID", "")
SLACK_CLIENT_SECRET = os.environ.get("SLACK_CLIENT_SECRET", "")
# Optional: restrict linking to a single workspace (the Slack team id, T...).
SLACK_TEAM_ID = os.environ.get("SLACK_TEAM_ID", "")
SLACK_STATE_COOKIE_NAME = "osw_slack_oauth_state"
SLACK_OIDC_SCOPES = "openid email profile"
_AUTHORIZE_URL = "https://slack.com/openid/connect/authorize"
_TOKEN_URL = "https://slack.com/api/openid.connect.token"
_USERINFO_URL = "https://slack.com/api/openid.connect.userInfo"
_USER_ID_CLAIM = "https://slack.com/user_id"
_TEAM_ID_CLAIM = "https://slack.com/team_id"
def slack_oauth_configured() -> bool:
return bool(SLACK_CLIENT_ID and SLACK_CLIENT_SECRET)
@dataclass(frozen=True)
class SlackIdentity:
user_id: str
team_id: str
email: str | None
email_verified: bool
name: str | None
def build_authorize_url(*, redirect_uri: str, state: str) -> str:
params = {
"response_type": "code",
"scope": SLACK_OIDC_SCOPES,
"client_id": SLACK_CLIENT_ID,
"redirect_uri": redirect_uri,
"state": state,
}
if SLACK_TEAM_ID:
# Pre-selects the workspace so users can't accidentally sign in elsewhere.
params["team"] = SLACK_TEAM_ID
return f"{_AUTHORIZE_URL}?{urlencode(params)}"
def parse_slack_identity(data: dict[str, Any]) -> SlackIdentity:
"""Build a SlackIdentity from an openid.connect.userInfo response."""
if not data.get("ok", True):
raise HTTPException(400, f"slack userinfo failed: {data.get('error', 'unknown')}")
user_id = data.get(_USER_ID_CLAIM)
if not isinstance(user_id, str) or not user_id:
raise HTTPException(400, "slack userinfo missing user id")
team_id = data.get(_TEAM_ID_CLAIM)
email = data.get("email")
return SlackIdentity(
user_id=user_id,
team_id=team_id if isinstance(team_id, str) else "",
email=email if isinstance(email, str) and email else None,
email_verified=bool(data.get("email_verified")),
name=data.get("name") if isinstance(data.get("name"), str) else None,
)
def verify_team(identity: SlackIdentity) -> None:
"""Reject identities from a different workspace when one is configured."""
if SLACK_TEAM_ID and identity.team_id != SLACK_TEAM_ID:
raise HTTPException(403, "Slack account is not in the authorized workspace")
async def exchange_slack_code(code: str, redirect_uri: str) -> str:
"""Exchange an authorization code for a user access token."""
async with httpx.AsyncClient(timeout=DEFAULT_HTTP_TIMEOUT) as client:
resp = await client.post(
_TOKEN_URL,
data={
"client_id": SLACK_CLIENT_ID,
"client_secret": SLACK_CLIENT_SECRET,
"code": code,
"grant_type": "authorization_code",
"redirect_uri": redirect_uri,
},
)
resp.raise_for_status()
data = resp.json()
if not data.get("ok") or not data.get("access_token"):
raise HTTPException(400, f"slack oauth exchange failed: {data.get('error', 'unknown')}")
return data["access_token"]
async def fetch_slack_identity(access_token: str) -> SlackIdentity:
"""Resolve the signed-in Slack user's verified identity."""
async with httpx.AsyncClient(timeout=DEFAULT_HTTP_TIMEOUT) as client:
resp = await client.get(
_USERINFO_URL,
headers={"Authorization": f"Bearer {access_token}"},
)
resp.raise_for_status()
return parse_slack_identity(resp.json())