Skip to content

Conversation

@nuel-solutions
Copy link
Contributor

  • Add permission_models.py with PermissionConfig and PermissionMode
  • Implement validate_user_permissions() with three modes:
    • allow-all (default, backward compatible)
    • watcher-based (validates against case watchers)
    • user-mapping (explicit Slack-to-AWS identity mapping)
  • Add admin user override and read-only command support
  • Update CDK stack to include permission config SSM parameter
  • Add comprehensive unit tests (14 tests, all passing)
  • Implement fail-closed security (denies on errors)
  • Add detailed logging for all permission checks

Resolves TODO in assets/slack_command_handler/index.py line 193

Description

Brief description of the changes made.

Type of change (Choose 1)

  • Bug Fix
  • New Feature: Non-new Integration Target
  • New Feature: New Integration Target
  • Documentation update
  • Security fix

Reason for this change

Brief description of why these changes need to be made.

Related Issue (if applicable)

Link to any related issues

Contributor Task List

  • I have reviewed the Contributing Guideline and Code of Conduct
  • I have performed a self-review of my code
  • I have added tests that prove my fix is effective or that my feature works
  • New and existing tests pass locally with my changes
  • The code coverage difference report check has passed
  • Security considerations have been addressed

New Integration Target Questions

If you are introducing a new integration target, additional scrutiny is applied to ensure a high bar is maintained.
For details on this review visit Pull Request Review Rubric.

How does the components of this integration communicate with each

Provide a brief description or attach an architecture diagram to this PR.

How does the integration authenticated and authorize connections between the integration and the target

Provide a brief description or attach a sequence diagram to this PR.

What kind of compute is used by this integration

  • Lambda
  • ECS Fargate or EKS (Auto Mode or Fargate Workers Only)
  • Other

Other: Provide a brief description or attach an architecture diagram to this PR.

How is state / caching maintained in the integration

Provide a brief description or attach a sequence diagram to this PR.

How much do you expect this integration to cost

Provide a brief set estimate or attach an estimate from https://calculator.aws/

By submitting this pull request, I confirm that my contribution is made under the terms of the MIT No Attribution license

- Add permission_models.py with PermissionConfig and PermissionMode
- Implement validate_user_permissions() with three modes:
  * allow-all (default, backward compatible)
  * watcher-based (validates against case watchers)
  * user-mapping (explicit Slack-to-AWS identity mapping)
- Add admin user override and read-only command support
- Update CDK stack to include permission config SSM parameter
- Add comprehensive unit tests (14 tests, all passing)
- Implement fail-closed security (denies on errors)
- Add detailed logging for all permission checks

Resolves TODO in assets/slack_command_handler/index.py line 193
Resolved conflicts in assets/slack_command_handler/index.py by:
- Keeping enhanced permission validation with command parameter
- Adding upstream's detailed logging for permission denials
- Preserving all upstream improvements (incident-details command, mark_slack_update, etc.)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant