Skip to content

fix(eve): slack - restrict HITL responses to turn caller#167

Open
AndrewBarba wants to merge 4 commits into
mainfrom
barba/slack-hitl-caller-only
Open

fix(eve): slack - restrict HITL responses to turn caller#167
AndrewBarba wants to merge 4 commits into
mainfrom
barba/slack-hitl-caller-only

Conversation

@AndrewBarba

@AndrewBarba AndrewBarba commented Jun 21, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • bind Slack HITL controls to the current turn caller using the Slack user_id
  • send mismatched responders an ephemeral explanation, then ignore the interaction
  • render non-actionable prompts when no Slack caller is available
  • document the behavior and add a patch changeset

Why

Slack interactions were authenticated, but any authenticated workspace user could respond to a pending HITL request. This makes caller-only responses the Slack channel default while keeping the prompt visible in the thread.

Validation

  • pnpm build
  • pnpm typecheck
  • pnpm lint
  • pnpm fmt
  • pnpm guard:invariants
  • pnpm docs:check
  • pnpm test:unit
  • pnpm test:integration
  • pnpm test:scenario

Signed-off-by: Andrew Barba <barba@hey.com>
@vercel

vercel Bot commented Jun 21, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
eve-docs Ready Ready Preview, Comment, Open in v0 Jun 22, 2026 8:24pm

@github-actions

github-actions Bot commented Jun 21, 2026

Copy link
Copy Markdown
Contributor

Bundle + Package Summary: apps/fixtures/weather-agent

Key takeaways

  • No notable deltas vs main (b42da82).

Delta vs main (b42da82)

Area Metric Baseline Current Delta
Package Packed tarball 3.27 MB 3.28 MB +12.1 kB ⚠️
Package Unpacked publish size 11.80 MB 11.84 MB +36.2 kB ⚠️
Package Installed footprint 52.01 MB 52.04 MB +36.2 kB ⚠️
Package Published files 2221 2231 +10
Package Installed files 5426 5436 +10
Runtime Unique function payloads 2 2 0
Runtime Total function bytes 9.34 MB 9.35 MB +4.6 kB ⚠️
Runtime Public routes 9 9 0
Changed function payloads vs main (b42da82) (2)
Function Status Baseline Current Delta Route changes
functions/.well-known/workflow/v1/flow.func changed 5.48 MB 5.48 MB +4.6 kB ⚠️ none
functions/__server.func changed 3.87 MB 3.87 MB +6 B ⚠️ none
Build Metadata
  • Preset: vercel
  • Nitro: nitro@3.0.260610-beta
  • Output directory: apps/fixtures/weather-agent/.vercel/output
  • Build metadata timestamp: 2026-06-22T20:25:17.428Z
  • Route aliases: 9 public, 1 internal (10 total aliases)
  • Vercel routes in config: 10
  • Severity legend: 🔴 dominant/large, 🟠 notable, 🟡 watch, ⚪ small
Package Drill-Down

Package Details

  • Package: eve@0.12.3
  • Package directory: packages/eve
  • Tarball: 3.28 MB (eve-0.12.3.tgz)
  • Unpacked payload: 11.84 MB across 2231 published files
  • Installed footprint: 52.04 MB across 5436 installed files
  • Installed root package: 10.73 MB
  • Installed dependencies: 41.32 MB
  • Runtime dependencies: 1
  • Peer dependencies: 12 (11 optional)

Installed footprint is measured from an isolated temporary npm install of the packed tarball.

Heavy installed dependencies

  • @rolldown/binding-linux-x64-gnu: 20.61 MB (39.6%)
  • eve: 10.73 MB (20.6%)
  • ai: 6.20 MB (11.9%)
  • zod: 4.97 MB (9.5%)
  • nitro: 2.41 MB (4.6%)
Publish payload breakdown
Published file size
🟠 dist/src/compiled/experimental-ai-sdk-code-mo... [####....................] 1.51 MB 12.7%
🟡 dist/src/compiled/@workflow/core/runtime.js      [##......................] 775.4 kB 6.6%
🟡 dist/src/compiled/@vercel/sandbox/index.js       [##......................] 632.0 kB 5.3%
🟡 dist/src/compiled/@chat-adapter/slack/index.js   [#.......................] 436.9 kB 3.7%
🟡 dist/src/compiled/_chunks/workflow/attribute-... [#.......................] 370.9 kB 3.1%
🔴 Other published files                            [########################] 8.12 MB 68.6%
Installed footprint breakdown
Installed package size
🔴 @rolldown/binding-linux-x64-gnu [########################] 20.61 MB 39.6%
🔴 eve                             [############............] 10.73 MB 20.6%
🔴 ai                              [#######.................] 6.20 MB 11.9%
🟠 zod                             [######..................] 4.97 MB 9.5%
🟠 nitro                           [###.....................] 2.41 MB 4.6%
🟡 rolldown                        [#.......................] 771.0 kB 1.5%
🔴 Other installed packages        [#######.................] 6.37 MB 12.2%
Runtime dependencies (1)
Package Range Notes
nitro 3.0.260610-beta
Peer dependencies (12)
Package Range Notes
@opentelemetry/api ^1.0.0 optional peer
@sveltejs/kit ^2.0.0 optional peer
ai catalog:
braintrust ^3.0.0 optional peer
just-bash ^3.0.0 optional peer
microsandbox ^0.5.0 optional peer
next ^16.0.0 optional peer
nuxt ^4.0.0 optional peer
react ^19.0.0 optional peer
svelte ^5.0.0 optional peer
vite ^8.0.0 optional peer
vue ^3.5.0 optional peer
Function Drill-Down

Payload Size Graph

Unique function payload size and share of total
🔴 functions/.well-known/workflow/v1/flow.func     [########################] 5.48 MB 58.6%
🔴 functions/__server.func                         [#################.......] 3.87 MB 41.4%

Top Function Payloads

🟠 functions/.well-known/workflow/v1/flow.func • 1 public route • 5.48 MB
Metric Value
Public routes /.well-known/workflow/v1/flow
Runtime nodejs24.x
Handler index.mjs
Payload 5.48 MB
Function files 5.48 MB across 27 files
Traced dependencies 0 B
Signal 🟠 Bundled file __eve_nitro_handler__.mjs is 1.51 MB (27.6%)

🟠 🔎 Dependency Analysis

📦 Bundled files:

Bundled file size
🟠 __eve_nitro_handler__.mjs              [########################] 1.51 MB 27.6%
🟠 _chunks/runtime.mjs                    [###############.........] 958.4 kB 17.5%
🟡 _chunks/sandbox.mjs                    [############............] 766.0 kB 14.0%
🟡 _chunks/attribute-changes-Bi5DLT8S.mjs [########................] 472.2 kB 8.6%
🟡 _chunks/dist-DTchiX0N.mjs              [#######.................] 460.6 kB 8.4%
🟠 Other bundled files                    [#####################...] 1.31 MB 23.9%

🧾 Vercel Config

{
  "handler": "index.mjs",
  "launcherType": "Nodejs",
  "shouldAddHelpers": false,
  "supportsResponseStreaming": true,
  "runtime": "nodejs24.x",
  "environment": {
    "NODE_OPTIONS": "--experimental-require-module",
    "WORKFLOW_QUEUE_NAMESPACE": "eve"
  },
  "maxDuration": "max",
  "experimentalTriggers": [
    {
      "type": "queue/v2beta",
      "topic": "__eve_wkf_workflow_*",
      "consumer": "default",
      "retryAfterSeconds": 5,
      "initialDelaySeconds": 0
    }
  ]
}

🟠 functions/__server.func • 8 public routes, 1 internal alias • 3.87 MB
Metric Value
Public routes /
/eve/v1/callback/[token]
/eve/v1/connections/[name]/callback/[token]
/eve/v1/health
/eve/v1/info
/eve/v1/session
/eve/v1/session/[sessionId]
/eve/v1/session/[sessionId]/stream
Internal aliases /__server
Runtime nodejs24.x
Handler index.mjs
Payload 3.87 MB
Function files 3.87 MB across 21 files
Traced dependencies 0 B
Signal 🟠 Bundled file index.mjs is 1.40 MB (36.3%)

🟠 🔎 Dependency Analysis

📦 Bundled files:

Bundled file size
🟠 index.mjs                              [########################] 1.40 MB 36.3%
🟠 _chunks/runtime.mjs                    [###############.........] 875.8 kB 22.6%
🟠 _chunks/sandbox.mjs                    [#############...........] 766.0 kB 19.8%
🟡 _chunks/attribute-changes-Bi5DLT8S.mjs [########................] 448.5 kB 11.6%
⚪ _libs/zod.mjs                          [##......................] 114.2 kB 3.0%
🟡 Other bundled files                    [####....................] 258.8 kB 6.7%

🧾 Vercel Config

{
  "handler": "index.mjs",
  "launcherType": "Nodejs",
  "shouldAddHelpers": false,
  "supportsResponseStreaming": true,
  "runtime": "nodejs24.x"
}

Signed-off-by: Andrew Barba <barba@hey.com>
@AndrewBarba AndrewBarba marked this pull request as ready for review June 21, 2026 18:55
Comment on lines +216 to +218
if (unauthorizedAction) {
notifyUnauthorizedHitlResponder(interaction, unauthorizedAction.user.id, ctx.waitUntil, deps);
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Shouldn't we return early here as well?


/** Returns a request-unique Block Kit block id that authorizes one Slack user. */
export function hitlResponderBlockId(userId: string, requestId: string): string {
return `${HITL_RESPONDER_BLOCK_PREFIX}${userId}:${requestId}`;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants