Matthew Meszaros
|
e8a9dbc810
|
Merge pull request #837 from warmbly/devin/1791175783-slack-link-auto-and-oidc
feat: auto-link Slack members by email, Continue with Slack for mismatched emails, standalone /slack/link page
|
2026-10-05 05:56:40 +00:00 |
|
 Matthew MeszarosandDevin AI
|
55d1b9a634
|
feat: link Slack members to Warmbly automatically by matching email, add Continue with Slack (Sign in with Slack) for mismatched emails, and move the Slack link page to a standalone /slack/link screen
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
|
2026-10-05 05:00:22 +00:00 |
|
Matthew Meszaros
|
cbee2d3073
|
feat: answer a node heartbeat sent with INTERNAL_API_TOKEN where NODE_BROKER_TOKEN is required with the node's desired version only, recording nothing, through NodeHeartbeatAuthMiddleware and fleetnode UpdateOnly, so a node on an older release always updates itself onto the broker token without NODE_ACCEPT_INTERNAL_TOKEN, and say so in the configuration and split-deployment docs
|
2026-10-05 06:54:31 +02:00 |
|
Matthew Meszaros
|
36149cdebd
|
feat: add Pipedrive CRM mode (migration 000262) with write-through deals, activities and notes, outreach logged as Pipedrive activities, per-connection webhooks, filter import, a Warmbly person panel and modals, a provider registry behind the shared /crm routes, a provider-aware dashboard, and centered popups replacing the integration side drawer
|
2026-10-04 19:20:48 +02:00 |
|
Matthew Meszaros
|
f23c04ddd8
|
Merge remote-tracking branch 'origin/main' into feature/slack-app-agent
# Conflicts:
# deploy/slack/manifest.json
# docs/content/docs/development/slack-app.mdx
# docs/content/docs/guides/slack.mdx
# internal/app/integration/slack.go
# internal/app/slackapp/agent.go
# internal/app/slackapp/client.go
# internal/app/slackapp/slackapp_test.go
# web/src/lib/integrations/oauthPopup.ts
|
2026-10-04 06:54:19 -07:00 |
|
Matthew Meszaros
|
f092b71a30
|
feat: answer a spent confirmation budget with reauth_limited and say so in the dashboard and admin dialogs, keep an open confirmation dialog from timing out under the person, and stop the OAuth app webhook secret reveal from re-prompting after a cancel
|
2026-10-04 05:25:32 -07:00 |
|
Matthew Meszaros
|
3de01f25b3
|
feat: gate MCP and /ai/tools per tool for keys and tokens, with AI_AGENT on the web and playbook tools, and require use_ai for member sessions on /ai/tools
|
2026-10-04 05:21:18 -07:00 |
|
Matthew Meszaros
|
ab39429e37
|
feat: send HSTS from the forms service only on FORMS_DOMAIN and strip it in the installer's Caddy block for customer-owned domains, so no customer apex is pinned to HTTPS
|
2026-10-04 05:19:22 -07:00 |
|
Matthew Meszaros
|
c178dadf81
|
feat: keep the key and blob brokers on NODE_BROKER_TOKEN only, and let an operator admit INTERNAL_API_TOKEN on the other node routes with NODE_ACCEPT_INTERNAL_TOKEN=true while nodes joined before the split upgrade
|
2026-10-04 05:18:01 -07:00 |
|
Matthew Meszaros
|
a6e72f1a92
|
feat: keep linking and unlinking Warmbly Cloud and adopting the cloud workspace's mailboxes with the instance administrator, and let members with manage_emails read the link and put their own workspace's mailboxes on it
|
2026-10-04 05:17:20 -07:00 |
|
Matthew Meszaros
|
cbf0667d8f
|
feat: hold every API key to its creator's current workspace role on each gated route and AI tool, and stop a key, including on the realtime socket, once its creator leaves the workspace (api_key_holder_left)
|
2026-10-04 05:15:30 -07:00 |
|
Matthew Meszaros
|
801c87ffe1
|
feat: make the Warmbly Slack bot a mention-driven agent that DMs the account link, answers the held question once linked, auto-links the installer, reacts while working, lets teammates take over a thread, sets up Slack and links integrations through permission-gated assistant tools with strict approvals in channels, drops the /warmbly slash command, and replaces the integration connect drawer and label field with a connect popup
|
2026-10-04 05:15:07 -07:00 |
|
Matthew Meszaros
|
5d4b0ad6e5
|
feat: hold the invite_member, update_member_role and rotate_webhook_secret AI tools to the same recent confirmation their REST routes require, answering reauth_required on /ai/tools and refusing them where no confirmed session exists
|
2026-10-04 05:14:30 -07:00 |
|
Matthew Meszaros
|
aca1aff4d6
|
feat: count a completed sign-in as a fresh confirmation for the first five minutes of the session, so accounts with no password or second factor can confirm an action by signing in again
|
2026-10-04 05:13:23 -07:00 |
|
Matthew Meszaros
|
663c3013d1
|
feat: bind each Remie approval to its tool call and run it once, show every argument and the resolved send on dashboard and Slack approval cards, keep always-allow to settings managers with a revocable list and never for tools that start sending or change access, withhold secrets and unpermitted tool results from the assistant and shared conversations, gate /mcp, /ai/tools and the web and playbook tools on AI_AGENT or use_ai, and scope get_mailbox by organization
|
2026-10-04 03:45:02 -07:00 |
|
Matthew Meszaros
|
886756ae0f
|
feat: share one api_key_mailbox_limited code and keyMailboxLimited check across the campaign, AI tool and MCP handlers
|
2026-10-04 03:43:26 -07:00 |
|
Matthew Meszaros
|
497f58bb5a
|
feat: hold a mailbox-limited API key to explicit sender lists of its own mailboxes when it creates, edits or starts a campaign, and refuse it on /ai/tools and /mcp, which act across the workspace, with api_key_mailbox_limited
|
2026-10-04 03:24:25 -07:00 |
|
Matthew Meszaros
|
a70811f56a
|
feat: write the mailbox connect and reauth audit entry under the mailbox's own organization when an OAuth flow finishes, so its spine event reaches that workspace
|
2026-10-04 03:22:09 -07:00 |
|
Matthew Meszaros
|
48c65611b5
|
feat: require view_contacts / READ_CONTACTS for an AI variable preview rendered against a named contact, matching test sends and template previews
|
2026-10-04 03:22:09 -07:00 |
|
Matthew Meszaros
|
1c555934a5
|
feat: authorize warmup ban status and warmup appeals by the caller's organization and its view_campaigns / manage_emails gates, so any member who manages mailboxes can appeal, answering 404 for a mailbox outside the workspace
|
2026-10-04 03:22:09 -07:00 |
|
Matthew Meszaros
|
6c36be44aa
|
feat: require the actor to hold every permission a role edit, re-role or member removal takes away as well as every one it grants, matching role deletion, with the workspace owner holding all permissions
|
2026-10-04 03:22:09 -07:00 |
|
Matthew Meszaros
|
5f180f5c76
|
feat: hold an API key with allowed_email_accounts to its mailboxes across the unibox (list, thread, message, count and overview reads; compose with auto pick within the list, drafts, agent-draft approve and discard, seen, folder, labels and snooze writes), campaign sender pools, analytics account statuses and GET /analytics/accounts/:id, and store a compose draft's mailbox only when it belongs to the caller's organization
|
2026-10-04 03:22:09 -07:00 |
|
Matthew Meszaros
|
ec77a3e3d2
|
feat: key unibox snoozes by organization as well as user and thread (migration 000259 backfills from each thread's mailbox organization), scope every snooze read and write and the org-transfer scope to it, and resolve unibox list cursors only within the caller's organization or user
|
2026-10-04 03:22:09 -07:00 |
|
Matthew Meszaros
|
9d461ad40e
|
feat: gate advisor apply and undo on view_analytics / READ_ANALYTICS and run the fix as the caller: a member under their org permissions, or an API key or OAuth grant under its own scope mask, with a fix for a mailbox outside the key's allowlist refused
|
2026-10-04 03:21:58 -07:00 |
|
Matthew Meszaros
|
e852a106a9
|
feat: serve every node-only internal route (data keys, message map, sync lookups, worker config, fleet heartbeat) on NODE_BROKER_TOKEN and leave only tracked links, domain redirects, page hits and forms on INTERNAL_API_TOKEN, render nodes only the node token when one is set, and have the installer generate a distinct NODE_BROKER_TOKEN for new installs and its own UPDATER_TOKEN
|
2026-10-04 03:21:58 -07:00 |
|
Matthew Meszaros
|
1c29643ecb
|
feat: re-apply the app and form write rules to workspace imports so imported OAuth apps get displayname-checked names, http(s) websites, valid redirect URIs and webhooks, only their workspace's own logos, and stay suspended when suspended at the source or imported under a developer block, imported forms keep only http(s) redirect URLs, valid designs and embed domains, and the hosted form page navigates only to http(s) redirect targets
|
2026-10-04 03:03:40 -07:00 |
|
Matthew Meszaros
|
43a9d004f2
|
feat: bound user-authored templates (range only over data fields, two-deep nesting, no template calls, 1 MiB output, capped compile cache) for campaign and automation rendering, accept only single addresses and single Message-IDs for to/cc/bcc/in_reply_to on every send path with invalid_recipient and invalid_message_id, refuse multi-line headers in the Gmail, Graph and SMTP writers, always apply a no-script CSP and drop non-http(s)/mailto/tel link targets in email previews, treat only single-slash paths as internal Remie links, accept integration OAuth callbacks only from the API origin, and follow only http(s) form redirects and app install links
|
2026-10-04 03:02:37 -07:00 |
|
Matthew Meszaros
|
bf47984cd5
|
feat: cap every OAuth grant and API key at the delegating member's role (consent narrows scopes and reports the withheld ones, tokens re-check the member's current role at every gate and MCP tool, keys stay within their creator's permissions, mailboxes and IP allowlist), keep OAuth tokens off API key and OAuth app management, require a fresh sign-in to approve an app, revoke a grant whose refresh token is presented twice, count only unexpired grants as installs, seal app webhook secrets under the instance key, name the workspace and flag unverified apps on the consent screen, and let credential managers list and revoke every member's app authorizations
|
2026-10-04 02:59:10 -07:00 |
|
Matthew Meszaros
|
8bb60e9449
|
feat: accept only Salesforce domains as an org's API host and call it through the SSRF-guarded client, register the Warmbly Cloud link only on self-hosted instances behind the instance admin with a second factor and dial it through safehttp with fixed error text, keep automation signing secrets in the sealed connection config, answer integration service failures with fixed messages, add security headers to the forms, tracking and docs origins and TLS 1.2+ to the nginx template, compare the captcha bypass in constant time, require TLS 1.2 for IMAP probes, and drop the unused RSA helpers
|
2026-10-04 02:58:43 -07:00 |
|
Matthew Meszaros
|
610d511307
|
feat: answer every server-side failure in admin, internal, webhook, warmup routing, Stripe webhook, agent tool and MCP handlers with the fixed internal error and log the detail against the request id, keep correctable webhook and routing refusals as typed errors with their own messages, drop the request URL from MillionVerifier transport errors so the API key never reaches a log or response, and redact :code path parameters in the access log
|
2026-10-04 02:57:17 -07:00 |
|
Matthew Meszaros
|
db4fc7b115
|
feat: require a recent confirmation for 2FA enrollment (a fresh sign-in for accounts with no password or factor), pool link approval, workspace export and import, member invites and role changes, webhook and OAuth app secret reveal and rotation, and the admin fleet join token, admin grant and workspace archive routes, with a confirm-it-is-you dialog and retry in the admin panel
|
2026-10-04 02:56:18 -07:00 |
|
Matthew Meszaros
|
5bd8dbfab9
|
feat: bind Warmbly Cloud brokered mailbox sign-ins to PKCE, a single-use state and a cloud consent page naming the requesting instance and workspace that sets the browser cookie the callback requires, return only to the instance's registered address, add PKCE and an OIDC nonce to Workspace and Microsoft 365 admin-proof sign-ins, post OAuth callback codes only to a configured dashboard origin, cap CLI-approved keys to the approver's role behind a fresh sign-in, and accept only same-origin login next paths
