Skip to content

Require joining Slack as part of Weave membership #118

Description

@Adambomb210

Problem

Having a Weave account doesn't mean someone is a full member of the Patchwork Labs Slack, but downstream apps assume it does.

  • /signup is open to anyone with a verified email (config/routes.rb).
  • After confirming their email, a new user is invited as a single-channel guest, confined to the code-of-conduct channel (app/jobs/invite_to_slack_job.rb). They're promoted to a full member only after accepting the CoC (SlackCodeOfConductAcceptedJob).
  • Some users never accept the invite, so they never get a slack_id.

This breaks Krater, the Project Ganymede portal. It creates a private Slack channel for each submitted project and invites the submitter. Slack's conversations.invite refuses single-channel guests (ura_max_channels), and users who aren't in Slack can't be invited at all.

Proposal

Make joining Slack (as a full member with the CoC accepted) a required step of becoming a member, rather than an optional side effect of signup.

  1. Add an explicit membership state, e.g. pending_slack → member, driven by the existing invite and CoC-acceptance flow. Users who were imported from Slack as full members, or who already have a slack_id and aren't guests, start as member.
  2. Show pending users where they are in onboarding ("accept your Slack invite", "accept the code of conduct"), and let them resend the invite.
  3. Expose the result to OAuth clients so they don't have to re-check Slack themselves. Either:
    • a slack_member boolean claim, plus a slack_id claim (the column already exists), or
    • a groups claim that includes something like community:member only after full Slack membership.
  4. Decide whether pending users can still sign in to downstream apps. For example, keep the OAuth sign-in working but have the claim be false, so each app can decide what to allow.

Acceptance criteria

  • A user who has signed up but hasn't joined Slack, or is still a guest, can be told apart from a full member through OIDC claims.
  • Promoting a user to full member after CoC acceptance updates that state.
  • Existing full members aren't affected.
  • Specs cover signup → invite → CoC accept → member, plus the imported-from-Slack path.

Context

Until this lands, Krater will check Slack itself when someone submits a proposal. It looks the user up by email and requires them to be a non-guest, non-deleted Slack member. Once Weave exposes slack_id and a membership claim, Krater will switch to those.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions