feat(teams): bound ingress routes and deduplicate activities - #1493
Draft
NeoHsu wants to merge 7 commits into
Draft
feat(teams): bound ingress routes and deduplicate activities#1493NeoHsu wants to merge 7 commits into
NeoHsu wants to merge 7 commits into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Important
Stacked draft: logical base
stack/teams-01b-connector-transportis PR #1492. GitHub requires an upstream PR base to exist inopenabdev/openab, so this draft temporarily targetsmainand may show preceding stack layers. Do not merge it until #1492 is merged and this branch is rebased onto currentmain; then review only its single incremental commit.What problem does this solve?
Correlate authenticated inbound activities to later replies without cross-tenant collisions or duplicate publication.
Discord Discussion URL: https://discord.com/channels/1491295327620169908/1491365158868619404/1531339032527765655
Microsoft Teams roadmap discussion.
Review Contract
Goal
Correlate authenticated inbound activities to later replies without cross-tenant collisions or duplicate publication.
Non-goals
No restart persistence, proactive routing, write acknowledgement requirement, or durable activity ownership is added.
Accepted Residual Risks
Route and dedupe state is process-local and disappears on restart; capacity pressure can reject new work rather than evict in-flight publishers.
Acceptance Criteria
State is bounded and expires independently; duplicate waiters share one publication result; tenant/conversation collisions are impossible; failed enqueue rolls back provisional state; untrusted or malformed activities create no accepted route.
Follow-ups
Persist only trusted conversation-level routes in PR 11; activity ownership and dedupe remain intentionally ephemeral.
At a Glance
Prior Art & Industry Research
OpenClaw: its Microsoft Teams extension separates access checks, Bot Framework route context, and outbound operations. For this slice the relevant comparison is trusted send context, scoped route state, and duplicate suppression.
Hermes Agent: its Teams platform adapter keeps Teams-specific transport and message shaping behind a platform adapter. It does not provide OpenAB’s negotiated Core/Gateway outcome contract, so this PR keeps the useful adapter boundary but adds explicit fail-closed semantics.
Proposed Solution
Why this approach?
Composite, bounded in-memory keys prevent cross-scope collisions while keeping activity-level state intentionally ephemeral.
Alternatives Considered
Key only by activity ID (rejected: cross-tenant collisions) or persist all activity state (rejected: unnecessary sensitive durability).
Validation
cargo check -p openab-gateway --features teams