- app_connections repo; POST /api/apps/connect (keys/basic): the credential goes to the secret broker over its socket and only the encrypted ref lands in the row; disconnect endpoint; /api/apps directory merged with live connection status; audit rows for connect/disconnect - Broker protocol: InvokeHttp carries a JSON body - slack.post tool (SendsExternally -> gated): marked broker_executed — the runtime skips its own grant consumption and the BROKER independently verifies + consumes the single-use grant, then calls Slack with the bot token injected; the runtime never sees the credential - Config: [broker] socket_path + [slack] base_url; e2e harness spawns the real teamclaw-broker daemon and the server hosts an e2e-only /__slack sink - SlackApp: Connection tab stores the token via the broker; connected state - Integration test: blocked while pending -> approved -> sink received exactly one post with 'Bearer xoxb-test-token' -> grant replay refused - E2E journey: connect Slack in the panel -> gated post card with preview -> sink empty while pending -> approve -> exactly one post, queue clear 133 Rust + 63 frontend tests + 21 Playwright journeys. Co-Authored-By: Claude Fable 5 <[email protected]>
27 lines
683 B
TOML
27 lines
683 B
TOML
[package]
|
|
name = "teamclaw-server"
|
|
version = "0.1.0"
|
|
edition.workspace = true
|
|
rust-version.workspace = true
|
|
license.workspace = true
|
|
publish.workspace = true
|
|
|
|
[dependencies]
|
|
axum = "0.8"
|
|
serde_json = { workspace = true }
|
|
sqlx = { workspace = true }
|
|
tc-api = { path = "../../tc-api" }
|
|
tc-auth = { path = "../../tc-auth" }
|
|
tc-config = { path = "../../tc-config" }
|
|
tc-db = { path = "../../tc-db" }
|
|
tc-files = { path = "../../tc-files" }
|
|
tc-llm = { path = "../../tc-llm" }
|
|
tc-runtime = { path = "../../tc-runtime" }
|
|
tc-scheduler = { path = "../../tc-scheduler" }
|
|
tc-domain = { path = "../../tc-domain" }
|
|
time = { workspace = true }
|
|
tokio = { workspace = true }
|
|
|
|
[lints]
|
|
workspace = true
|