Skip to content

Expose safe Slack OAuth exchange diagnostics - #369

Merged
ericlovold merged 1 commit into
mainfrom
codex/slack-oauth-diagnostics
Oct 9, 2026
Merged

ericlovold merged 1 commit into
mainfrom
codex/slack-oauth-diagnostics

Conversation

@ericlovold

@ericlovold ericlovold commented Oct 9, 2026 •

Copy link
Copy Markdown
Owner

Slack installation failures all displayed “Slack did not return a bot token,” including configuration, network, and exchange rejections. Return a typed result with fixed diagnostic codes and show corresponding dashboard messages so the next live attempt can identify the failure category.

Known Slack errors are allowlisted. Unknown errors, response bodies, exception messages, tokens, client secrets, and authorization codes are never reflected into redirects. Existing token/channel validation and approval permissions are unchanged.

Validation: npm run check passed: typecheck, lint (warnings only), 1,900 tests; 56 DB tests skipped. Added failure classification, timeout, missing configuration, and redirect secret-leak tests. Browser rendering not checked. The production install cause remains unverified until deployment and a fresh consent attempt.


Note

Medium Risk
Touches OAuth token exchange and redirect query parameters for Slack install, but failures are constrained to fixed codes with tests guarding against secret leakage; successful install and permission checks are unchanged.

Overview
Replaces the generic Slack install failure path with typed, bounded OAuth diagnostics so admins see why token exchange failed instead of a single “no bot token” message.

exchangeSlackCode now returns a discriminated SlackExchangeResult with fixed error codes (missing config, allowlisted Slack API errors, HTTP/JSON/network/timeout, and post-success validation gaps like missing bot token or channel). The OAuth callback redirects to slack=oauth_<code> on failure; WebhookSettings maps each code to a specific user-facing explanation. Sensitive Slack payloads, secrets, codes, and arbitrary error strings are not echoed into redirect URLs.

Tests cover failure classification, timeout handling, missing configuration, and redirects that only expose bounded diagnostics.

Reviewed by Cursor Bugbot for commit de6d47f. Bugbot is set up for automated code reviews on this repo. Configure here.

@cursor

cursor Bot commented Oct 9, 2026

Copy link
Copy Markdown

Bugbot couldn't run - usage limit reached

Bugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit.

A user or team admin can review and increase usage limits in the Cursor dashboard.

(requestId: c8bc63ab-2df7-45bc-8aaa-ade72e29f011)

@coderabbitai

coderabbitai Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration
  • Configuration used: Repository: ericlovold/sanction/.coderabbit.yaml
  • Review profile: ASSERTIVE
  • Plan: Essentials
  • Run ID: 8ad0ae71-01b8-4a99-9946-b0620004bde5

📥 Commits

Reviewing files that changed from the base of the PR and between d28f503 and de6d47f.


📒 Files selected for processing (5)
  • app/api/slack/oauth/callback/route.ts
  • components/webhook-settings.tsx
  • lib/slackOAuth.ts
  • tests/slack-oauth.route.test.ts
  • tests/slack-oauth.test.ts

 ___________________________________________________________________________
< In Vino Veritas, In Codice Bugas. In wine, there is truth; in code, bugs. >
 ---------------------------------------------------------------------------
  \
   \   \
        \ /\
        ( )
      .( o ).
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR


  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved. Cursor Bugbot was skipped (usage limit), so that signal was not used; no approval policy or existing review state requires human review. No reviewers were assigned.

Open in Web View Automation 

Sent by Cursor Approval Agent: Pull Request Router and Approver

@ericlovold
ericlovold merged commit 236b556 into main Oct 9, 2026
8 of 9 checks passed

This branch was successfully deployed

1 active deployment
Preview — de6d47f9 Deployed Oct 9, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant