feat(teams): enforce typed scope and mention routing - #1497
Draft
NeoHsu wants to merge 11 commits into
Draft
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Important
Stacked draft: logical base
stack/teams-04b-reactions-previewis PR #1496. GitHub requires an upstream PR base to exist inopenabdev/openab, so this draft temporarily targetsmainand may show preceding stack layers. Do not merge it until #1496 is merged and this branch is rebased onto currentmain; then review only its single incremental commit.What problem does this solve?
Make Teams trust and mention admission depend on authenticated typed scope rather than structural string heuristics.
Discord Discussion URL: https://discord.com/channels/1491295327620169908/1491365158868619404/1531339032527765655
Microsoft Teams roadmap discussion.
Review Contract
Goal
Make Teams trust and mention admission depend on authenticated typed scope rather than structural string heuristics.
Non-goals
This PR does not validate every client UI, enable ambient channel reading, persist routes, or add attachments.
Accepted Residual Risks
Older peers use the documented legacy shape and cannot prove all typed properties. GroupChat and Team-channel presentation still requires tenant access for live validation.
Acceptance Criteria
Personal messages do not require a mention; group/channel rules use typed recipient entities; malformed or contradictory shapes fail closed before session, attachment, or agent work; Unified and Standalone apply the same policy.
Follow-ups
Complete the unavailable GroupChat/channel live matrix and revisit ambient reading only under a separate permission ADR.
At a Glance
Prior Art & Industry Research
OpenClaw: its Microsoft Teams extension separates access checks, Bot Framework route context, and outbound operations. For this slice the relevant comparison is Teams access checks and conversation-scope admission.
Hermes Agent: its Teams platform adapter keeps Teams-specific transport and message shaping behind a platform adapter. It does not provide OpenAB’s negotiated Core/Gateway outcome contract, so this PR keeps the useful adapter boundary but adds explicit fail-closed semantics.
Proposed Solution
Why this approach?
Typed authenticated scope avoids structural guesses and allows Personal, GroupChat, and channel policy to diverge safely.
Alternatives Considered
Infer scope from IDs or parent fields (rejected: structurally ambiguous) or require mentions in Personal chat (rejected: incorrect Teams UX).
Validation
cargo check -p openab-corecargo check -p openab-gateway --features teams