Add service access recovery to channel Bind and Edit - #3681
Merged
AbigailDeng merged 5 commits intoSep 29, 2026
Merged
AbigailDeng merged 5 commits into
AbigailDeng merged 5 commits into
Conversation
AbigailDeng
merged commit Sep 29, 2026
68fda9f
into
feat/2026-08-04_workflow-activity-vnext
33 of 34 checks passed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem and behavior
When a channel needs a service omitted during login, both Bind bot and Edit channel now show the missing access and offer Manage service access. Both routes reuse the existing configuration form, service picker and access notice. The button opens the existing full NyxID consent flow, preserves unsaved choices, and returns to the same page for an explicit Bind or Save action.
requiredServiceIdquery parameters containing exact NyxID UserService IDs. Hints are trimmed, bounded and deduplicated; they never grant or automatically select a service. Names and slugs come from the authenticated inventory, and another same-slug account cannot satisfy an exact-ID hint.bind + botIdoredit + registrationId. Bind does not require an existing registration ID.skillIddefault. Refresh actual service availability and grants; newly available services receive a Requested label and remain unselected until chosen.serviceAccessReview, PKCE, callback/backend finalization and sanitizedreturnTo. The shared callback return label is “Back to previous page”. English and Chinese catalogs stay aligned.NyxID limitation
This uses the current full consent page. Ordinary repeated consent can initialize app defaults instead of all previously granted services; users must retain the services they still need under Service access → Customize. Channel selections do not initialize NyxID's picker. Opening consent does not change grants, but submitting a smaller selection can replace them.
The incremental contract proposed in NyxID #1683 remains a separate integration after upstream deployment. This change sends neither unsupported preselection inputs nor slug-based resource narrowing.
Affected paths and documentation
Channel Bind/Edit routing, shared configuration form, service picker/notice, temporary draft storage, UserService access adapter/query, callback copy and locale catalogs. The link contract, shared user path, typed draft identities and upstream limitation are documented in
apps/aevatar-console-web/docs/superpowers/specs/2026-09-28-channel-service-access.md.Backend behavior was checked against
origin/feature/integrate; this frontend PR targetsfeat/2026-08-04_workflow-activity-vnext.Local verification
Commands run from the repository root. Full frontend suite, typecheck and production build are delegated to GitHub CI by personal local workflow policy. No reliable repository-native affected typecheck is available.
Latest Bind extension: 4 relevant suites / 26 tests pass across scoped runs. The initial combined run passed the 23 existing Edit/default-skill/access tests. The new Bind suite passed all 3 tests after correcting its inventory fixture and waiting for asynchronous service rendering. Production code did not change between these test runs.
Dependency preflight selected 5 files. Its broad
workflow-activity-vnext/index.test.tsxcontains unrelated workflow/settings domains, so the execution was narrowed to the 4 channel suites above. The router entry was excluded from discovery and exercised through rendered Bind/Edit route tests. Changed-file Biome checks passed for all 4 files; stability guards and whitespace checks passed.Earlier focused validation of the edit, callback and adapter changes in this PR passed 3 suites / 27 tests, plus 7 catalog tests:
The local dev server uses the configured remote backend. Authenticated browser inspection confirmed the shared Bind Services header and Requested labels for Firecrawl and ChronoAI Lark Bot on an actual unbound bot. Existing dirty Edit tabs were preserved. Missing-access, partial/cancelled consent, restoration and explicit submission are covered by route integration tests; no live binding or new OAuth consent was submitted during Bind verification.
Design baseline
apps/aevatar-console-web/docs/design-baselines/workflow-activity-vnext/aevatar-workflow-activity-vnext.excalidraw30e74d7b410ae72c4c91432355436679033679c54c10b1702908435b001577deapps/aevatar-console-web/docs/superpowers/specs/2026-08-04-workflow-activity-vnext-design.mdapps/aevatar-console-web/docs/superpowers/specs/2026-08-04-workflow-activity-vnext-user-paths.md