diff --git a/cmd/route_parity/main.go b/cmd/route_parity/main.go index 14bb157a..b6938d08 100644 --- a/cmd/route_parity/main.go +++ b/cmd/route_parity/main.go @@ -233,6 +233,7 @@ var criticalRoutes = []route{ {Method: "GET", Path: "/api/v1/accounts/:account_id/integrations/slack/list_all_channels", Controller: "api/v1/accounts/integrations/slack#list_all_channels", Source: "routes.rb:352"}, {Method: "POST", Path: "/api/v1/accounts/:account_id/integrations/dyte/create_a_meeting", Controller: "api/v1/accounts/integrations/dyte#create_a_meeting", Source: "routes.rb:357"}, {Method: "POST", Path: "/api/v1/accounts/:account_id/integrations/dyte/add_participant_to_meeting", Controller: "api/v1/accounts/integrations/dyte#add_participant_to_meeting", Source: "routes.rb:358"}, + {Method: "POST", Path: "/api/v1/accounts/:account_id/notion/authorization", Controller: "api/v1/accounts/notion/authorizations#create", Source: "routes.rb:335"}, {Method: "DELETE", Path: "/api/v1/accounts/:account_id/integrations/shopify", Controller: "api/v1/accounts/integrations/shopify#destroy", Source: "routes.rb:361"}, {Method: "POST", Path: "/api/v1/accounts/:account_id/integrations/shopify/auth", Controller: "api/v1/accounts/integrations/shopify#auth", Source: "routes.rb:363"}, {Method: "GET", Path: "/api/v1/accounts/:account_id/integrations/shopify/orders", Controller: "api/v1/accounts/integrations/shopify#orders", Source: "routes.rb:364"}, diff --git a/docs/CHATWOOT_PARITY_DEVELOPMENT_PLAN.md b/docs/CHATWOOT_PARITY_DEVELOPMENT_PLAN.md index bdc29a1a..67ef0c7e 100644 --- a/docs/CHATWOOT_PARITY_DEVELOPMENT_PLAN.md +++ b/docs/CHATWOOT_PARITY_DEVELOPMENT_PLAN.md @@ -49,16 +49,16 @@ Hermes task landing checklist: ## Current Baseline -- Current tracking checkpoint: 2026-06-06 Notion integration destroy parity checkpoint, prepared as `feat(integrations): align notion parity`. -- Latest implementation checkpoint: this checkpoint, prepared as `feat(integrations): align notion parity`. +- Current tracking checkpoint: 2026-06-06 Notion authorization parity checkpoint, prepared as `feat(integrations): align notion authorization`. +- Latest implementation checkpoint: this checkpoint, prepared as `feat(integrations): align notion authorization`. - Latest documentation/tooling checkpoint: this tracker update for P3.24 plus the landed parity tracker history; this document is the active follow-up plan and supersedes `.hermes/plans/*`. - Plan landing status: complete for the current known Hermes plans and user-confirmed scope. Future work should update this file directly instead of opening a parallel tracker. -- Worktree status at this implementation checkpoint: Notion account destroy from `reference/chatwoot/config/routes.rb:379`, `Api::V1::Accounts::Integrations::NotionController`, Notion callback specs, and reused dashboard integrations API are implemented. GoChat now exposes no-trailing and trailing Notion destroy routes, finds OAuth callback-created hooks by `app_id: notion` with legacy `hook_type` fallback, and returns Chatwoot-compatible empty `200 OK` deletes. Live API/browser/enterprise smoke still needs the full PostgreSQL/Redis/Meilisearch/GoChat/Vite/Chrome stack. +- Worktree status at this implementation checkpoint: Notion account authorization from `reference/chatwoot/config/routes.rb:334-335`, `Api::V1::Accounts::Notion::AuthorizationsController`, Notion authorization request specs, Notion callback specs, and reused dashboard `notion_auth.js` are implemented. GoChat now exposes admin-gated `POST /api/v1/accounts/:account_id/notion/authorization`, returns Chatwoot `{ success: true, url }` payloads, signs callback state for the existing Notion callback, and keeps Notion destroy routes/hook lookup/delete responses aligned. Live API/browser/enterprise smoke still needs the full PostgreSQL/Redis/Meilisearch/GoChat/Vite/Chrome stack. - Next executable implementation checkpoint: continue Phase 2/3 drift audit, Phase 6 placeholder audit, or B12 live smoke from fresh reference/smoke evidence. - `go test ./...` passes when run outside the restricted socket sandbox; focused Shopify handler/service tests pass in the sandbox. -- Route dump succeeds with `941` registered routes after Notion no-trailing destroy tracking. +- Route dump succeeds with `942` registered routes after Notion authorization tracking. - Route parity artifacts now exist under `docs/parity/` and are generated by `cmd/route_parity`. -- Tracked frontend-critical route audit covers 404 Chatwoot routes: 391 exact, 0 method-compatible, 13 parameter-compatible, 0 missing. The 13 parameter-compatible routes are Gin-internal parameter-name differences for nested AgentCapacityPolicy users/inbox limits, dashboard app member `:id` names, plus the public article `.md`/`.png` suffixes served through the same external article route dispatcher. +- Tracked frontend-critical route audit covers 405 Chatwoot routes: 392 exact, 0 method-compatible, 13 parameter-compatible, 0 missing. The 13 parameter-compatible routes are Gin-internal parameter-name differences for nested AgentCapacityPolicy users/inbox limits, dashboard app member `:id` names, plus the public article `.md`/`.png` suffixes served through the same external article route dispatcher. - `/api/v1/widget` stubs are burned down and public inbox/contact/conversation/message core flows are backed by real handlers. - Handler test stability fixes are committed into the baseline before feature parity work continues. - `.codegraph/` is generated indexing output and is not part of tracked product code. @@ -140,13 +140,14 @@ This table is the shortest authoritative handoff view. If an older lower section | Priority | Workstream | Current state | Next checkpoint | Commit close rule | | --- | --- | --- | --- | --- | +| 0 | P3.28 Notion authorization parity | Implemented for reused dashboard Notion connect flow: `POST /api/v1/accounts/:account_id/notion/authorization` is registered and tracked from `routes.rb:335`, the route is administrator-gated like Chatwoot's `OauthAuthorizationController`, the response returns raw `{ success: true, url }`, the URL targets `https://api.notion.com/v1/oauth/authorize` with `response_type=code`, `owner=user`, frontend `/notion/callback`, configured `client_id`, and signed account state for the existing callback. | Keep in Review; reopen only if live Notion OAuth smoke exposes GlobalID state compatibility, config-source drift, feature-gate behavior, or frontend payload drift beyond the inspected authorization controller/spec/frontend contract. | Focused Notion authorization handler/service tests, route dump/parity regeneration (`942` routes; `392 exact`, `13 parameter-compatible`, `0 missing out of 405`), full `go test ./...`, and `git diff --check` must pass before commit. | | 0 | P3.27 Notion integration destroy parity | Implemented for reused dashboard Notion integration disconnect flow: no-trailing and trailing destroy routes are registered, the account route is tracked from `routes.rb:379`, OAuth callback-created hooks are found by `app_id: notion` with legacy hook-type fallback, and delete returns empty `200 OK` instead of a local success/message envelope. | Keep in Review; reopen only if live Notion OAuth/disconnect smoke exposes feature-gate drift, callback-created hook shape drift, or frontend delete error handling beyond the inspected controller/spec/frontend contract. | Focused Notion handler/service tests, route dump/parity regeneration (`941` routes; `391 exact`, `13 parameter-compatible`, `0 missing out of 404`), full `go test ./...`, and `git diff --check` must pass before commit. | | 0 | P3.26 Shopify integration parity | Implemented for reused dashboard Shopify integration and customer-order panel: no-trailing and trailing destroy routes are registered, auth returns raw `{ redirect_url }`, missing shop domains return Chatwoot's `422 { error: "Shop domain is required" }`, orders returns raw `{ orders: [...] }`, account-scoped contacts are required, contacts without email/phone return `422 { error: "Contact information missing" }`, Shopify customers/search and orders REST calls are made through fakeable clients, order payloads include `admin_url`, callback-created hooks are found by `app_id: shopify`, and delete returns empty `200 OK`. | Keep in Review; reopen only if live Shopify OAuth/order smoke exposes token/session setup drift, REST API version drift, Shopify error-body wording, or frontend order payload drift beyond the inspected controller/helper/spec/frontend contract. | Focused Shopify handler/service tests, route dump/parity regeneration (`940` routes; `390 exact`, `13 parameter-compatible`, `0 missing out of 403`), sandbox package tests, escalated full `go test ./...`, and `git diff --check` passed. | | 0 | P3.25 Linear integration parity | Implemented for reused dashboard Linear issue flow: no-trailing and trailing destroy routes are registered, teams/team_entities/search/linked/create/link/unlink return raw Chatwoot payloads, provider errors return `422 { error }`, blank search returns Chatwoot's exact search-string error, requests proxy Linear GraphQL via fakeable clients, delete revokes Linear tokens and returns empty `200 OK`, create/link/unlink resolve conversations by account display ID, conversation links use the reused frontend URL, and successful mutations create Chatwoot-style Linear activity messages. | Keep in Review; reopen only if live Linear OAuth/GraphQL smoke exposes token refresh behavior, GraphQL query/mutation field drift, activity job queue semantics, or frontend payload drift beyond the inspected controller/processor/client/spec contract. | Focused Linear handler/service tests, route dump/parity regeneration (`939` routes; `387 exact`, `13 parameter-compatible`, `0 missing out of 400`), sandbox package tests, escalated full `go test ./...`, and `git diff --check` passed. | | 0 | P3.24 Slack integration parity | Implemented for reused dashboard Slack settings flow: no-trailing and trailing singleton routes are registered for create/update/delete, `PUT` and `PATCH` update both work, create accepts frontend `code` and exchanges it for a Slack access token, hooks are persisted with `app_id: slack` and disabled status, update accepts frontend `reference_id`, fetches real private/public Slack channels with pagination, joins public channels, persists `reference_id/settings.channel_name/status`, create/update return raw Chatwoot app payloads with hooks, list-all returns raw channel arrays, invalid channels return Chatwoot's `422 { error }`, and delete returns empty `200 OK`. | Keep in Review; reopen only if live Slack OAuth/channel smoke exposes OAuth redirect, provider error, app serializer, or Slack channel pagination drift beyond the inspected controller/builder/spec/frontend contract. | Focused Slack handler/service tests, route dump/parity regeneration, sandbox focused `go test`, escalated full `go test ./...`, and `git diff --check` passed. | | 0 | P3.23 nested contact inbox creation API | Implemented for Chatwoot nested contact inbox creation: raw JSON/form/query params are accepted, contact and inbox are account-scoped, missing source IDs are generated through Chatwoot channel rules, duplicate contact+inbox+source rows are returned idempotently, `hmac_verified` is persisted on creation, and the response is raw `{ source_id, inbox }` rather than the local model/envelope. | Keep in Review; reopen only if live CRM/new-conversation smoke exposes inbox access-policy, unsupported channel, or serializer drift beyond the inspected controller/builder/Jbuilder contract. | Focused nested ContactInbox handler/service/repository tests, route parity check, full `go test ./...`, and `git diff --check` passed. | | 1 | P3.2a invitation/confirmation mail parity | Implemented for current non-SSO reference behavior: profile resend is no longer a TODO-only log, new invited agents and unconfirmed invited profile resends generate reset-password invitation links, normal unconfirmed profile resends generate confirmation links, `users.unconfirmed_email` is modeled for email-update routing, and fakeable/environment SMTP mailers keep default tests offline. | Keep in Review; reopen only if reused frontend smoke or fresh reference evidence exposes additional Devise confirmation states outside excluded SSO/SAML/LDAP/OIDC variants. | Focused profile and agent invitation tests, combined handler/service/repository/router/migrate/app tests, full `go test ./...`, and `git diff --check` passed. | -| 2 | Phase 2/3 drift | Tracked route parity is 0 missing for the current 404-route critical set; dashboard `/app` shell routes from `routes.rb:19-20`, `.well-known` app association and custom-domain challenge routes from `routes.rb:657-660`, Twilio callback routes from `routes.rb:639-640`, enterprise Twilio voice routes from `routes.rb:643-646`, root Linear/Shopify/Notion OAuth callback routes from `routes.rb:630/634/654`, root Twitter/Google/Microsoft/Instagram/TikTok callback routes from `routes.rb:626/649-652`, assignment policy routes from `routes.rb:306-313`, help-center portal/category/article routes from `routes.rb:385-404`, public help-center portal/sitemap/article/category/search/article-detail routes from `routes.rb:590-601`, enterprise contact outbound voice call from `routes.rb:216`, account agent-bot routes from `routes.rb:94-97`, account webhook routes from `routes.rb:342`, account integration app/hook routes from `routes.rb:345-348`, account Slack routes from `routes.rb:350-352`, account Dyte routes from `routes.rb:357-358`, account Shopify routes from `routes.rb:361-364`, account Linear routes from `routes.rb:365-373`, account Notion route from `routes.rb:379`, dashboard app routes from `routes.rb:130`, canned response routes from `routes.rb:114`, notification subscription routes from `routes.rb:440`, team/team-member routes from `routes.rb:296-300`, conversation participant routes from `routes.rb:150`, conversation direct upload route from `routes.rb:151`, conversation draft message routes from `routes.rb:152`, conversation inbox assistant route from `routes.rb:165`, conversation reporting events route from `routes.rb:166`, and account reporting events route from `routes.rb:234` are now explicitly tracked. Notification list/action serializers, user notification-settings raw payloads, campaigns raw payload/display-id routes, Devise password reset/confirmation payloads, CRM shared attachment payloads plus fixed 100-row attachment pagination, account/settings payloads, assignable-agent payloads, agent index full-list behavior, agent create/update/delete defaults/errors/scope, account agent-bot route/payload/mutation behavior, account webhook payload/mutation behavior, integration app/hook payload behavior, account Slack OAuth/channel payload behavior, account Dyte create/join payload behavior, account Shopify customer-order payload behavior, account Linear GraphQL issue payload behavior, account Notion destroy behavior, dashboard app raw payload/serializer behavior, canned response raw payload/search/delete behavior, notification subscription payload behavior, team update/frontend route behavior, conversation participant route/payload/final-set update behavior, conversation direct upload ActiveStorage behavior, conversation draft message Redis-key-equivalent behavior, conversation inbox assistant Copilot payload behavior, conversation reporting-event raw array behavior, account reporting-events payload/filter/pagination behavior, label CRUD payloads, custom filters, custom attribute definitions, contact outbound voice calls, assignment policy CRUD and inbox binding payloads, Twilio inbound/status callbacks, enterprise Twilio voice callbacks, Linear/Shopify/Notion root integration callbacks, Shopify OAuth auth redirects, root channel OAuth callbacks, help-center portal/category/article payloads, dashboard app shell route behavior, app association JSON payloads, Cloudflare custom hostname verification, public widget popular-article lists, public help-center category list/show payloads, public portal show/default-locale payloads, public portal search payloads, public article show/markdown/tracking routes, and public sitemap XML now match the inspected Chatwoot contract. | Continue the next evidence-backed route/controller/serializer drift after Notion parity or from B12 findings. | Regenerate parity artifacts when routes change and add endpoint-family fixture tests. | +| 2 | Phase 2/3 drift | Tracked route parity is 0 missing for the current 405-route critical set; dashboard `/app` shell routes from `routes.rb:19-20`, `.well-known` app association and custom-domain challenge routes from `routes.rb:657-660`, Twilio callback routes from `routes.rb:639-640`, enterprise Twilio voice routes from `routes.rb:643-646`, root Linear/Shopify/Notion OAuth callback routes from `routes.rb:630/634/654`, root Twitter/Google/Microsoft/Instagram/TikTok callback routes from `routes.rb:626/649-652`, assignment policy routes from `routes.rb:306-313`, help-center portal/category/article routes from `routes.rb:385-404`, public help-center portal/sitemap/article/category/search/article-detail routes from `routes.rb:590-601`, enterprise contact outbound voice call from `routes.rb:216`, account agent-bot routes from `routes.rb:94-97`, account webhook routes from `routes.rb:342`, account integration app/hook routes from `routes.rb:345-348`, account Slack routes from `routes.rb:350-352`, account Dyte routes from `routes.rb:357-358`, account Shopify routes from `routes.rb:361-364`, account Linear routes from `routes.rb:365-373`, account Notion authorization/destroy routes from `routes.rb:335/379`, dashboard app routes from `routes.rb:130`, canned response routes from `routes.rb:114`, notification subscription routes from `routes.rb:440`, team/team-member routes from `routes.rb:296-300`, conversation participant routes from `routes.rb:150`, conversation direct upload route from `routes.rb:151`, conversation draft message routes from `routes.rb:152`, conversation inbox assistant route from `routes.rb:165`, conversation reporting events route from `routes.rb:166`, and account reporting events route from `routes.rb:234` are now explicitly tracked. Notification list/action serializers, user notification-settings raw payloads, campaigns raw payload/display-id routes, Devise password reset/confirmation payloads, CRM shared attachment payloads plus fixed 100-row attachment pagination, account/settings payloads, assignable-agent payloads, agent index full-list behavior, agent create/update/delete defaults/errors/scope, account agent-bot route/payload/mutation behavior, account webhook payload/mutation behavior, integration app/hook payload behavior, account Slack OAuth/channel payload behavior, account Dyte create/join payload behavior, account Shopify customer-order payload behavior, account Linear GraphQL issue payload behavior, account Notion authorization/destroy behavior, dashboard app raw payload/serializer behavior, canned response raw payload/search/delete behavior, notification subscription payload behavior, team update/frontend route behavior, conversation participant route/payload/final-set update behavior, conversation direct upload ActiveStorage behavior, conversation draft message Redis-key-equivalent behavior, conversation inbox assistant Copilot payload behavior, conversation reporting-event raw array behavior, account reporting-events payload/filter/pagination behavior, label CRUD payloads, custom filters, custom attribute definitions, contact outbound voice calls, assignment policy CRUD and inbox binding payloads, Twilio inbound/status callbacks, enterprise Twilio voice callbacks, Linear/Shopify/Notion root integration callbacks, Shopify OAuth auth redirects, root channel OAuth callbacks, help-center portal/category/article payloads, dashboard app shell route behavior, app association JSON payloads, Cloudflare custom hostname verification, public widget popular-article lists, public help-center category list/show payloads, public portal show/default-locale payloads, public portal search payloads, public article show/markdown/tracking routes, and public sitemap XML now match the inspected Chatwoot contract. | Continue the next evidence-backed route/controller/serializer drift after Notion authorization parity or from B12 findings. | Regenerate parity artifacts when routes change and add endpoint-family fixture tests. | | 3 | Phase 6 placeholder audit | Widget/public/webhook critical placeholders are burned down; inbox WhatsApp health/register-webhook and sync-template drift are closed; refreshed `docs/parity/placeholder_audit.md` shows only webhook nil-handler fallbacks still call `chatwootParityStub`; dashboard conversation transcript/custom-attribute response drift and message retry status drift are closed. | Keep in Review; reopen only if fresh `rg`, route smoke, or B12 finds a frontend-reachable placeholder/stub in account/contact/conversation/message/inbox/widget/public paths. | `rg` placeholder audit and `scripts/parity_frontend_smoke.sh --check` are recorded; no reused-frontend blocker is ownerless. | | 4 | P3.9 account agent-bot API | Implemented for the reused dashboard AgentBots settings route with no-trailing-slash routes, PATCH update, raw Jbuilder-style payloads, account mutation scope, system-bot show/list visibility, empty `200 OK` delete, and full reset/avatar action payloads. | Keep in Review; reopen only if live settings smoke exposes avatar upload storage or administrator-secret gating drift. | Focused AgentBot handler tests, service/router focused tests, route dump/parity regeneration, full `go test ./...