Expose ExternalMessageGateway.addCollaborator for authenticated gateways - #160
Open
PrincipleTechWG wants to merge 1 commit into
Open
Conversation
…ays. Channel gateways (e.g. Teams) already authenticate caller emails for submitExternalMessage but cannot grant Build to other roster members who already have accounts. Add an owner-attributed Overseer path and surface it on the gateway so admission stays at the trusted identity boundary. Co-authored-by: Cursor <cursoragent@cursor.com>
|
I have read the CLA Document and I hereby sign the CLA You can retrigger this bot by commenting recheck in this Pull Request. Posted by the CLA Assistant Lite bot. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Channel gateways (Teams, etc.) already authenticate
callerEmailforsubmitExternalMessage, but cannot grant Build to other conversation members who already have accounts.What
ExternalMessageGateway.addCollaborator({ gadgetKey, username, role, note? })resolving the Overseer via the same${source}:${gadgetKey}naming as submit.OverseerDurableObject.addExternalCollaboratorthat grants viaSharingManageras the workspace owner (there is no browser session /#sharingCalleron this path).nullwhen the username has no account (same contract as OverseeraddCollaborator). Throws when sharing is prohibited.Why
Without this, every group-chat participant after the first needs a manual Build share in Workshop. Gateways already have roster → Graph email resolution; only the RPC is missing.
Security
Gateways remain the trusted identity boundary: only pass usernames the gateway has authenticated (never model- or client-supplied identity). Documented on the interface.
Size note
This is a small additive surface on an existing service-binding entrypoint. Happy to trim or reshape if maintainers prefer a sibling entrypoint.