Title: improvement(slack): request the approved mention/assistant/DM scopes, advertised on v2 only by TheodoreSpeaks · Pull Request #5898 · simstudioai/sim · GitHub
Open Graph Title: improvement(slack): request the approved mention/assistant/DM scopes, advertised on v2 only by TheodoreSpeaks · Pull Request #5898 · simstudioai/sim
X Title: improvement(slack): request the approved mention/assistant/DM scopes, advertised on v2 only by TheodoreSpeaks · Pull Request #5898 · simstudioai/sim
Description: What Slack app review has since approved app_mentions:read, assistant:write, and im:history — they're live in the prod app manifest under oauth_config.scopes.bot — but the repo still had them commented out behind a stale "TODO: Re-add once Slack app review approves these". So Sim was requesting a narrower grant than the app is entitled to. Newly connected accounts got tokens missing exactly the scopes that back three simSubscribed events on the native Sim app trigger (#5892): Event Scope it needs app_mention app_mentions:read assistant_thread_started / _context_changed assistant:write message.im (DMs) im:history The requested set now matches the manifest's 20 approved bot scopes exactly (verified at runtime). Why v1 keeps the narrow list Scopes are per-credential, not per-block — one Slack app → one slack provider → one shared token, requested server-side via getCanonicalScopesForProvider('slack') (lib/auth/auth.ts:2805). The grant itself can't be scoped to v2. What is per-block is what each picker advertises and treats as missing. So: slack_v2 + the slack_oauth trigger advertise the full 20 — they host the native Sim app trigger that needs them. The legacy v1 block stays pinned to the pre-expansion 17. It has no feature needing the new three, and advertising them there would flag every existing Slack credential as "missing scopes" and prompt a needless reconnect. A reconnect still grants the full set regardless of which block started it — this only controls the nag and the displayed permission list. Verified that the integrations/connections surface keys isConnected off a direct providerId match, not scope completeness, so existing Slack connections are not marked incomplete. Not included The Home tab (app_home_opened) is still custom-bot-only and correctly gated. It is absent from the manifest's event_subscriptions.bot_events, so Slack does not deliver it to the shared app. Flipping its simSubscribed flag would make deploys pass while the trigger silently never fires. Enabling it is a manifest change first (add app_home_opened to bot_events; no new scope required), then a one-line catalog flip. Checks bunx vitest run lib/webhooks triggers/slack blocks tools/slack — 886 passed (79 files) bun run type-check — no new errors (5 pre-existing better-auth errors unchanged) bun run lint:check — clean check-block-registry.ts — pass Runtime-verified: full=20, v1=17, zero leakage of the three into v1 🤖 Generated with Claude Code https://claude.ai/code/session_018asmKsWQ5Vi7T7wD9uHofz
Open Graph Description: What Slack app review has since approved app_mentions:read, assistant:write, and im:history — they're live in the prod app manifest under oauth_config.scopes.bot — but the repo still had them c...
X Description: What Slack app review has since approved app_mentions:read, assistant:write, and im:history — they're live in the prod app manifest under oauth_config.scopes.bot — but the repo still had th...
Opengraph URL: https://github.com/simstudioai/sim/pull/5898
X: @github
Domain: github.com
| route-pattern | /:user_id/:repository/pull/:id/files(.:format) |
| route-controller | pull_requests |
| route-action | files |
| fetch-nonce | v2:c9d6f98f-a40e-f86b-0721-df2f5b1b96f3 |
| current-catalog-service-hash | ae870bc5e265a340912cde392f23dad3671a0a881730ffdadd82f2f57d81641b |
| request-id | BEBC:12EAEE:8F3620:CD1935:6A63806D |
| html-safe-nonce | a639ac00cb487692a688b2ba2fb707b8161ef8d7e35bf679fd5047b1af693e84 |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiJCRUJDOjEyRUFFRTo4RjM2MjA6Q0QxOTM1OjZBNjM4MDZEIiwidmlzaXRvcl9pZCI6IjU5Mjg5OTUwMTg2NjE2NTg3MzMiLCJyZWdpb25fZWRnZSI6ImlhZCIsInJlZ2lvbl9yZW5kZXIiOiJpYWQifQ== |
| visitor-hmac | 2bdfbd4fdf3012a7e2d3c3dce804d94e5c9d048bc652b9d5201011c51bff48e4 |
| hovercard-subject-tag | pull_request:4119796573 |
| github-keyboard-shortcuts | repository,pull-request-list,pull-request-conversation,pull-request-files-changed,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | / |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/simstudioai/sim/pull/5898/files |
| twitter:image | https://avatars.githubusercontent.com/u/19564703?s=400&v=4 |
| twitter:card | summary_large_image |
| og:image | https://avatars.githubusercontent.com/u/19564703?s=400&v=4 |
| og:image:alt | What Slack app review has since approved app_mentions:read, assistant:write, and im:history — they're live in the prod app manifest under oauth_config.scopes.bot — but the repo still had them c... |
| og:site_name | GitHub |
| og:type | object |
| hostname | github.com |
| expected-hostname | github.com |
| None | e4fb64aef87da454ec25b158147f7f5f14aef29216e5ca1612c2e48faa599d1f |
| turbo-cache-control | no-preview |
| diff-view | unified |
| go-import | github.com/simstudioai/sim git https://github.com/simstudioai/sim.git |
| octolytics-dimension-user_id | 199344406 |
| octolytics-dimension-user_login | simstudioai |
| octolytics-dimension-repository_id | 912559512 |
| octolytics-dimension-repository_nwo | simstudioai/sim |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | false |
| octolytics-dimension-repository_network_root_id | 912559512 |
| octolytics-dimension-repository_network_root_nwo | simstudioai/sim |
| turbo-body-classes | logged-out env-production page-responsive full-width |
| disable-turbo | true |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | e839936ba5faffb9c836dda1cf4729d50c88a32e |
| ui-target | canary-2 |
| theme-color | #1e2327 |
| color-scheme | light dark |
Links:
Viewport: width=device-width