Skip to content

Add service access recovery to channel Bind and Edit - #3681

Merged
AbigailDeng merged 5 commits into
feat/2026-08-04_workflow-activity-vnextfrom
feat/2026-09-28_channel-service-access
Sep 29, 2026
Merged

AbigailDeng merged 5 commits into
feat/2026-08-04_workflow-activity-vnextfrom
feat/2026-09-28_channel-service-access

Conversation

@AbigailDeng

@AbigailDeng AbigailDeng commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Problem and behavior

When a channel needs a service omitted during login, both Bind bot and Edit channel now show the missing access and offer Manage service access. Both routes reuse the existing configuration form, service picker and access notice. The button opens the existing full NyxID consent flow, preserves unsaved choices, and returns to the same page for an explicit Bind or Save action.

  • Both canonical routes accept repeated requiredServiceId query parameters containing exact NyxID UserService IDs. Hints are trimmed, bounded and deduplicated; they never grant or automatically select a service. Names and slugs come from the authenticated inventory, and another same-slug account cannot satisfy an exact-ID hint.
  • Preserve the complete return path, query and fragment, plus the non-secret label, skill and service draft. Tab-scoped drafts expire after one hour and are isolated by account, scope and typed target: bind + botId or edit + registrationId. Bind does not require an existing registration ID.
  • On Bind return, restore the user's skill override, including an explicitly cleared choice, ahead of the link's skillId default. Refresh actual service availability and grants; newly available services receive a Requested label and remain unselected until chosen.
  • Partial/cancelled consent retains missing-access guidance. Storage or redirect failure keeps the form open with retry. Browser history restoration refreshes grants and resets the pending review state. Selected revoked services must be reauthorized or deselected before submission.
  • Restored choices show one short inline reminder. Only unresolved access needs show a separate notice. Binding and saving retain accepted-to-observed confirmation; authorization review never submits a channel mutation. Bind completion requires the returned registration ID, original bot ID and submitted configuration to match the observed result.
  • Reuse serviceAccessReview, PKCE, callback/backend finalization and sanitized returnTo. The shared callback return label is “Back to previous page”. English and Chinese catalogs stay aligned.

NyxID limitation

This uses the current full consent page. Ordinary repeated consent can initialize app defaults instead of all previously granted services; users must retain the services they still need under Service access → Customize. Channel selections do not initialize NyxID's picker. Opening consent does not change grants, but submitting a smaller selection can replace them.

The incremental contract proposed in NyxID #1683 remains a separate integration after upstream deployment. This change sends neither unsupported preselection inputs nor slug-based resource narrowing.

Affected paths and documentation

Channel Bind/Edit routing, shared configuration form, service picker/notice, temporary draft storage, UserService access adapter/query, callback copy and locale catalogs. The link contract, shared user path, typed draft identities and upstream limitation are documented in apps/aevatar-console-web/docs/superpowers/specs/2026-09-28-channel-service-access.md.

Backend behavior was checked against origin/feature/integrate; this frontend PR targets feat/2026-08-04_workflow-activity-vnext.

Local verification

Commands run from the repository root. Full frontend suite, typecheck and production build are delegated to GitHub CI by personal local workflow policy. No reliable repository-native affected typecheck is available.

Latest Bind extension: 4 relevant suites / 26 tests pass across scoped runs. The initial combined run passed the 23 existing Edit/default-skill/access tests. The new Bind suite passed all 3 tests after correcting its inventory fixture and waiting for asynchronous service rendering. Production code did not change between these test runs.

