fix(teams)!: harden Bot Connector transport - #1492
Draft
NeoHsu wants to merge 6 commits into
Draft
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Important
Stacked draft: logical base
stack/teams-01a-fail-closed-dispatchis PR #1491. GitHub requires an upstream PR base to exist inopenabdev/openab, so this draft temporarily targetsmainand may show preceding stack layers. Do not merge it until #1491 is merged and this branch is rebased onto currentmain; then review only its single incremental commit.What problem does this solve?
Make Teams public-cloud Bot Connector transport fail closed, bounded, and safe against credential or endpoint disclosure.
Discord Discussion URL: https://discord.com/channels/1491295327620169908/1491365158868619404/1531339032527765655
Microsoft Teams roadmap discussion.
Review Contract
Goal
Make Teams public-cloud Bot Connector transport fail closed, bounded, and safe against credential or endpoint disclosure.
Non-goals
Sovereign-cloud endpoint profiles, Graph APIs, automatic ambiguous-write retries, and route persistence are not included.
Accepted Residual Risks
Only the Microsoft public-cloud Connector allowlist is accepted. Timeouts and ambiguous responses become Unknown and may leave the platform state uncertain; no blind retry is attempted.
Acceptance Criteria
Unsafe URLs and redirects are rejected before credential use; tokens, secrets, service URLs, and raw bodies are redacted; OAuth/JWKS requests are bounded; explicit HTTP outcomes are classified consistently; tests and compilation pass.
Follow-ups
Add reviewed sovereign-cloud profiles and broader endpoint policy only with authoritative Microsoft documentation and dedicated tests.
At a Glance
Prior Art & Industry Research
OpenClaw: its Microsoft Teams extension separates access checks, Bot Framework route context, and outbound operations. For this slice the relevant comparison is Bot Framework service-URL validation, outbound transport, and credential isolation.
Hermes Agent: its Teams platform adapter keeps Teams-specific transport and message shaping behind a platform adapter. It does not provide OpenAB’s negotiated Core/Gateway outcome contract, so this PR keeps the useful adapter boundary but adds explicit fail-closed semantics.
Proposed Solution
Why this approach?
A narrow public-cloud allowlist and explicit outcomes bound credential use and make ambiguous writes observable without creating duplicates.
Alternatives Considered
Accept arbitrary
serviceUrlvalues (rejected: credential exfiltration risk) or retry every failure (rejected: duplicate activity risk).Migration
This intentionally tightens previously permissive transport behavior. Existing Microsoft commercial/public-cloud deployments need no configuration change. Deployments using sovereign, private, proxy-rewritten, or otherwise non-allowlisted Connector endpoints must keep Teams disabled or defer this upgrade until a reviewed endpoint profile is available; do not bypass the URL policy.
Validation
cargo check -p openab-gateway --features teams