You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The implementation is complete and merged. This issue remains open only for operational acceptance in one owner-designated isolated Slack test workspace/app: authenticated admin setup, immutable user/channel/repository bindings, rotation, disable, deletion/reinstall, denial paths, sanitized platform/application/database/export checks, and rollout/rollback evidence. Public evidence must contain only the redacted readiness projection. Completion requires the designated workspace/app plus approved admin and deployment/log access through the private operational boundary.
Secrets are encrypted and absent from logs, exports, diagnostics, and OSS state.
Admin setup, rotation, disable, and deletion are exercised in a private test organization.
Code Mower delivery
Produce exactly one independently reviewable PR for this issue. Record the named builder, keep one writer on the branch, run focused tests and applicable full checks, obtain an independent Code Mower review against the exact current head, resolve every P0/P1/P2 finding, and pass normal CI plus code-mower/gate. Update the parent epic with PR/head, review, validation, outcome, and safe metadata-only upload evidence. Do not put credentials, source, diffs, prompts, transcripts, private context, task/message prose, or raw provider output in cloud data.
Repository boundary and completion plan
One implementation PR in the authorized CodeMower.com repository; delivered by Code Mower Codex with independent qualified Code Mower Claude review. #917 is complete, so this unit is ready. Preserve private repository/PR bindings in the authorized record and publish only safe scorecard evidence. #919 consumes installation/policy readiness and the separately frozen OSS supervisor contract #977. Installation registration alone does not establish qualified runtime readiness or authorize provider spending.
Canonical remaining outcome — 2026-09-17
The implementation is complete and merged. This issue remains open only for operational acceptance in one owner-designated isolated Slack test workspace/app: authenticated admin setup, immutable user/channel/repository bindings, rotation, disable, deletion/reinstall, denial paths, sanitized platform/application/database/export checks, and rollout/rollback evidence. Public evidence must contain only the redacted readiness projection. Completion requires the designated workspace/app plus approved admin and deployment/log access through the private operational boundary.
Part of #903.
Problem
Slack installations, organization membership, repository aliases, users, channels, and token lifecycle need an explicit hosted trust boundary.
Scope
Implement OAuth v2 state validation and HTTPS redirect handling, encrypted bot/refresh/signing-secret storage, one-organization installation binding, explicit member mapping, repository aliases, per-user action roles, channel allowlists, Slack Connect policy, disable/uninstall, and rotation. Provide an administrator setup/disable surface.
Dependencies
Acceptance criteria
Code Mower delivery
Produce exactly one independently reviewable PR for this issue. Record the named builder, keep one writer on the branch, run focused tests and applicable full checks, obtain an independent Code Mower review against the exact current head, resolve every P0/P1/P2 finding, and pass normal CI plus
code-mower/gate. Update the parent epic with PR/head, review, validation, outcome, and safe metadata-only upload evidence. Do not put credentials, source, diffs, prompts, transcripts, private context, task/message prose, or raw provider output in cloud data.Repository boundary and completion plan
One implementation PR in the authorized CodeMower.com repository; delivered by Code Mower Codex with independent qualified Code Mower Claude review. #917 is complete, so this unit is ready. Preserve private repository/PR bindings in the authorized record and publish only safe scorecard evidence. #919 consumes installation/policy readiness and the separately frozen OSS supervisor contract #977. Installation registration alone does not establish qualified runtime readiness or authorize provider spending.