feat(channels): align twitter authorization

This commit is contained in:
2026-06-06 18:29:35 +08:00
parent 0f2d64c8f6
commit 5b143b6da7
7 changed files with 294 additions and 8 deletions
+1
View File
@@ -233,6 +233,7 @@ var criticalRoutes = []route{
{Method: "GET", Path: "/api/v1/accounts/:account_id/integrations/slack/list_all_channels", Controller: "api/v1/accounts/integrations/slack#list_all_channels", Source: "routes.rb:352"},
{Method: "POST", Path: "/api/v1/accounts/:account_id/integrations/dyte/create_a_meeting", Controller: "api/v1/accounts/integrations/dyte#create_a_meeting", Source: "routes.rb:357"},
{Method: "POST", Path: "/api/v1/accounts/:account_id/integrations/dyte/add_participant_to_meeting", Controller: "api/v1/accounts/integrations/dyte#add_participant_to_meeting", Source: "routes.rb:358"},
{Method: "POST", Path: "/api/v1/accounts/:account_id/twitter/authorization", Controller: "api/v1/accounts/twitter/authorizations#create", Source: "routes.rb:315"},
{Method: "POST", Path: "/api/v1/accounts/:account_id/notion/authorization", Controller: "api/v1/accounts/notion/authorizations#create", Source: "routes.rb:335"},
{Method: "DELETE", Path: "/api/v1/accounts/:account_id/integrations/shopify", Controller: "api/v1/accounts/integrations/shopify#destroy", Source: "routes.rb:361"},
{Method: "POST", Path: "/api/v1/accounts/:account_id/integrations/shopify/auth", Controller: "api/v1/accounts/integrations/shopify#auth", Source: "routes.rb:363"},
+9 -6
View File
@@ -49,16 +49,16 @@ Hermes task landing checklist:
## Current Baseline
- Current tracking checkpoint: 2026-06-06 Notion authorization parity checkpoint, prepared as `feat(integrations): align notion authorization`.
- Latest implementation checkpoint: this checkpoint, prepared as `feat(integrations): align notion authorization`.
- Current tracking checkpoint: 2026-06-06 Twitter authorization parity checkpoint, prepared as `feat(channels): align twitter authorization`.
- Latest implementation checkpoint: this checkpoint, prepared as `feat(channels): align twitter authorization`.
- Latest documentation/tooling checkpoint: this tracker update for P3.24 plus the landed parity tracker history; this document is the active follow-up plan and supersedes `.hermes/plans/*`.
- Plan landing status: complete for the current known Hermes plans and user-confirmed scope. Future work should update this file directly instead of opening a parallel tracker.
- Worktree status at this implementation checkpoint: Notion account authorization from `reference/chatwoot/config/routes.rb:334-335`, `Api::V1::Accounts::Notion::AuthorizationsController`, Notion authorization request specs, Notion callback specs, and reused dashboard `notion_auth.js` are implemented. GoChat now exposes admin-gated `POST /api/v1/accounts/:account_id/notion/authorization`, returns Chatwoot `{ success: true, url }` payloads, signs callback state for the existing Notion callback, and keeps Notion destroy routes/hook lookup/delete responses aligned. Live API/browser/enterprise smoke still needs the full PostgreSQL/Redis/Meilisearch/GoChat/Vite/Chrome stack.
- Worktree status at this implementation checkpoint: Twitter account authorization from `reference/chatwoot/config/routes.rb:315`, `Api::V1::Accounts::Twitter::AuthorizationsController`, Twitter authorization request specs, Twitter callback behavior, and reused dashboard `twitterClient.js` are implemented. GoChat now exposes administrator-gated `POST /api/v1/accounts/:account_id/twitter/authorization`, requests a Twitter OAuth1 request token through a fakeable client, returns Chatwoot `{ success: true, url }` payloads, signs callback state for the existing Twitter callback, and keeps previously aligned Notion authorization/destroy behavior intact. Live API/browser/enterprise smoke still needs the full PostgreSQL/Redis/Meilisearch/GoChat/Vite/Chrome stack.
- Next executable implementation checkpoint: continue Phase 2/3 drift audit, Phase 6 placeholder audit, or B12 live smoke from fresh reference/smoke evidence.
- `go test ./...` passes when run outside the restricted socket sandbox; focused Shopify handler/service tests pass in the sandbox.
- Route dump succeeds with `942` registered routes after Notion authorization tracking.
- Route dump succeeds with `943` registered routes after Twitter authorization tracking.
- Route parity artifacts now exist under `docs/parity/` and are generated by `cmd/route_parity`.
- Tracked frontend-critical route audit covers 405 Chatwoot routes: 392 exact, 0 method-compatible, 13 parameter-compatible, 0 missing. The 13 parameter-compatible routes are Gin-internal parameter-name differences for nested AgentCapacityPolicy users/inbox limits, dashboard app member `:id` names, plus the public article `.md`/`.png` suffixes served through the same external article route dispatcher.
- Tracked frontend-critical route audit covers 406 Chatwoot routes: 393 exact, 0 method-compatible, 13 parameter-compatible, 0 missing. The 13 parameter-compatible routes are Gin-internal parameter-name differences for nested AgentCapacityPolicy users/inbox limits, dashboard app member `:id` names, plus the public article `.md`/`.png` suffixes served through the same external article route dispatcher.
- `/api/v1/widget` stubs are burned down and public inbox/contact/conversation/message core flows are backed by real handlers.
- Handler test stability fixes are committed into the baseline before feature parity work continues.
- `.codegraph/` is generated indexing output and is not part of tracked product code.
@@ -140,6 +140,7 @@ This table is the shortest authoritative handoff view. If an older lower section
| Priority | Workstream | Current state | Next checkpoint | Commit close rule |
| --- | --- | --- | --- | --- |
| 0 | P3.29 Twitter authorization parity | Implemented for reused dashboard Twitter connect flow: `POST /api/v1/accounts/:account_id/twitter/authorization` is registered and tracked from `routes.rb:315`, the route is administrator-gated like Chatwoot's controller, the response returns raw `{ success: true, url }`, the request-token call uses Twitter OAuth1 signing with configured consumer key/secret and frontend `/twitter/callback?state=...`, and the returned URL targets `/oauth/authorize?oauth_token=...`. | Keep in Review; reopen only if live Twitter OAuth smoke exposes request-token signing/header drift, Redis request-token mapping requirements beyond signed callback state, provider base URL drift, or frontend payload drift beyond the inspected authorization controller/spec/frontend contract. | Focused Twitter authorization handler/router/route tests, route dump/parity regeneration (`943` routes; `393 exact`, `13 parameter-compatible`, `0 missing out of 406`), full `go test ./...`, and `git diff --check` must pass before commit. |
| 0 | P3.28 Notion authorization parity | Implemented for reused dashboard Notion connect flow: `POST /api/v1/accounts/:account_id/notion/authorization` is registered and tracked from `routes.rb:335`, the route is administrator-gated like Chatwoot's `OauthAuthorizationController`, the response returns raw `{ success: true, url }`, the URL targets `https://api.notion.com/v1/oauth/authorize` with `response_type=code`, `owner=user`, frontend `/notion/callback`, configured `client_id`, and signed account state for the existing callback. | Keep in Review; reopen only if live Notion OAuth smoke exposes GlobalID state compatibility, config-source drift, feature-gate behavior, or frontend payload drift beyond the inspected authorization controller/spec/frontend contract. | Focused Notion authorization handler/service tests, route dump/parity regeneration (`942` routes; `392 exact`, `13 parameter-compatible`, `0 missing out of 405`), full `go test ./...`, and `git diff --check` must pass before commit. |
| 0 | P3.27 Notion integration destroy parity | Implemented for reused dashboard Notion integration disconnect flow: no-trailing and trailing destroy routes are registered, the account route is tracked from `routes.rb:379`, OAuth callback-created hooks are found by `app_id: notion` with legacy hook-type fallback, and delete returns empty `200 OK` instead of a local success/message envelope. | Keep in Review; reopen only if live Notion OAuth/disconnect smoke exposes feature-gate drift, callback-created hook shape drift, or frontend delete error handling beyond the inspected controller/spec/frontend contract. | Focused Notion handler/service tests, route dump/parity regeneration (`941` routes; `391 exact`, `13 parameter-compatible`, `0 missing out of 404`), full `go test ./...`, and `git diff --check` must pass before commit. |
| 0 | P3.26 Shopify integration parity | Implemented for reused dashboard Shopify integration and customer-order panel: no-trailing and trailing destroy routes are registered, auth returns raw `{ redirect_url }`, missing shop domains return Chatwoot's `422 { error: "Shop domain is required" }`, orders returns raw `{ orders: [...] }`, account-scoped contacts are required, contacts without email/phone return `422 { error: "Contact information missing" }`, Shopify customers/search and orders REST calls are made through fakeable clients, order payloads include `admin_url`, callback-created hooks are found by `app_id: shopify`, and delete returns empty `200 OK`. | Keep in Review; reopen only if live Shopify OAuth/order smoke exposes token/session setup drift, REST API version drift, Shopify error-body wording, or frontend order payload drift beyond the inspected controller/helper/spec/frontend contract. | Focused Shopify handler/service tests, route dump/parity regeneration (`940` routes; `390 exact`, `13 parameter-compatible`, `0 missing out of 403`), sandbox package tests, escalated full `go test ./...`, and `git diff --check` passed. |
@@ -147,7 +148,7 @@ This table is the shortest authoritative handoff view. If an older lower section
| 0 | P3.24 Slack integration parity | Implemented for reused dashboard Slack settings flow: no-trailing and trailing singleton routes are registered for create/update/delete, `PUT` and `PATCH` update both work, create accepts frontend `code` and exchanges it for a Slack access token, hooks are persisted with `app_id: slack` and disabled status, update accepts frontend `reference_id`, fetches real private/public Slack channels with pagination, joins public channels, persists `reference_id/settings.channel_name/status`, create/update return raw Chatwoot app payloads with hooks, list-all returns raw channel arrays, invalid channels return Chatwoot's `422 { error }`, and delete returns empty `200 OK`. | Keep in Review; reopen only if live Slack OAuth/channel smoke exposes OAuth redirect, provider error, app serializer, or Slack channel pagination drift beyond the inspected controller/builder/spec/frontend contract. | Focused Slack handler/service tests, route dump/parity regeneration, sandbox focused `go test`, escalated full `go test ./...`, and `git diff --check` passed. |
| 0 | P3.23 nested contact inbox creation API | Implemented for Chatwoot nested contact inbox creation: raw JSON/form/query params are accepted, contact and inbox are account-scoped, missing source IDs are generated through Chatwoot channel rules, duplicate contact+inbox+source rows are returned idempotently, `hmac_verified` is persisted on creation, and the response is raw `{ source_id, inbox }` rather than the local model/envelope. | Keep in Review; reopen only if live CRM/new-conversation smoke exposes inbox access-policy, unsupported channel, or serializer drift beyond the inspected controller/builder/Jbuilder contract. | Focused nested ContactInbox handler/service/repository tests, route parity check, full `go test ./...`, and `git diff --check` passed. |
| 1 | P3.2a invitation/confirmation mail parity | Implemented for current non-SSO reference behavior: profile resend is no longer a TODO-only log, new invited agents and unconfirmed invited profile resends generate reset-password invitation links, normal unconfirmed profile resends generate confirmation links, `users.unconfirmed_email` is modeled for email-update routing, and fakeable/environment SMTP mailers keep default tests offline. | Keep in Review; reopen only if reused frontend smoke or fresh reference evidence exposes additional Devise confirmation states outside excluded SSO/SAML/LDAP/OIDC variants. | Focused profile and agent invitation tests, combined handler/service/repository/router/migrate/app tests, full `go test ./...`, and `git diff --check` passed. |
| 2 | Phase 2/3 drift | Tracked route parity is 0 missing for the current 405-route critical set; dashboard `/app` shell routes from `routes.rb:19-20`, `.well-known` app association and custom-domain challenge routes from `routes.rb:657-660`, Twilio callback routes from `routes.rb:639-640`, enterprise Twilio voice routes from `routes.rb:643-646`, root Linear/Shopify/Notion OAuth callback routes from `routes.rb:630/634/654`, root Twitter/Google/Microsoft/Instagram/TikTok callback routes from `routes.rb:626/649-652`, assignment policy routes from `routes.rb:306-313`, help-center portal/category/article routes from `routes.rb:385-404`, public help-center portal/sitemap/article/category/search/article-detail routes from `routes.rb:590-601`, enterprise contact outbound voice call from `routes.rb:216`, account agent-bot routes from `routes.rb:94-97`, account webhook routes from `routes.rb:342`, account integration app/hook routes from `routes.rb:345-348`, account Slack routes from `routes.rb:350-352`, account Dyte routes from `routes.rb:357-358`, account Shopify routes from `routes.rb:361-364`, account Linear routes from `routes.rb:365-373`, account Notion authorization/destroy routes from `routes.rb:335/379`, dashboard app routes from `routes.rb:130`, canned response routes from `routes.rb:114`, notification subscription routes from `routes.rb:440`, team/team-member routes from `routes.rb:296-300`, conversation participant routes from `routes.rb:150`, conversation direct upload route from `routes.rb:151`, conversation draft message routes from `routes.rb:152`, conversation inbox assistant route from `routes.rb:165`, conversation reporting events route from `routes.rb:166`, and account reporting events route from `routes.rb:234` are now explicitly tracked. Notification list/action serializers, user notification-settings raw payloads, campaigns raw payload/display-id routes, Devise password reset/confirmation payloads, CRM shared attachment payloads plus fixed 100-row attachment pagination, account/settings payloads, assignable-agent payloads, agent index full-list behavior, agent create/update/delete defaults/errors/scope, account agent-bot route/payload/mutation behavior, account webhook payload/mutation behavior, integration app/hook payload behavior, account Slack OAuth/channel payload behavior, account Dyte create/join payload behavior, account Shopify customer-order payload behavior, account Linear GraphQL issue payload behavior, account Notion authorization/destroy behavior, dashboard app raw payload/serializer behavior, canned response raw payload/search/delete behavior, notification subscription payload behavior, team update/frontend route behavior, conversation participant route/payload/final-set update behavior, conversation direct upload ActiveStorage behavior, conversation draft message Redis-key-equivalent behavior, conversation inbox assistant Copilot payload behavior, conversation reporting-event raw array behavior, account reporting-events payload/filter/pagination behavior, label CRUD payloads, custom filters, custom attribute definitions, contact outbound voice calls, assignment policy CRUD and inbox binding payloads, Twilio inbound/status callbacks, enterprise Twilio voice callbacks, Linear/Shopify/Notion root integration callbacks, Shopify OAuth auth redirects, root channel OAuth callbacks, help-center portal/category/article payloads, dashboard app shell route behavior, app association JSON payloads, Cloudflare custom hostname verification, public widget popular-article lists, public help-center category list/show payloads, public portal show/default-locale payloads, public portal search payloads, public article show/markdown/tracking routes, and public sitemap XML now match the inspected Chatwoot contract. | Continue the next evidence-backed route/controller/serializer drift after Notion authorization parity or from B12 findings. | Regenerate parity artifacts when routes change and add endpoint-family fixture tests. |
| 2 | Phase 2/3 drift | Tracked route parity is 0 missing for the current 406-route critical set; dashboard `/app` shell routes from `routes.rb:19-20`, `.well-known` app association and custom-domain challenge routes from `routes.rb:657-660`, Twilio callback routes from `routes.rb:639-640`, enterprise Twilio voice routes from `routes.rb:643-646`, root Linear/Shopify/Notion OAuth callback routes from `routes.rb:630/634/654`, root Twitter/Google/Microsoft/Instagram/TikTok callback routes from `routes.rb:626/649-652`, assignment policy routes from `routes.rb:306-313`, help-center portal/category/article routes from `routes.rb:385-404`, public help-center portal/sitemap/article/category/search/article-detail routes from `routes.rb:590-601`, enterprise contact outbound voice call from `routes.rb:216`, account agent-bot routes from `routes.rb:94-97`, account webhook routes from `routes.rb:342`, account integration app/hook routes from `routes.rb:345-348`, account Slack routes from `routes.rb:350-352`, account Dyte routes from `routes.rb:357-358`, account Shopify routes from `routes.rb:361-364`, account Linear routes from `routes.rb:365-373`, account Notion authorization/destroy routes from `routes.rb:335/379`, account Twitter authorization route from `routes.rb:315`, dashboard app routes from `routes.rb:130`, canned response routes from `routes.rb:114`, notification subscription routes from `routes.rb:440`, team/team-member routes from `routes.rb:296-300`, conversation participant routes from `routes.rb:150`, conversation direct upload route from `routes.rb:151`, conversation draft message routes from `routes.rb:152`, conversation inbox assistant route from `routes.rb:165`, conversation reporting events route from `routes.rb:166`, and account reporting events route from `routes.rb:234` are now explicitly tracked. Notification list/action serializers, user notification-settings raw payloads, campaigns raw payload/display-id routes, Devise password reset/confirmation payloads, CRM shared attachment payloads plus fixed 100-row attachment pagination, account/settings payloads, assignable-agent payloads, agent index full-list behavior, agent create/update/delete defaults/errors/scope, account agent-bot route/payload/mutation behavior, account webhook payload/mutation behavior, integration app/hook payload behavior, account Slack OAuth/channel payload behavior, account Dyte create/join payload behavior, account Shopify customer-order payload behavior, account Linear GraphQL issue payload behavior, account Notion authorization/destroy behavior, account Twitter authorization behavior, dashboard app raw payload/serializer behavior, canned response raw payload/search/delete behavior, notification subscription payload behavior, team update/frontend route behavior, conversation participant route/payload/final-set update behavior, conversation direct upload ActiveStorage behavior, conversation draft message Redis-key-equivalent behavior, conversation inbox assistant Copilot payload behavior, conversation reporting-event raw array behavior, account reporting-events payload/filter/pagination behavior, label CRUD payloads, custom filters, custom attribute definitions, contact outbound voice calls, assignment policy CRUD and inbox binding payloads, Twilio inbound/status callbacks, enterprise Twilio voice callbacks, Linear/Shopify/Notion root integration callbacks, Shopify OAuth auth redirects, root channel OAuth callbacks, help-center portal/category/article payloads, dashboard app shell route behavior, app association JSON payloads, Cloudflare custom hostname verification, public widget popular-article lists, public help-center category list/show payloads, public portal show/default-locale payloads, public portal search payloads, public article show/markdown/tracking routes, and public sitemap XML now match the inspected Chatwoot contract. | Continue the next evidence-backed route/controller/serializer drift after Twitter authorization parity or from B12 findings. | Regenerate parity artifacts when routes change and add endpoint-family fixture tests. |
| 3 | Phase 6 placeholder audit | Widget/public/webhook critical placeholders are burned down; inbox WhatsApp health/register-webhook and sync-template drift are closed; refreshed `docs/parity/placeholder_audit.md` shows only webhook nil-handler fallbacks still call `chatwootParityStub`; dashboard conversation transcript/custom-attribute response drift and message retry status drift are closed. | Keep in Review; reopen only if fresh `rg`, route smoke, or B12 finds a frontend-reachable placeholder/stub in account/contact/conversation/message/inbox/widget/public paths. | `rg` placeholder audit and `scripts/parity_frontend_smoke.sh --check` are recorded; no reused-frontend blocker is ownerless. |
| 4 | P3.9 account agent-bot API | Implemented for the reused dashboard AgentBots settings route with no-trailing-slash routes, PATCH update, raw Jbuilder-style payloads, account mutation scope, system-bot show/list visibility, empty `200 OK` delete, and full reset/avatar action payloads. | Keep in Review; reopen only if live settings smoke exposes avatar upload storage or administrator-secret gating drift. | Focused AgentBot handler tests, service/router focused tests, route dump/parity regeneration, full `go test ./...`, and `git diff --check` passed. |
| 5 | P3.10 account webhooks API | Implemented for the reused dashboard Webhooks settings route with PATCH update, Chatwoot `{ payload }` list/mutation serializers, nested `{ webhook: ... }` bodies, generated secret, account-scoped mutations, URL/subscription validation, optional inbox serialization, and empty `200 OK` delete. | Keep in Review; reopen only if live settings smoke exposes audit writer or delivery-signature drift beyond the existing delivery service boundary. | Focused webhook handler/service/router tests, migration test, route dump/parity regeneration, full `go test ./...`, and `git diff --check` passed. |
@@ -243,6 +244,7 @@ This ledger records the committed parity checkpoints that future slices should b
| Commit | Scope | Verification summary | Follow-up state |
| --- | --- | --- | --- |