|
2026-10-04 02:53:16 -07:00 |
|
Matthew Meszaros
|
9f7d45a1fb
|
feat: charge every password, emailed-code and TOTP attempt atomically before comparing it (Redis INCR+expire script) with a per-account TOTP budget across challenges, put the signed-in password change on the reauth budget, set the per-account login limit to 50 per hour, give tester passwords an expiry (users.password_expires_at, migration 000257) and clear them plus every session on revoke, mint warmblyctl reset links with the password-reset purpose, expire fleet join tokens (7 days default, 30 max, reusable inside the window), derive captcha from the resolved Turnstile secret, refuse weak bootstrap argon2id hashes, make registration codes single-use, rate-limit the v1 invitation lookup, and draw RIDs and user codes without modulo bias
|
2026-10-04 02:52:22 -07:00 |
|
Matthew Meszaros
|
f0ec39febd
|
feat: scope automation and sequence unsubscribes to the caller's organization, require manage_settings to create, edit, enable or delete automations, run each integration action only on its own provider's connection (400 action_provider_mismatch), refuse org-permission gates when no organization service is wired, read /integrations/bookings like contacts, scope lead claims, research runs and CRM list cursors to the organization, and bind contact note edits to the contact in the path
|
2026-10-04 02:47:10 -07:00 |
|
Matthew Meszaros
|
e1c4a91ad1
|
feat: confirm a Slack link only for the Warmbly member whose email matches the Slack account's confirmed profile email (read via users.info with the new users:read and users:read.email scopes, refused as slack_link_email_mismatch), show the Slack account's name and avatar on the link page and after linking, return the Slack connection in GET /integrations/slack/status only to manage_settings or use_integrations, scope agent-thread lookups by organization, and check a Draft a reply card's conversation belongs to the clicker's workspace before starting the assistant
|
2026-10-04 02:45:04 -07:00 |
|
Matthew Meszaros
|
4cfba5340a
|
feat: verify every HubSpot app request by its v3 signature over the public backend URL, refuse card-fetch query values on the webhook and workflow action routes, take exactly one portalId, userId and userEmail on card routes and act as the matched accepted member holding the matching campaign and contact permissions, route a portal only to its single live HubSpot-mode workspace, delete mirrored deals and tasks only when HubSpot answers the record is gone, and scope the card's permitted fetch to the card routes
|
2026-10-04 02:42:12 -07:00 |
|
Matthew Meszaros
|
d505508997
|
feat: audit OAuth app moderation and developer blocks under their own entity types, refuse logo removal on suspended apps, delete a replaced workspace-uploaded app logo once no other app shows it, confirm before revoking every token in the admin panel, open store cards on Space, retry a new logo URL after a failed one, toast only after the clipboard write succeeds, and freeze the listing form baseline while it is open
|
2026-10-04 01:20:28 -07:00 |
|
Matthew Meszaros
|
bc9caba267
|
feat: validate OAuth app names through displayname and websites as http(s), clean dynamically registered client names and stop storing their logo_uri, refuse edits and logo uploads on suspended apps or blocked developers, scope logo deletion to the app's own images, keep hidden listings from being unpublished, count only installs from other aged workspaces toward the directory threshold, refresh integration popularity outside the lock, and count only live connections in the Integrations store
|
2026-10-04 01:10:39 -07:00 |
|
Matthew Meszaros
|
1a483cb27f
|
Merge remote-tracking branch 'origin/main' into feature/integrations-page-redesign
# Conflicts:
# internal/app/integration/service.go
# web/src/app/app/integrations/page.tsx
# web/src/hooks/useDocumentTitle.ts
|