python3 /Users/abigaildeng/.codex/skills/frontend-incremental-pr/scripts/frontend_change_scope.py --repo . --base HEAD
python3 /Users/abigaildeng/.codex/skills/frontend-incremental-pr/scripts/frontend_change_scope.py --repo . --base origin/feat/2026-08-04_workflow-activity-vnext
pnpm --dir apps/aevatar-console-web exec jest --listTests --runInBand --findRelatedTests src/pages/workflow-activity-vnext/channels/ChannelConfigurationPage.tsx src/pages/workflow-activity-vnext/channels/serviceAccessDraft.ts
pnpm --dir apps/aevatar-console-web exec jest --runInBand --runTestsByPath src/pages/workflow-activity-vnext/channels/ChannelBindServiceAccess.test.tsx src/pages/workflow-activity-vnext/channels/ChannelServiceAccess.test.tsx src/pages/workflow-activity-vnext/channels/ChannelDefaultSkill.test.tsx src/pages/workflow-activity-vnext/channels/ChannelEditPage.test.tsx
pnpm --dir apps/aevatar-console-web exec jest --runInBand --runTestsByPath src/pages/workflow-activity-vnext/channels/ChannelBindServiceAccess.test.tsx
pnpm --dir apps/aevatar-console-web exec biome check src/pages/workflow-activity-vnext/channels/ChannelBindServiceAccess.test.tsx src/pages/workflow-activity-vnext/channels/ChannelConfigurationPage.tsx src/pages/workflow-activity-vnext/channels/serviceAccessDraft.ts src/pages/workflow-activity-vnext/index.tsx
env PATH="/Users/abigaildeng/.cache/codex-runtimes/codex-primary-runtime/dependencies/python/bin:$PATH" bash tools/ci/test_stability_guards.sh
git diff --check

Dependency preflight selected 5 files. Its broad workflow-activity-vnext/index.test.tsx contains unrelated workflow/settings domains, so the execution was narrowed to the 4 channel suites above. The router entry was excluded from discovery and exercised through rendered Bind/Edit route tests. Changed-file Biome checks passed for all 4 files; stability guards and whitespace checks passed.

Earlier focused validation of the edit, callback and adapter changes in this PR passed 3 suites / 27 tests, plus 7 catalog tests:

pnpm --dir apps/aevatar-console-web exec jest --runInBand --runTestsByPath src/pages/workflow-activity-vnext/channels/ChannelServiceAccess.test.tsx src/pages/auth/callback/index.test.tsx src/shared/api/channelServicesApi.test.ts
pnpm --dir apps/aevatar-console-web exec jest --runInBand --runTestsByPath src/locales/catalog.test.ts
pnpm --dir apps/aevatar-console-web exec biome check src/locales/channelMessages.en-US.ts src/locales/channelMessages.zh-CN.ts src/pages/auth/callback/index.test.tsx src/pages/auth/callback/index.tsx src/pages/workflow-activity-vnext/channels/ChannelConfigurationPage.tsx src/pages/workflow-activity-vnext/channels/ChannelServiceAccess.test.tsx src/pages/workflow-activity-vnext/channels/ChannelServiceAccessNotice.tsx src/pages/workflow-activity-vnext/channels/ChannelServicePicker.tsx src/pages/workflow-activity-vnext/channels/connectionStyles.ts src/pages/workflow-activity-vnext/channels/queries.ts src/pages/workflow-activity-vnext/channels/serviceAccessDraft.ts src/pages/workflow-activity-vnext/index.tsx src/shared/api/channelServicesApi.test.ts src/shared/api/channelServicesApi.ts
pnpm --dir apps/aevatar-console-web exec biome check --formatter-enabled=false src/locales/projectMessages.en-US.ts src/locales/projectMessages.zh-CN.ts

The local dev server uses the configured remote backend. Authenticated browser inspection confirmed the shared Bind Services header and Requested labels for Firecrawl and ChronoAI Lark Bot on an actual unbound bot. Existing dirty Edit tabs were preserved. Missing-access, partial/cancelled consent, restoration and explicit submission are covered by route integration tests; no live binding or new OAuth consent was submitted during Bind verification.

Design baseline

  • Baseline: apps/aevatar-console-web/docs/design-baselines/workflow-activity-vnext/
  • Primary: aevatar-workflow-activity-vnext.excalidraw
  • SHA-256: 30e74d7b410ae72c4c91432355436679033679c54c10b1702908435b001577de
  • Contract: apps/aevatar-console-web/docs/superpowers/specs/2026-08-04-workflow-activity-vnext-design.md
  • User paths: apps/aevatar-console-web/docs/superpowers/specs/2026-08-04-workflow-activity-vnext-user-paths.md
  • Direction: existing compact white work surface, AlibabaSans, blue actions, token-based amber access notice and wrapping mobile actions.
  • Existing auth/session/returnTo and Umi localization remain authoritative. Production data comes from real APIs and acknowledged user actions; fixtures remain test-only.

@AbigailDeng AbigailDeng changed the title Add service access recovery to channel editing Add service access recovery to channel Bind and Edit Sep 29, 2026
@AbigailDeng
AbigailDeng merged commit 68fda9f into feat/2026-08-04_workflow-activity-vnext Sep 29, 2026
33 of 34 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant