- app_connections repo; POST /api/apps/connect (keys/basic): the credential goes to the secret broker over its socket and only the encrypted ref lands in the row; disconnect endpoint; /api/apps directory merged with live connection status; audit rows for connect/disconnect - Broker protocol: InvokeHttp carries a JSON body - slack.post tool (SendsExternally -> gated): marked broker_executed — the runtime skips its own grant consumption and the BROKER independently verifies + consumes the single-use grant, then calls Slack with the bot token injected; the runtime never sees the credential - Config: [broker] socket_path + [slack] base_url; e2e harness spawns the real teamclaw-broker daemon and the server hosts an e2e-only /__slack sink - SlackApp: Connection tab stores the token via the broker; connected state - Integration test: blocked while pending -> approved -> sink received exactly one post with 'Bearer xoxb-test-token' -> grant replay refused - E2E journey: connect Slack in the panel -> gated post card with preview -> sink empty while pending -> approve -> exactly one post, queue clear 133 Rust + 63 frontend tests + 21 Playwright journeys. Co-Authored-By: Claude Fable 5 <[email protected]>
23 lines
502 B
TOML
23 lines
502 B
TOML
# Configuration for the local/CI end-to-end harness. The server runs with
|
|
# TEAMCLAW_MODE=e2e, which applies the deterministic seed at boot.
|
|
|
|
deploy_target = "air_gapped"
|
|
listen_addr = "127.0.0.1:8080"
|
|
|
|
[database]
|
|
url = "postgres://postgres:[email protected]:54330/teamclaw_e2e"
|
|
|
|
[llm]
|
|
provider = "scripted"
|
|
model = "scripted-e2e"
|
|
scenario_path = "deploy/e2e/scenarios.toml"
|
|
|
|
[auth]
|
|
mode = "local"
|
|
|
|
[broker]
|
|
socket_path = "/tmp/teamclaw-e2e-broker.sock"
|
|
|
|
[slack]
|
|
base_url = "http://127.0.0.1:8080/__slack"
|