2026-10-04 00:45:48 -07:00 |
|
Matthew Meszaros
|
4bc2417618
|
Merge remote-tracking branch 'origin/main' into feature/integrations-page-redesign
# Conflicts:
# docs/content/docs/api/error-codes.mdx
# docs/content/docs/guides/integrations.mdx
# web/src/app/app/integrations/page.tsx
|
2026-10-04 00:32:54 -07:00 |
|
Matthew Meszaros
|
7555f641a5
|
feat: turn Integrations into an app store with sidebar views, search, sorting and filters, list community apps by link until featured or widely installed, redesign the OAuth app registration dialog, store app logos re-encoded per app like the workspace logo, and add admin suspension, token revocation and developer blocks for OAuth apps
|
2026-10-04 00:31:52 -07:00 |
|
Matthew Meszaros
|
6b7e254e56
|
feat: add native Salesforce sync with Lead and Contact matching and links, a leased activity outbox that logs sends, replies, bounces, opt-outs and meetings as Tasks, Lead Status and Email Opt Out writeback, a pull loop with CRM pause rules, list view and Campaign imports, sandbox and My Domain OAuth that refreshes expired sessions, a Salesforce settings page with contact and inbox cards in web, and docs
|
2026-10-04 08:54:27 +02:00 |
|
Matthew Meszaros
|
900806f328
|
feat: make HubSpot sync jobs lease-safe with per-claim tokens and one-at-a-time claims, log each email once across retries with the interested-reply outcome as its own job, move merged HubSpot contacts in a transaction, run backfill as one cursor job that skips refused records, rebuild the HubSpot client after a reconnect, accept a single portalId on card requests, and remember the Warmbly property group only after it exists
|
2026-10-04 08:18:16 +02:00 |
|
Matthew Meszaros
|
37e91fc89f
|
feat: add HubSpot CRM mode where HubSpot deals, pipelines, tasks, notes and owners are mirrored and written through, sends and replies log as HubSpot emails, exit rules hold campaigns, list import, sync health, setup wizard in web, HubSpot app project with record card and workflow action, and docs
|
2026-10-04 07:47:51 +02:00 |
|
Matthew Meszaros
|
8883a1df6b
|
feat: connect Microsoft 365 organizations through Microsoft's v2.0 admin consent page followed by a sign-in on the same state, read the approving admin's directory role from the Graph token as well as the ID token, return an organization-wide approval link for single-mailbox Outlook sign-in (admin_consent_url) and show it in the connect panel, and document publisher verification and the admin approval path
|
2026-10-03 20:17:38 +02:00 |
|
Matthew Meszaros
|
4957214431
|
feat: redesign the Integrations page with search, category chips, recommended and popularity-ranked integrations, add a community app directory where OAuth apps are published unverified by link and verified in a new admin review queue, with docs and OpenAPI
|
2026-10-03 09:24:34 -07:00 |
|
Matthew Meszaros
|
61d16dfe9a
|
feat: add Warmbly for Slack with the AI assistant in DMs, mentions and the assistant pane, unified inbox threads with reply, AI draft and lead actions, per-category notification routing and DMs, account linking, dashboard Slack settings, manifest and docs
|
2026-10-03 15:35:11 +02:00 |
|
Claude
|
3288238cc0
|
feat: paginate and batch GET /analytics/accounts so account status reads are bounded per page and the overflow past 1000 mailboxes is reachable via cursor
|
2026-10-03 06:46:20 +00:00 |
|
Matthew Meszaros
|
b8a8ec4743
|
Merge remote-tracking branch 'origin/main' into feat/unibox-rail-layout-per-member
|
2026-10-01 22:58:31 -07:00 |
|
Matthew Meszaros
|
8f89c36756
|
feat: refresh the open conversation for inbox events that name only a message id, give unibox refresh keys added just before a max-wait flush a trailing flush, cancel a shared unibox overview computation once its last caller leaves and bound it and GET /unibox/overview at 30s, include scheduled sends in the coalesced inbox refresh, and word the slow pgxpool acquire log as acquire time rather than saturation
|
2026-10-01 22:41:00 -07:00 |
|