| `feat(channels): align twitter authorization` | Advances P3.29 Twitter authorization parity by matching Chatwoot `Api::V1::Accounts::Twitter::AuthorizationsController#create`, route `315`, request specs, callback expectations, and reused dashboard `twitterClient.js`. GoChat now exposes administrator-gated `POST /api/v1/accounts/:account_id/twitter/authorization`, requests a Twitter OAuth1 token through a fakeable signed request-token client, returns raw `{ success: true, url }`, and signs callback state for the existing Twitter callback path. | `go test ./internal/handler/api/v1 ./internal/router ./cmd/route_parity -run 'TwitterAuthorization\|Router\|RouteParity' -count=1`; `go run ./cmd/dump_routes > docs/parity/gochat_routes.txt`; `go run ./cmd/route_parity`; full `go test ./...`; `git diff --check`. Route dump is `TOTAL: 943`; tracked route parity is `393 exact, 0 method-compatible, 13 parameter-compatible, 0 missing out of 406`. | P3.29 moves to Review for current Twitter authorization evidence; continue Phase 2/3 drift audit, Phase 6 placeholder audit, B12 live smoke, or fresh reference/smoke drift. |
| `feat(integrations): align notion authorization` | Advances P3.28 Notion authorization parity by matching Chatwoot `Api::V1::Accounts::Notion::AuthorizationsController#create`, route `335`, request specs, and reused dashboard `notion_auth.js`. GoChat now exposes administrator-gated `POST /api/v1/accounts/:account_id/notion/authorization`, returns raw `{ success: true, url }`, builds the Notion OAuth authorize URL with `response_type=code`, `owner=user`, frontend `/notion/callback`, configured client ID, and signed account state compatible with the existing callback. | `go test ./internal/service ./internal/handler/api/v1 ./internal/router ./cmd/route_parity -run 'NotionIntegration\|Router\|RouteParity' -count=1`; `go run ./cmd/dump_routes > docs/parity/gochat_routes.txt`; `go run ./cmd/route_parity`; full `go test ./...`; `git diff --check`. Route dump is `TOTAL: 942`; tracked route parity is `392 exact, 0 method-compatible, 13 parameter-compatible, 0 missing out of 405`. | P3.28 moves to Review for current Notion authorization evidence; continue Phase 2/3 drift audit, Phase 6 placeholder audit, B12 live smoke, or fresh reference/smoke drift. |
| `feat(integrations): align notion parity` | Advances P3.27 Notion integration destroy parity by matching Chatwoot `Api::V1::Accounts::Integrations::NotionController#destroy`, route `379`, Notion callback hook shape, and reused dashboard integrations delete flow. GoChat now exposes no-trailing and trailing `DELETE /api/v1/accounts/:account_id/integrations/notion`, finds OAuth-created hooks by `app_id: notion` with legacy hook-type fallback, and returns empty `200 OK` instead of the local `{ message }` envelope. | `go test ./internal/service ./internal/handler/api/v1 ./cmd/route_parity -run 'NotionIntegration\|RouteParity' -count=1`; `go test ./internal/service ./internal/handler/api/v1 ./internal/router ./cmd/route_parity -run 'NotionIntegration\|Router\|RouteParity' -count=1`; `go run ./cmd/dump_routes > docs/parity/gochat_routes.txt`; `go run ./cmd/route_parity`; full `go test ./...`; `git diff --check`. Route dump is `TOTAL: 941`; tracked route parity is `391 exact, 0 method-compatible, 13 parameter-compatible, 0 missing out of 404`. | P3.27 moves to Review for current Notion destroy evidence; continue Phase 2/3 drift audit, Phase 6 placeholder audit, B12 live smoke, or fresh reference/smoke drift. |
| `feat(contacts): align contact inbox creation` | Advances P3.23 nested contact inbox creation parity by matching Chatwoot `Api::V1::Accounts::Contacts::ContactInboxesController#create`, `ContactInboxBuilder`, `HmacConcern`, route `212`, request specs, and the contact inbox Jbuilder partial. GoChat now accepts raw JSON/form/query params, account-scopes contact and inbox lookup, generates source IDs for API/WebWidget/Email/Sms/Whatsapp/Twilio channels, returns existing contact+inbox+source rows idempotently, persists `hmac_verified` on creation, and returns raw `{ source_id, inbox }` instead of the local model. | `go test ./internal/handler/api/v1 ./internal/service ./internal/repository -run 'ContactInbox\|ContactHandlerCRUD' -count=1`; `go test ./internal/handler/api/v1 ./internal/service ./internal/repository ./internal/router ./cmd/route_parity -run 'ContactInbox\|ContactHandlerCRUD\|Router\|RouteParity' -count=1`; `go run ./cmd/route_parity`; full `go test ./...`; `git diff --check`. Route dump remains `TOTAL: 933`; tracked route parity remains `374 exact, 0 method-compatible, 13 parameter-compatible, 0 missing out of 387`. | P3.23 moves to Review for current nested contact inbox creation evidence; continue Phase 2/3 drift audit, Phase 6 placeholder audit, B12 live smoke, or fresh reference/smoke drift. |
@@ -2449,3 +2451,4 @@ Verification milestone gates:
- 2026-06-06: P3.26 Shopify integration checkpoint prepared as `feat(integrations): align shopify parity`; audited Chatwoot Shopify account controller/specs, integration helper, callback behavior, routes `361-364`, and reused dashboard integrations/Shopify APIs. GoChat now exposes no-trailing and trailing Shopify destroy, returns raw auth/order payloads, uses Chatwoot `422 { error }` bodies for missing shop domains and missing contact info, resolves account-scoped contacts, calls Shopify customer search and orders REST endpoints through fakeable clients, appends order `admin_url`, finds callback-created hooks by `app_id: shopify`, and deletes with empty `200 OK`. Focused Shopify handler/service tests, route dump/parity regeneration (`940` routes; `390 exact`, `13 parameter-compatible`, `0 missing out of 403`), sandbox package tests, escalated full `go test ./...`, and `git diff --check` passed; continue Phase 2/3 drift audit, Phase 6 placeholder audit, or B12 live smoke.
- 2026-06-06: P3.27 Notion integration checkpoint prepared as `feat(integrations): align notion parity`; audited Chatwoot Notion account destroy controller, route `379`, Notion callback hook shape, and reused dashboard integrations delete flow. GoChat now exposes no-trailing and trailing Notion destroy, finds callback-created hooks by `app_id: notion` with legacy hook-type fallback, tracks the account route in route parity, and deletes with empty `200 OK`. Focused Notion handler/service tests, route dump/parity regeneration (`941` routes; `391 exact`, `13 parameter-compatible`, `0 missing out of 404`), full `go test ./...`, and `git diff --check` passed; continue Phase 2/3 drift audit, Phase 6 placeholder audit, or B12 live smoke.
- 2026-06-06: P3.28 Notion authorization checkpoint prepared as `feat(integrations): align notion authorization`; audited Chatwoot Notion account authorization controller/specs, route `335`, callback state handling, and reused dashboard `notion_auth.js`. GoChat now exposes administrator-gated `POST /api/v1/accounts/:account_id/notion/authorization`, returns raw `{ success: true, url }`, builds Notion OAuth URLs with `response_type=code`, `owner=user`, frontend `/notion/callback`, configured client ID, and signed account state, and tracks the account authorization route in route parity. Focused Notion authorization handler/service tests, route dump/parity regeneration (`942` routes; `392 exact`, `13 parameter-compatible`, `0 missing out of 405`), full `go test ./...`, and `git diff --check` passed; continue Phase 2/3 drift audit, Phase 6 placeholder audit, or B12 live smoke.
- 2026-06-06: P3.29 Twitter authorization checkpoint prepared as `feat(channels): align twitter authorization`; audited Chatwoot Twitter account authorization controller/specs, route `315`, Twitter callback behavior, and reused dashboard `twitterClient.js`. GoChat now exposes administrator-gated `POST /api/v1/accounts/:account_id/twitter/authorization`, signs and sends the OAuth1 request-token call through a fakeable client, returns raw `{ success: true, url }`, builds `/oauth/authorize?oauth_token=...` URLs, signs callback state for the existing Twitter callback, and tracks the account authorization route in route parity. Focused Twitter authorization handler/router tests, route dump/parity regeneration (`943` routes; `393 exact`, `13 parameter-compatible`, `0 missing out of 406`), full `go test ./...`, and `git diff --check` passed; continue Phase 2/3 drift audit, Phase 6 placeholder audit, or B12 live smoke.
+2 -1
View File
@@ -757,6 +757,7 @@ POST /api/v1/accounts/:account_id/teams/:team_id/team_members
POST /api/v1/accounts/:account_id/teams/:team_id/team_members/
POST /api/v1/accounts/:account_id/tiktok_channels/
POST /api/v1/accounts/:account_id/twilio_sms_channels/
POST /api/v1/accounts/:account_id/twitter/authorization
POST /api/v1/accounts/:account_id/twitter/webhooks
POST /api/v1/accounts/:account_id/twitter_channels/oauth_callback
POST /api/v1/accounts/:account_id/update_active_at
@@ -940,4 +941,4 @@ PUT /public/api/v1/csat_survey/:id
PUT /public/api/v1/inboxes/:inbox_id/contacts/:contact_id
PUT /public/api/v1/inboxes/:inbox_id/contacts/:contact_id/conversations/:conversation_id/messages/:message_id
PUT /widget/direct_uploads/:upload_uuid
TOTAL: 942
TOTAL: 943
+2 -1
View File
@@ -7,7 +7,7 @@ Generated from:
This report covers tracked frontend-critical Chatwoot routes from `reference/chatwoot/config/routes.rb`, including API v1 account routes, Captain/Copilot, assignment policies, widget/public APIs, and API v2 reports. Ruby is not installed in the workspace, so Chatwoot routes are sourced from static route declarations instead of `bin/rails routes`.
Summary: 392 exact, 0 method-compatible, 13 parameter-compatible, 0 missing out of 405 tracked critical routes.
Summary: 393 exact, 0 method-compatible, 13 parameter-compatible, 0 missing out of 406 tracked critical routes.
## Missing Critical Routes
@@ -372,6 +372,7 @@ These routes exist with equivalent method and path shape but different parameter
| POST | `/api/v1/accounts/:account_id/sla_policies` | `/api/v1/accounts/:account_id/sla_policies` | `api/v1/accounts/sla_policies#create` | `routes.rb:121` | exact |
| POST | `/api/v1/accounts/:account_id/teams/` | `/api/v1/accounts/:account_id/teams/` | `api/v1/accounts/teams#create` | `routes.rb:296` | exact |
| POST | `/api/v1/accounts/:account_id/teams/:team_id/team_members/` | `/api/v1/accounts/:account_id/teams/:team_id/team_members/` | `api/v1/accounts/teams/team_members#create` | `routes.rb:297` | exact |
| POST | `/api/v1/accounts/:account_id/twitter/authorization` | `/api/v1/accounts/:account_id/twitter/authorization` | `api/v1/accounts/twitter/authorizations#create` | `routes.rb:315` | exact |
| POST | `/api/v1/accounts/:account_id/update_active_at` | `/api/v1/accounts/:account_id/update_active_at` | `api/v1/accounts#update_active_at` | `routes.rb:49` | exact |
| POST | `/api/v1/accounts/:account_id/webhooks` | `/api/v1/accounts/:account_id/webhooks` | `api/v1/accounts/webhooks#create` | `routes.rb:342` | exact |
| POST | `/api/v1/notification_subscriptions` | `/api/v1/notification_subscriptions` | `api/v1/notification_subscriptions#create` | `routes.rb:440` | exact |
@@ -0,0 +1,132 @@
package v1
import (
"encoding/json"
"io"
"net/http"
"net/http/httptest"
"net/url"
"strings"
"testing"
"github.com/gin-gonic/gin"
"github.com/golang-jwt/jwt/v5"
"github.com/stretchr/testify/assert"
"github.com/stretchr/testify/require"
)
func setupTwitterAuthorizationRouter() *gin.Engine {
gin.SetMode(gin.TestMode)
r := gin.New()
r.RedirectTrailingSlash = false
handler := NewTwitterChannelHandler(nil, nil, nil, nil)
r.POST("/api/v1/accounts/:account_id/twitter/authorization", handler.ChatwootAuthorization)
return r
}
func TestTwitterAuthorization_BadAccountID(t *testing.T) {
r := setupTwitterAuthorizationRouter()
w := httptest.NewRecorder()
req, _ := http.NewRequest(http.MethodPost, "/api/v1/accounts/abc/twitter/authorization", nil)
r.ServeHTTP(w, req)
assert.Equal(t, http.StatusBadRequest, w.Code)
var resp map[string]interface{}
require.NoError(t, json.Unmarshal(w.Body.Bytes(), &resp))
errBody := resp["error"].(map[string]interface{})
assert.Contains(t, errBody["message"], "invalid account_id")
}
func TestTwitterAuthorization_ReturnsChatwootPayload(t *testing.T) {
t.Setenv("TWITTER_CONSUMER_KEY", "twitter-key")
t.Setenv("TWITTER_CONSUMER_SECRET", "twitter-secret")
t.Setenv("TWITTER_OAUTH_REQUEST_TOKEN_URL", "https://oauth.example.test/request_token")
t.Setenv("TWITTER_API_BASE_URL", "https://api.twitter.test")
t.Setenv("FRONTEND_URL", "https://app.example.test/")
originalClient := twitterAuthorizationHTTPClient
twitterAuthorizationHTTPClient = &http.Client{Transport: twitterAuthorizationRoundTripFunc(func(req *http.Request) (*http.Response, error) {
assert.Equal(t, http.MethodPost, req.Method)
assert.Equal(t, "https://oauth.example.test/request_token", req.URL.String())
authHeader := req.Header.Get("Authorization")
assert.Contains(t, authHeader, "OAuth ")
assert.Contains(t, authHeader, `oauth_consumer_key="twitter-key"`)
assert.Contains(t, authHeader, "oauth_callback=")
return &http.Response{StatusCode: http.StatusOK, Body: io.NopCloser(strings.NewReader("oauth_token=request-token&oauth_token_secret=request-secret")), Header: http.Header{}}, nil
})}
t.Cleanup(func() { twitterAuthorizationHTTPClient = originalClient })
r := setupTwitterAuthorizationRouter()
w := httptest.NewRecorder()
req, _ := http.NewRequest(http.MethodPost, "/api/v1/accounts/42/twitter/authorization", nil)
r.ServeHTTP(w, req)
assert.Equal(t, http.StatusOK, w.Code)
var resp map[string]interface{}
require.NoError(t, json.Unmarshal(w.Body.Bytes(), &resp))
assert.Equal(t, true, resp["success"])
assert.Equal(t, "https://api.twitter.test/oauth/authorize?oauth_token=request-token", resp["url"])
}
func TestTwitterAuthorization_SignedStateMatchesCallback(t *testing.T) {
t.Setenv("TWITTER_CONSUMER_KEY", "twitter-key")
t.Setenv("TWITTER_CONSUMER_SECRET", "twitter-secret")
t.Setenv("TWITTER_OAUTH_REQUEST_TOKEN_URL", "https://oauth.example.test/request_token")
t.Setenv("FRONTEND_URL", "https://app.example.test")
originalClient := twitterAuthorizationHTTPClient
