The Socket Mode inbound listener crashed at registration time on first live
run: `@app.action({})` raised `BoltError: action ({}) must be any of str,
Pattern, and dict` under slack_bolt 1.28.0, killing the listener thread (the
whole inbound answer path — message/app_mention/block_actions — went down,
caught only by the coordinator's respawn watchdog). serve() is marked
`# pragma: no cover - live socket`, so this was never exercised until the R720
bring-up. Replace the unsupported empty-dict matcher with a catch-all
`re.compile(r".*")` action_id regex; handle_event still does the real filtering
+ AUTHZ-01 owner-allowlist gate, so over-matching is safe.
Verified on sh-secrev: listener connects (live Socket Mode WebSocket), outbound
chat.postMessage works, 0 errors. /sh-security-review PASS (no confirmed
critical/high; matcher change introduces no new findings).
Also adds the dedicated Slack app (manifest + README) backing the clarifier
gate — "Sea Haven agent-team" (A0BC7AT8NUD), workspace-scoped install to avoid
the Enterprise-Grid `scope_not_allowed_on_enterprise` org-install trap — and
patches the provisioning runbook's stale langgraph pin (1.1.10 -> 1.2.5).
40 lines
857 B
JSON
40 lines
857 B
JSON
{
|
|
"display_information": {
|
|
"name": "Sea Haven agent-team",
|
|
"description": "Human-gated clarifier for the R720 agent-team SDLC pipeline (Plane-2 coordinator).",
|
|
"background_color": "#0c4f6f"
|
|
},
|
|
"features": {
|
|
"bot_user": {
|
|
"display_name": "agent-team",
|
|
"always_online": true
|
|
}
|
|
},
|
|
"oauth_config": {
|
|
"scopes": {
|
|
"bot": [
|
|
"chat:write",
|
|
"channels:history",
|
|
"groups:history",
|
|
"im:history",
|
|
"app_mentions:read"
|
|
]
|
|
}
|
|
},
|
|
"settings": {
|
|
"event_subscriptions": {
|
|
"bot_events": [
|
|
"message.channels",
|
|
"message.groups",
|
|
"message.im",
|
|
"app_mention"
|
|
]
|
|
},
|
|
"interactivity": {
|
|
"is_enabled": true
|
|
},
|
|
"socket_mode_enabled": true,
|
|
"org_deploy_enabled": false,
|
|
"token_rotation_enabled": false
|
|
}
|
|
}
|