`, and `git diff --check` passed. | | 5 | P3.10 account webhooks API | Implemented for the reused dashboard Webhooks settings route with PATCH update, Chatwoot `{ payload }` list/mutation serializers, nested `{ webhook: ... }` bodies, generated secret, account-scoped mutations, URL/subscription validation, optional inbox serialization, and empty `200 OK` delete. | Keep in Review; reopen only if live settings smoke exposes audit writer or delivery-signature drift beyond the existing delivery service boundary. | Focused webhook handler/service/router tests, migration test, route dump/parity regeneration, full `go test ./...`, and `git diff --check` passed. | @@ -242,6 +243,7 @@ This ledger records the committed parity checkpoints that future slices should b | Commit | Scope | Verification summary | Follow-up state | | --- | --- | --- | --- | +| `feat(integrations): align notion authorization` | Advances P3.28 Notion authorization parity by matching Chatwoot `Api::V1::Accounts::Notion::AuthorizationsController#create`, route `335`, request specs, and reused dashboard `notion_auth.js`. GoChat now exposes administrator-gated `POST /api/v1/accounts/:account_id/notion/authorization`, returns raw `{ success: true, url }`, builds the Notion OAuth authorize URL with `response_type=code`, `owner=user`, frontend `/notion/callback`, configured client ID, and signed account state compatible with the existing callback. | `go test ./internal/service ./internal/handler/api/v1 ./internal/router ./cmd/route_parity -run 'NotionIntegration\|Router\|RouteParity' -count=1`; `go run ./cmd/dump_routes > docs/parity/gochat_routes.txt`; `go run ./cmd/route_parity`; full `go test ./...`; `git diff --check`. Route dump is `TOTAL: 942`; tracked route parity is `392 exact, 0 method-compatible, 13 parameter-compatible, 0 missing out of 405`. | P3.28 moves to Review for current Notion authorization evidence; continue Phase 2/3 drift audit, Phase 6 placeholder audit, B12 live smoke, or fresh reference/smoke drift. | | `feat(integrations): align notion parity` | Advances P3.27 Notion integration destroy parity by matching Chatwoot `Api::V1::Accounts::Integrations::NotionController#destroy`, route `379`, Notion callback hook shape, and reused dashboard integrations delete flow. GoChat now exposes no-trailing and trailing `DELETE /api/v1/accounts/:account_id/integrations/notion`, finds OAuth-created hooks by `app_id: notion` with legacy hook-type fallback, and returns empty `200 OK` instead of the local `{ message }` envelope. | `go test ./internal/service ./internal/handler/api/v1 ./cmd/route_parity -run 'NotionIntegration\|RouteParity' -count=1`; `go test ./internal/service ./internal/handler/api/v1 ./internal/router ./cmd/route_parity -run 'NotionIntegration\|Router\|RouteParity' -count=1`; `go run ./cmd/dump_routes > docs/parity/gochat_routes.txt`; `go run ./cmd/route_parity`; full `go test ./...`; `git diff --check`. Route dump is `TOTAL: 941`; tracked route parity is `391 exact, 0 method-compatible, 13 parameter-compatible, 0 missing out of 404`. | P3.27 moves to Review for current Notion destroy evidence; continue Phase 2/3 drift audit, Phase 6 placeholder audit, B12 live smoke, or fresh reference/smoke drift. | | `feat(contacts): align contact inbox creation` | Advances P3.23 nested contact inbox creation parity by matching Chatwoot `Api::V1::Accounts::Contacts::ContactInboxesController#create`, `ContactInboxBuilder`, `HmacConcern`, route `212`, request specs, and the contact inbox Jbuilder partial. GoChat now accepts raw JSON/form/query params, account-scopes contact and inbox lookup, generates source IDs for API/WebWidget/Email/Sms/Whatsapp/Twilio channels, returns existing contact+inbox+source rows idempotently, persists `hmac_verified` on creation, and returns raw `{ source_id, inbox }` instead of the local model. | `go test ./internal/handler/api/v1 ./internal/service ./internal/repository -run 'ContactInbox\|ContactHandlerCRUD' -count=1`; `go test ./internal/handler/api/v1 ./internal/service ./internal/repository ./internal/router ./cmd/route_parity -run 'ContactInbox\|ContactHandlerCRUD\|Router\|RouteParity' -count=1`; `go run ./cmd/route_parity`; full `go test ./...`; `git diff --check`. Route dump remains `TOTAL: 933`; tracked route parity remains `374 exact, 0 method-compatible, 13 parameter-compatible, 0 missing out of 387`. | P3.23 moves to Review for current nested contact inbox creation evidence; continue Phase 2/3 drift audit, Phase 6 placeholder audit, B12 live smoke, or fresh reference/smoke drift. | | `docs: land contact inbox parity plan` | Documentation-only checkpoint requested before continuing implementation. Confirms the clean committed baseline at `2072396 feat(reporting): align account events`, lands P3.23 nested contact inbox creation as the next executable slice, and records the exact Chatwoot route/controller/builder/HMAC/Jbuilder references plus Go owner files, behavior gaps, and exit gates. | `git diff --check`. No Go code or route artifacts changed. | Start `feat(contacts): align contact inbox creation`, then continue Phase 2/3 drift audit, Phase 6 placeholder audit, or B12 live smoke from concrete reference/smoke evidence. | @@ -2446,3 +2448,4 @@ Verification milestone gates: - 2026-06-06: P3.25 Linear integration checkpoint prepared as `feat(integrations): align linear parity`; audited Chatwoot Linear controller/request specs, processor service, GraphQL client queries/mutations, activity-message service, account routes `365-373`, and reused dashboard Linear API. GoChat now exposes no-trailing and trailing Linear destroy plus teams/team_entities/create/link/unlink/search/linked routes, calls Linear GraphQL through fakeable clients, returns raw Chatwoot data payloads, maps provider failures to `422 { error }`, resolves conversations by account display ID, builds frontend conversation links, creates Linear activity messages for create/link/unlink, revokes tokens on delete, and returns empty `200 OK`. Focused Linear handler/service tests, route dump/parity regeneration (`939` routes; `387 exact`, `13 parameter-compatible`, `0 missing out of 400`), sandbox package tests, escalated full `go test ./...`, and `git diff --check` passed; continue Phase 2/3 drift audit, Phase 6 placeholder audit, or B12 live smoke. - 2026-06-06: P3.26 Shopify integration checkpoint prepared as `feat(integrations): align shopify parity`; audited Chatwoot Shopify account controller/specs, integration helper, callback behavior, routes `361-364`, and reused dashboard integrations/Shopify APIs. GoChat now exposes no-trailing and trailing Shopify destroy, returns raw auth/order payloads, uses Chatwoot `422 { error }` bodies for missing shop domains and missing contact info, resolves account-scoped contacts, calls Shopify customer search and orders REST endpoints through fakeable clients, appends order `admin_url`, finds callback-created hooks by `app_id: shopify`, and deletes with empty `200 OK`. Focused Shopify handler/service tests, route dump/parity regeneration (`940` routes; `390 exact`, `13 parameter-compatible`, `0 missing out of 403`), sandbox package tests, escalated full `go test ./...`, and `git diff --check` passed; continue Phase 2/3 drift audit, Phase 6 placeholder audit, or B12 live smoke. - 2026-06-06: P3.27 Notion integration checkpoint prepared as `feat(integrations): align notion parity`; audited Chatwoot Notion account destroy controller, route `379`, Notion callback hook shape, and reused dashboard integrations delete flow. GoChat now exposes no-trailing and trailing Notion destroy, finds callback-created hooks by `app_id: notion` with legacy hook-type fallback, tracks the account route in route parity, and deletes with empty `200 OK`. Focused Notion handler/service tests, route dump/parity regeneration (`941` routes; `391 exact`, `13 parameter-compatible`, `0 missing out of 404`), full `go test ./...`, and `git diff --check` passed; continue Phase 2/3 drift audit, Phase 6 placeholder audit, or B12 live smoke. +- 2026-06-06: P3.28 Notion authorization checkpoint prepared as `feat(integrations): align notion authorization`; audited Chatwoot Notion account authorization controller/specs, route `335`, callback state handling, and reused dashboard `notion_auth.js`. GoChat now exposes administrator-gated `POST /api/v1/accounts/:account_id/notion/authorization`, returns raw `{ success: true, url }`, builds Notion OAuth URLs with `response_type=code`, `owner=user`, frontend `/notion/callback`, configured client ID, and signed account state, and tracks the account authorization route in route parity. Focused Notion authorization handler/service tests, route dump/parity regeneration (`942` routes; `392 exact`, `13 parameter-compatible`, `0 missing out of 405`), full `go test ./...`, and `git diff --check` passed; continue Phase 2/3 drift audit, Phase 6 placeholder audit, or B12 live smoke. diff --git a/docs/parity/gochat_routes.txt b/docs/parity/gochat_routes.txt index a34db3e4..6a3849dc 100644 --- a/docs/parity/gochat_routes.txt +++ b/docs/parity/gochat_routes.txt @@ -726,6 +726,7 @@ POST /api/v1/accounts/:account_id/notifications/:notification_id/snooze POST /api/v1/accounts/:account_id/notifications/:notification_id/unread POST /api/v1/accounts/:account_id/notifications/destroy_all POST /api/v1/accounts/:account_id/notifications/read_all +POST /api/v1/accounts/:account_id/notion/authorization POST /api/v1/accounts/:account_id/platform_apps/ POST /api/v1/accounts/:account_id/platform_apps/:platform_app_id/permissibles POST /api/v1/accounts/:account_id/platform_apps/:platform_app_id/regenerate_access_token @@ -939,4 +940,4 @@ PUT /public/api/v1/csat_survey/:id PUT /public/api/v1/inboxes/:inbox_id/contacts/:contact_id PUT /public/api/v1/inboxes/:inbox_id/contacts/:contact_id/conversations/:conversation_id/messages/:message_id PUT /widget/direct_uploads/:upload_uuid -TOTAL: 941 +TOTAL: 942 diff --git a/docs/parity/route_parity.md b/docs/parity/route_parity.md index 3bb8709c..0f8d6be3 100644 --- a/docs/parity/route_parity.md +++ b/docs/parity/route_parity.md @@ -7,7 +7,7 @@ Generated from: This report covers tracked frontend-critical Chatwoot routes from `reference/chatwoot/config/routes.rb`, including API v1 account routes, Captain/Copilot, assignment policies, widget/public APIs, and API v2 reports. Ruby is not installed in the workspace, so Chatwoot routes are sourced from static route declarations instead of `bin/rails routes`. -Summary: 391 exact, 0 method-compatible, 13 parameter-compatible, 0 missing out of 404 tracked critical routes. +Summary: 392 exact, 0 method-compatible, 13 parameter-compatible, 0 missing out of 405 tracked critical routes. ## Missing Critical Routes @@ -361,6 +361,7 @@ These routes exist with equivalent method and path shape but different parameter | POST | `/api/v1/accounts/:account_id/notifications/:notification_id/unread` | `/api/v1/accounts/:account_id/notifications/:notification_id/unread` | `api/v1/accounts/notifications#unread` | `routes.rb:291` | exact | | POST | `/api/v1/accounts/:account_id/notifications/destroy_all` | `/api/v1/accounts/:account_id/notifications/destroy_all` | `api/v1/accounts/notifications#destroy_all` | `routes.rb:287` | exact | | POST | `/api/v1/accounts/:account_id/notifications/read_all` | `/api/v1/accounts/:account_id/notifications/read_all` | `api/v1/accounts/notifications#read_all` | `routes.rb:285` | exact | +| POST | `/api/v1/accounts/:account_id/notion/authorization` | `/api/v1/accounts/:account_id/notion/authorization` | `api/v1/accounts/notion/authorizations#create` | `routes.rb:335` | exact | | POST | `/api/v1/accounts/:account_id/portals` | `/api/v1/accounts/:account_id/portals` | `api/v1/accounts/portals#create` | `routes.rb:385` | exact | | POST | `/api/v1/accounts/:account_id/portals/:portal_id/articles` | `/api/v1/accounts/:account_id/portals/:portal_id/articles` | `api/v1/accounts/articles#create` | `routes.rb:403` | exact | | POST | `/api/v1/accounts/:account_id/portals/:portal_id/articles/bulk_actions/translate` | `/api/v1/accounts/:account_id/portals/:portal_id/articles/bulk_actions/translate` | `api/v1/accounts/articles/bulk_actions#translate` | `routes.rb:397` | exact | diff --git a/internal/handler/api/v1/notion_integration_handler.go b/internal/handler/api/v1/notion_integration_handler.go index 8f43e316..9336ad8f 100644 --- a/internal/handler/api/v1/notion_integration_handler.go +++ b/internal/handler/api/v1/notion_integration_handler.go @@ -20,6 +20,23 @@ func NewNotionIntegrationHandler(svc *service.NotionIntegrationService) *NotionI return &NotionIntegrationHandler{svc: svc} } +// Authorization creates a Notion OAuth authorization URL. +// POST /api/v1/accounts/:account_id/notion/authorization +func (h *NotionIntegrationHandler) Authorization(c *gin.Context) { + accountID, err := parseUintParam(c, "account_id") + if err != nil { + response.AbortWithStatusError(c, http.StatusBadRequest, response.ErrBadRequest, "invalid account_id") + return + } + + result, svcErr := h.svc.BuildAuthorizationURL(accountID) + if svcErr != nil { + c.JSON(http.StatusUnprocessableEntity, gin.H{"success": false}) + return + } + c.JSON(http.StatusOK, result) +} + // Delete removes a Notion integration for an account. // DELETE /api/v1/accounts/:account_id/integrations/notion func (h *NotionIntegrationHandler) Delete(c *gin.Context) { diff --git a/internal/handler/api/v1/notion_integration_handler_test.go b/internal/handler/api/v1/notion_integration_handler_test.go index e7025ed2..bd161dfd 100644 --- a/internal/handler/api/v1/notion_integration_handler_test.go +++ b/internal/handler/api/v1/notion_integration_handler_test.go @@ -35,7 +35,9 @@ func setupNotionIntegrationRouter(t *testing.T) (*gin.Engine, *gorm.DB) { handler := NewNotionIntegrationHandler(service.NewNotionIntegrationService(repository.NewIntegrationHookRepo(db))) - integrations := r.Group("/api/v1/accounts/:account_id/integrations") + account := r.Group("/api/v1/accounts/:account_id") + account.POST("/notion/authorization", handler.Authorization) + integrations := account.Group("/integrations") RegisterNotionIntegrationRoutes(integrations, handler) return r, db @@ -60,6 +62,41 @@ func TestNotionIntegration_Delete_BadAccountID(t *testing.T) { assert.Contains(t, errBody["message"], "invalid account_id") } +func TestNotionIntegration_Authorization_BadAccountID(t *testing.T) { + r, _ := setupNotionIntegrationRouter(t) + + w := httptest.NewRecorder() + req, _ := http.NewRequest("POST", "/api/v1/accounts/abc/notion/authorization", nil) + r.ServeHTTP(w, req) + + assert.Equal(t, http.StatusBadRequest, w.Code) + + var resp map[string]interface{} + json.Unmarshal(w.Body.Bytes(), &resp) + errBody := resp["error"].(map[string]interface{}) + assert.Contains(t, errBody["message"], "invalid account_id") +} + +func TestNotionIntegration_Authorization_ReturnsChatwootPayload(t *testing.T) { + t.Setenv("NOTION_CLIENT_ID", "notion-client") + t.Setenv("NOTION_CLIENT_SECRET", "notion-secret") + t.Setenv("FRONTEND_URL", "https://app.example.test/") + r, db := setupNotionIntegrationRouter(t) + account := &model.Account{Name: "Test Account"} + require.NoError(t, db.Create(account).Error) + + w := httptest.NewRecorder() + req, _ := http.NewRequest("POST", fmt.Sprintf("/api/v1/accounts/%d/notion/authorization", account.ID), nil) + r.ServeHTTP(w, req) + + assert.Equal(t, http.StatusOK, w.Code) + var resp map[string]interface{} + require.NoError(t, json.Unmarshal(w.Body.Bytes(), &resp)) + assert.Equal(t, true, resp["success"]) + assert.Contains(t, resp["url"], "https://api.notion.com/v1/oauth/authorize") + assert.Contains(t, resp["url"], "redirect_uri=https%3A%2F%2Fapp.example.test%2Fnotion%2Fcallback") +} + func TestNotionIntegration_Delete_NoTrailingSlashReturnsEmptyOK(t *testing.T) { r, db := setupNotionIntegrationRouter(t) account := &model.Account{Name: "Test Account"} diff --git a/internal/router/router.go b/internal/router/router.go index 589123fc..dfbee9e1 100644 --- a/internal/router/router.go +++ b/internal/router/router.go @@ -1579,6 +1579,9 @@ func registerV1Routes(g *gin.RouterGroup, h *Handlers) { macros.POST("/:macro_id/toggle_active", h.Macro.ToggleActive) } + // Notion OAuth authorization (ref: Chatwoot namespace :notion resource :authorization) + accountScoped.POST("/notion/authorization", middleware.RoleCheck("administrator"), h.NotionIntegration.Authorization) + // G16: Third-party Integrations — IntegrationHook CRUD + Slack/Shopify/Linear/Notion // Reference: Chatwoot namespace :integrations under :account integrations := accountScoped.Group("/integrations") diff --git a/internal/service/linear_notion_integration_service.go b/internal/service/linear_notion_integration_service.go index 6ba77d5a..91cf4a23 100644 --- a/internal/service/linear_notion_integration_service.go +++ b/internal/service/linear_notion_integration_service.go @@ -16,6 +16,7 @@ import ( "github.com/gochat/gochat/internal/model" "github.com/gochat/gochat/internal/repository" applogger "github.com/gochat/gochat/pkg/logger" + "github.com/golang-jwt/jwt/v5" ) // LinearProviderError mirrors Chatwoot's `{ error: ... }`, 422 provider failures. @@ -594,11 +595,48 @@ type NotionIntegrationService struct { hookRepo *repository.IntegrationHookRepo } +// NotionAuthorizationResponse mirrors Chatwoot's Notion authorization payload. +type NotionAuthorizationResponse struct { + Success bool `json:"success"` + URL string `json:"url,omitempty"` +} + // NewNotionIntegrationService creates a new NotionIntegrationService. func NewNotionIntegrationService(hookRepo *repository.IntegrationHookRepo) *NotionIntegrationService { return &NotionIntegrationService{hookRepo: hookRepo} } +// BuildAuthorizationURL returns the Notion OAuth authorize URL for an account. +func (s *NotionIntegrationService) BuildAuthorizationURL(accountID uint) (*NotionAuthorizationResponse, error) { + clientID := strings.TrimSpace(os.Getenv("NOTION_CLIENT_ID")) + clientSecret := strings.TrimSpace(os.Getenv("NOTION_CLIENT_SECRET")) + if clientID == "" || clientSecret == "" { + return nil, fmt.Errorf("Notion OAuth is not configured") + } + + token := jwt.NewWithClaims(jwt.SigningMethodHS256, jwt.MapClaims{ + "sub": accountID, + "iat": time.Now().Unix(), + }) + state, err := token.SignedString([]byte(clientSecret)) + if err != nil { + return nil, fmt.Errorf("failed to generate Notion state: %w", err) + } + + frontendURL := strings.TrimRight(os.Getenv("FRONTEND_URL"), "/") + if frontendURL == "" { + frontendURL = "http://localhost:3000" + } + params := url.Values{} + params.Set("client_id", clientID) + params.Set("owner", "user") + params.Set("redirect_uri", frontendURL+"/notion/callback") + params.Set("response_type", "code") + params.Set("state", state) + + return &NotionAuthorizationResponse{Success: true, URL: "https://api.notion.com/v1/oauth/authorize?" + params.Encode()}, nil +} + // Delete removes a Notion integration hook for an account. func (s *NotionIntegrationService) Delete(ctx context.Context, accountID uint) error { hooks, err := s.findNotionHooks(ctx, accountID) diff --git a/internal/service/linear_notion_integration_service_test.go b/internal/service/linear_notion_integration_service_test.go index ac064875..6e9d45a1 100644 --- a/internal/service/linear_notion_integration_service_test.go +++ b/internal/service/linear_notion_integration_service_test.go @@ -6,9 +6,11 @@ import ( "encoding/json" "io" "net/http" + "net/url" "strings" "testing" + "github.com/golang-jwt/jwt/v5" "github.com/stretchr/testify/assert" "github.com/stretchr/testify/require" "gorm.io/driver/sqlite" @@ -370,6 +372,48 @@ func TestLinearIntegrationService_GetLinkedIssues_UsesConversationDisplayID(t *t // NotionIntegrationService tests // ======================================== +func TestNotionIntegrationService_BuildAuthorizationURL(t *testing.T) { + t.Setenv("NOTION_CLIENT_ID", "notion-client") + t.Setenv("NOTION_CLIENT_SECRET", "notion-secret") + t.Setenv("FRONTEND_URL", "https://app.example.test/") + svc, _ := setupNotionService(t) + + resp, err := svc.BuildAuthorizationURL(42) + require.NoError(t, err) + require.NotNil(t, resp) + assert.True(t, resp.Success) + + parsed, err := url.Parse(resp.URL) + require.NoError(t, err) + assert.Equal(t, "https", parsed.Scheme) + assert.Equal(t, "api.notion.com", parsed.Host) + assert.Equal(t, "/v1/oauth/authorize", parsed.Path) + query := parsed.Query() + assert.Equal(t, "notion-client", query.Get("client_id")) + assert.Equal(t, "code", query.Get("response_type")) + assert.Equal(t, "user", query.Get("owner")) + assert.Equal(t, "https://app.example.test/notion/callback", query.Get("redirect_uri")) + + claims := jwt.MapClaims{} + token, err := jwt.ParseWithClaims(query.Get("state"), claims, func(token *jwt.Token) (any, error) { + return []byte("notion-secret"), nil + }) + require.NoError(t, err) + require.True(t, token.Valid) + assert.Equal(t, float64(42), claims["sub"]) +} + +func TestNotionIntegrationService_BuildAuthorizationURL_NotConfigured(t *testing.T) { + t.Setenv("NOTION_CLIENT_ID", "") + t.Setenv("NOTION_CLIENT_SECRET", "") + svc, _ := setupNotionService(t) + + resp, err := svc.BuildAuthorizationURL(42) + assert.Nil(t, resp) + assert.Error(t, err) + assert.Contains(t, err.Error(), "Notion OAuth is not configured") +} + func TestNotionIntegrationService_Delete_Success(t *testing.T) { svc, db := setupNotionService(t) accountID := seedLinearNotionAccount(db, t)