From ab2de838d76e2229da0867c93c2f18dc34d0d076 Mon Sep 17 00:00:00 2001 From: hugocasa Date: Thu, 1 Oct 2026 18:20:36 +0200 Subject: [PATCH] feat: offer slack write scopes as bot and user scope options (#11472) * fix: offer user scopes in the slack scope editor and drop the generated description on type change Co-Authored-By: Claude Opus 5.5 * feat: offer slack write scopes as bot and user scope options Co-Authored-By: Claude Opus 5.5 --------- Co-authored-by: Claude Opus 5.5 --- backend/oauth_connect.json | 16 ++++++++++++++++ backend/windmill-oauth/src/lib.rs | 5 +++-- .../src/lib/components/AppConnectInner.svelte | 8 +++++++- 3 files changed, 26 insertions(+), 3 deletions(-) diff --git a/backend/oauth_connect.json b/backend/oauth_connect.json index 0509e7f30a..add60a8614 100644 --- a/backend/oauth_connect.json +++ b/backend/oauth_connect.json @@ -43,6 +43,22 @@ "mpim:read", "files:read" ], + "scope_options": [ + { "value": "reactions:write", "label": "Add emoji reactions" }, + { "value": "channels:manage", "label": "Create, archive and manage public channels, invite members, set topics" }, + { "value": "groups:write", "label": "Create and manage private channels the app is in" }, + { "value": "usergroups:write", "label": "Edit user groups (workspace settings often block bots)" } + ], + "user_scope_options": [ + { "value": "reactions:write", "label": "Add emoji reactions" }, + { "value": "channels:write", "label": "Create, archive and manage public channels" }, + { "value": "channels:write.invites", "label": "Invite members to public channels" }, + { "value": "channels:write.topic", "label": "Set public channel topics" }, + { "value": "groups:write", "label": "Create and manage private channels" }, + { "value": "users.profile:write", "label": "Set your status and edit your profile" }, + { "value": "reminders:write", "label": "Create reminders for yourself" }, + { "value": "usergroups:write", "label": "Edit user groups" } + ], "token_response_path": "authed_user" }, "supabase_wizard": { diff --git a/backend/windmill-oauth/src/lib.rs b/backend/windmill-oauth/src/lib.rs index d37ab44742..15f5ac6b9e 100644 --- a/backend/windmill-oauth/src/lib.rs +++ b/backend/windmill-oauth/src/lib.rs @@ -92,8 +92,9 @@ pub struct OAuthConfig { /// The registry JSON may also carry frontend-only keys for the connect /// dialog, deliberately not modelled here: `scope_options`, a scope pick /// list, `resource_fields`, the fields of the resource type the dialog - /// asks for once the token is in (Snowflake's database and warehouse), and - /// `user_scopes`, Slack's user-token scopes, sent as `user_scope`. + /// asks for once the token is in (Snowflake's database and warehouse), + /// `user_scopes`, Slack's user-token scopes, sent as `user_scope`, and + /// `user_scope_options`, the pick list offered alongside `user_scopes`. pub scopes: Option>, /// Default scopes for the client-credentials (2-legged) flow. These differ /// from the authorization-code `scopes` for most providers (member/consent diff --git a/frontend/src/lib/components/AppConnectInner.svelte b/frontend/src/lib/components/AppConnectInner.svelte index ed9a27c0b8..bea6023073 100644 --- a/frontend/src/lib/components/AppConnectInner.svelte +++ b/frontend/src/lib/components/AppConnectInner.svelte @@ -278,7 +278,9 @@ let scopeOptions = $derived( useClientCredentials ? defaultCcScopes() - : [...(registryEntry()?.scope_options ?? []), ...instanceScopes] + : useUserToken + ? [...(registryEntry()?.user_scope_options ?? []), ...(registryEntry()?.user_scopes ?? [])] + : [...(registryEntry()?.scope_options ?? []), ...instanceScopes] ) /** Their slice of the resource type's schema, so they render with the type's own @@ -334,6 +336,10 @@ ccInstance = '' tokenUrl = '' scopes = [] + if (description === generatedDescription) { + description = '' + } + generatedDescription = '' } /** Default scopes for the client-credentials grant. Registry providers use