Skip to content

feat(slack): require full slack membership and expose it via oidc - #121

Open
jaspermayone with Copilot wants to merge 3 commits into
mainfrom
copilot/require-joining-slack-as-part-of-weave-membership
Open

jaspermayone with Copilot wants to merge 3 commits into
mainfrom
copilot/require-joining-slack-as-part-of-weave-membership

Conversation

Copilot AI commented Sep 28, 2026 •

Copy link
Copy Markdown

A Weave account does not make someone a full member of the Patchwork Labs Slack. Downstream apps (Krater) assumed that it does. This PR makes full Slack membership an explicit state, gives people one page that takes them through joining, and exposes the state to OAuth clients.

Fixes #118

Membership state

  • New column users.slack_membership: pending (default) or member.
  • A user becomes member when Slack reports a regular (non-guest, non-deactivated) account:
    • SlackCodeOfConductAcceptedJob sets it after users.admin.setRegular succeeds.
    • The team_join and user_change webhooks set it from the Slack user flags. user_change also ends membership when an account is made a guest or deactivated.
    • The 6-hourly Slack sync and SyncUserToSlackJob set it from users.list / users.lookupByEmail.
  • Backfill migration: users with a slack_id who were not invited as guests by Weave, or who accepted the CoC, start as member. The next Slack sync corrects any wrong guess.
  • User#slack_member? now means full membership. The old meaning (has a slack_id) is User#in_slack_workspace?.
stateDiagram-v2
    [*] --> pending: sign up
    pending --> pending: confirm email, Slack invite sent
    pending --> pending: accept invite (single-channel guest)
    pending --> member: accept Code of Conduct (promoted)
    member --> pending: made a guest or deactivated in Slack
    [*] --> member: imported from Slack as a full member
Loading

Onboarding: slack.patchworklabs.org → /slack

  • Any request to slack.* redirects (302) to /slack on the canonical host, so the session cookie applies.
  • /slack shows the next step: sign up, send invite, accept invite, accept Code of Conduct, member.
  • POST /slack sends or resends the invite (10 minute cooldown, plus a Rack::Attack throttle).
  • POST /slack/code-of-conduct accepts the CoC from the web, for people who can't find the Slack DM. It also retries a failed promotion.
  • / sends signed-in pending users to /slack. The profile page shows a "Finish joining" banner. The home page links to "Join the Slack".
  • The admin user page shows the real membership state.

OIDC

New optional scope slack with two claims, in the id_token and at /oauth/userinfo:

Claim Meaning
slack_member true only for full (non-guest) members
slack_id Slack user ID; omitted before they join

Pending users can still sign in. Each client decides what to allow. Krater must add slack to its registered scopes and request it. UserSerializer also includes both fields.

Deploy steps (outside this repo)

  • DNS: add slack.patchworklabs.org in Cloudflare (proxied, same as weave).
  • Traefik on alastor (hosts/alastor/configuration.nix, idp router): add || Host(\slack.patchworklabs.org`)` to the rule.

Tests

  • New: model, job, webhook service, onboarding request, OIDC claim specs, and an end-to-end flow spec (signup → confirm → invite → join as guest → CoC → member, plus the imported-from-Slack path).
  • bundle exec rspec: 446 examples, 0 failures. bin/rails test: 11 runs, 0 failures. RuboCop, Brakeman, herb, zeitwerk: clean.

Copilot AI linked an issue Sep 28, 2026 that may be closed by this pull request
Copilot AI changed the title [WIP] Fix membership validation for Slack invites in Weave WIP: enforce Slack-backed membership state in OIDC (session interrupted) Sep 28, 2026
Copilot AI requested a review from jaspermayone September 28, 2026 19:46
@jaspermayone jaspermayone changed the title WIP: enforce Slack-backed membership state in OIDC (session interrupted) feat(slack): require full slack membership and expose it via oidc Sep 28, 2026
@jaspermayone
jaspermayone marked this pull request as ready for review September 28, 2026 21:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Require joining Slack as part of Weave membership

2 participants