Skip to content

fix(server): deny unknown users on every inbound channel - #482

Merged
patroza merged 2 commits into
fork/devfrom
fix/known-user-channel-gate
Sep 23, 2026
Merged

patroza merged 2 commits into
fork/devfrom
fix/known-user-channel-gate

Conversation

@patroza

@patroza patroza commented Sep 23, 2026 •

Copy link
Copy Markdown
Owner

Summary

GitHub, Discord, and Teams refuse anyone who is not on the identity map. They cannot start, continue, stop, or approve a T3 thread.

Jira uses the same gate for the agent. An unmapped Jira account can still leave a context note on a thread that is already linked. That note does not start or continue the agent.

Teams people are matched by teamsAadObjectId (Azure AD object id / Graph from.user.id) or teamsUserId (Bot Framework 29:… id). An empty map denies everyone.

Test plan

  • Identity map, Teams actor, and Jira trust tests
  • Changed-file check and typecheck on the first push
  • After deploy, an unmapped Teams user cannot open or continue a thread; an unmapped Jira user can leave a context note on an already-linked thread and cannot run the agent

grok-4.7 / Grok harness

Jira let unmapped accounts append context onto a linked thread, and Teams started or continued a thread for anyone who could reach the bot. Both now use the same closed identity map as Discord and GitHub: an empty map or an unmapped actor cannot start, continue, stop, or approve a thread.

Teams people are matched by Azure AD object id (`teamsAadObjectId`) or Bot Framework user id (`teamsUserId`).

grok-4.7 / Grok harness
Unknown Jira accounts still cannot start or continue an agent thread. They can leave a context note on a thread that is already linked.

grok-4.7 / Grok harness
@patroza
patroza marked this pull request as ready for review September 23, 2026 09:34
@patroza
patroza merged commit fa27684 into fork/dev Sep 23, 2026
13 of 16 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant