Skip to content

Commit 71a374f

Browse files
committed
Merge upstream/main into feat/secure-ticket-ids
2 parents db269f4 + 20c5580 commit 71a374f

22 files changed

Lines changed: 6033 additions & 294 deletions

File tree

‎.env.example‎

Lines changed: 46 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -66,6 +66,52 @@ SLACK_APP_TOKEN=xapp-...
6666
SLACK_SIGNING_SECRET=
6767
SLACK_SOCKET_MODE=true
6868

69+
# ─── Slack Ticket Mirror ─────────────────────────────────────────────────────
70+
# Mirrors tickets into one Slack channel: the ticket opens a thread, community
71+
# follow-ups and the AI reply thread under it. Read-only (replying in Slack does
72+
# NOT post back to the source).
73+
#
74+
# Which tickets: the allowlist in isMirrorableSource()
75+
# (packages/outpost/shared/src/platforms/slack-mirror-config.ts) — today Discord,
76+
# GitHub issues, and GitHub discussions. Slack-sourced tickets are excluded
77+
# (they already live in Slack); so are Teams/Email/Web/Manual/Linear.
78+
#
79+
# Mode: off (default, nothing is enqueued and the handler no-ops)
80+
# | shadow (logs what it would post; posts nothing; needs NO token)
81+
# | live (posts; requires SLACK_BOT_TOKEN, or the mirror stays disabled
82+
# and logs why once)
83+
# Any mode does nothing at all while SLACK_MIRROR_CHANNEL_ID is unset.
84+
#
85+
# Deliberately INDEPENDENT of SHADOW_MODE — that flag protects community
86+
# surfaces (Discord/GitHub) where real reporters watch; this posts to an
87+
# internal team channel, so staging posting here is intended.
88+
#
89+
# WHICH SERVICES need these vars: the handler runs in outpost-worker, but the
90+
# PRODUCERS gate on the same config — readSlackMirrorConfig() is called from
91+
# InboundHandler, which runs inside outpost-discord-bot and outpost-github-app.
92+
# Set SLACK_MIRROR_MODE + SLACK_MIRROR_CHANNEL_ID on the worker AND on every
93+
# service that creates tickets, or nothing is ever enqueued and the mirror is
94+
# silently dead.
95+
#
96+
# SCOPE IN v1: ticket-opens from Discord and GitHub, AI replies on both, and
97+
# community follow-ups from DISCORD ONLY. A follow-up comment on a GitHub issue
98+
# or discussion never reaches the mirror, and nothing logs that it did not — so
99+
# a Slack thread that stops after the AI reply does not mean the reporter went
100+
# quiet. See docs/deployment.md.
101+
SLACK_MIRROR_MODE=off
102+
# Channel ID, NOT a channel name. Slack: open channel -> click its name ->
103+
# bottom of the details pane -> Channel ID. Looks like C09AB2CD3EF.
104+
SLACK_MIRROR_CHANNEL_ID=
105+
# NOTE: SLACK_BOT_TOKEN above needs chat:write and must be set on the WORKER
106+
# service (outpost-worker) — the mirror handler posts from there, not from the
107+
# Slack bot. Invite the bot to the channel or posts fail not_in_channel (the
108+
# handler reports that as permanent and does not retry it).
109+
# Keep this channel OUT of MONITORED_CHANNEL_IDS. The Slack bot drops events
110+
# carrying a bot_id (apps/slack-bot/src/events/message.ts), so its own mirror
111+
# posts would not become tickets today — but monitoring the mirror channel
112+
# would duplicate every ticket's context into the bot's inbound path and makes
113+
# the loop one filter change away. Keep the two channel sets disjoint.
114+
69115
# ─── Teams Bot ───────────────────────────────────────────────────────────────
70116
TEAMS_APP_ID=
71117
TEAMS_APP_PASSWORD=

0 commit comments

Comments
 (0)