feat(teams): add metadata-first attachment ingress - #1500
Draft
NeoHsu wants to merge 14 commits into
Draft
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Important
Stacked draft: logical base
stack/teams-07-progressive-responseis PR #1499. GitHub requires an upstream PR base to exist inopenabdev/openab, so this draft temporarily targetsmainand may show preceding stack layers. Do not merge it until #1499 is merged and this branch is rebased onto currentmain; then review only its single incremental commit.What problem does this solve?
Allow trusted Teams turns to materialize bounded image and text attachments only after all admission gates pass.
Discord Discussion URL: https://discord.com/channels/1491295327620169908/1491365158868619404/1531339032527765655
Microsoft Teams roadmap discussion.
Review Contract
Goal
Allow trusted Teams turns to materialize bounded image and text attachments only after all admission gates pass.
Non-goals
Arbitrary binary files, Graph/RSC downloads, Office document parsing, outbound files, and default enablement are excluded.
Accepted Residual Risks
Some Teams client upload paths require a separately packaged manifest capability; unsupported or oversized attachments are represented as bounded rejected metadata rather than downloaded.
Acceptance Criteria
The feature is default off on both processes; metadata crosses first; denied events and recognized commands cause no download; auth never crosses into Core; redirects cannot forward Bot credentials cross-origin; budgets and single-use claims are enforced.
Follow-ups
Validate the separately packaged
supportsFilestenant path and add new file classes only with explicit media/security policy.At a Glance
Prior Art & Industry Research
OpenClaw: its Microsoft Teams extension separates access checks, Bot Framework route context, and outbound operations. For this slice the relevant comparison is authenticated inbound attachment handling and deferred media access.
Hermes Agent: its Teams platform adapter keeps Teams-specific transport and message shaping behind a platform adapter. It does not provide OpenAB’s negotiated Core/Gateway outcome contract, so this PR keeps the useful adapter boundary but adds explicit fail-closed semantics.
Proposed Solution
Why this approach?
Metadata-first admission ensures Microsoft credentials and bytes stay outside Core until trust and command gates have completed.
Alternatives Considered
Download in Gateway before Core admission (rejected: untrusted resource use) or use Graph/RSC (rejected: expands permissions and secret scope).
Validation
cargo check -p openab-corecargo check -p openab-gateway --features teams