var callbackURL string
twitterAuthorizationHTTPClient = &http.Client{Transport: twitterAuthorizationRoundTripFunc(func(req *http.Request) (*http.Response, error) {
authHeader := req.Header.Get("Authorization")
for _, part := range strings.Split(strings.TrimPrefix(authHeader, "OAuth "), ",") {
part = strings.TrimSpace(part)
if strings.HasPrefix(part, "oauth_callback=") {
callbackURL = strings.Trim(strings.TrimPrefix(part, "oauth_callback="), `"`)
decoded, err := url.QueryUnescape(callbackURL)
require.NoError(t, err)
callbackURL = decoded
}
}
return &http.Response{StatusCode: http.StatusOK, Body: io.NopCloser(strings.NewReader("oauth_token=request-token")), Header: http.Header{}}, nil
})}
t.Cleanup(func() { twitterAuthorizationHTTPClient = originalClient })
r := setupTwitterAuthorizationRouter()
w := httptest.NewRecorder()
req, _ := http.NewRequest(http.MethodPost, "/api/v1/accounts/42/twitter/authorization", nil)
r.ServeHTTP(w, req)
require.Equal(t, http.StatusOK, w.Code)
parsed, err := url.Parse(callbackURL)
require.NoError(t, err)
assert.Equal(t, "https://app.example.test/twitter/callback", parsed.Scheme+"://"+parsed.Host+parsed.Path)
claims := jwt.MapClaims{}
token, err := jwt.ParseWithClaims(parsed.Query().Get("state"), claims, func(token *jwt.Token) (any, error) {
return []byte("twitter-secret"), nil
})
require.NoError(t, err)
require.True(t, token.Valid)
assert.Equal(t, float64(42), claims["sub"])
}
func TestTwitterAuthorization_NotConfigured(t *testing.T) {
t.Setenv("TWITTER_CONSUMER_KEY", "")
t.Setenv("TWITTER_CONSUMER_SECRET", "")
r := setupTwitterAuthorizationRouter()
w := httptest.NewRecorder()
req, _ := http.NewRequest(http.MethodPost, "/api/v1/accounts/42/twitter/authorization", nil)
r.ServeHTTP(w, req)
assert.Equal(t, http.StatusUnprocessableEntity, w.Code)
var resp map[string]interface{}
require.NoError(t, json.Unmarshal(w.Body.Bytes(), &resp))
assert.Equal(t, false, resp["success"])
}
type twitterAuthorizationRoundTripFunc func(*http.Request) (*http.Response, error)
func (f twitterAuthorizationRoundTripFunc) RoundTrip(req *http.Request) (*http.Response, error) {
return f(req)
}
@@ -25,10 +25,24 @@ package v1
// - GET /api/v1/accounts/:id/twitter/webhooks → List registered webhooks
import (
"context"
"crypto/hmac"
"crypto/rand"
"crypto/sha1"
"encoding/base64"
"encoding/hex"
"fmt"
"io"
"net/http"
"net/url"
"os"
"sort"
"strconv"
"strings"
"time"
"github.com/gin-gonic/gin"
"github.com/golang-jwt/jwt/v5"
twitterchannel "github.com/gochat/gochat/internal/channel/twitter"
"github.com/gochat/gochat/internal/model"
@@ -36,8 +50,11 @@ import (
"github.com/gochat/gochat/internal/repository"
"github.com/gochat/gochat/internal/service"
applogger "github.com/gochat/gochat/pkg/logger"
"github.com/gochat/gochat/pkg/response"
)
var twitterAuthorizationHTTPClient = http.DefaultClient
// TwitterChannelHandler handles Twitter/X channel management.
type TwitterChannelHandler struct {
twService *service.ChannelTwitterService
@@ -95,6 +112,136 @@ func (h *TwitterChannelHandler) Authorization(c *gin.Context) {
c.JSON(http.StatusOK, gin.H{"authorization_url": authURL})
}
// ChatwootAuthorization creates a Twitter OAuth1 authorization URL.
// POST /api/v1/accounts/:account_id/twitter/authorization
func (h *TwitterChannelHandler) ChatwootAuthorization(c *gin.Context) {
accountID, err := parseUintParam(c, "account_id")
if err != nil {
response.AbortWithStatusError(c, http.StatusBadRequest, response.ErrBadRequest, "invalid account_id")
return
}
redirectURL, err := buildTwitterChatwootAuthorizationURL(c.Request.Context(), accountID)
if err != nil {
applogger.L().Errorf("Failed to build Twitter authorization URL: %v", err)
c.JSON(http.StatusUnprocessableEntity, gin.H{"success": false})
return
}
c.JSON(http.StatusOK, gin.H{"success": true, "url": redirectURL})
}
func buildTwitterChatwootAuthorizationURL(ctx context.Context, accountID uint) (string, error) {
consumerKey := strings.TrimSpace(os.Getenv("TWITTER_CONSUMER_KEY"))
consumerSecret := strings.TrimSpace(os.Getenv("TWITTER_CONSUMER_SECRET"))
if consumerKey == "" || consumerSecret == "" {
return "", fmt.Errorf("Twitter OAuth is not configured")
}
state, err := signedTwitterState(accountID, consumerSecret)
if err != nil {
return "", err
}
callbackURL := strings.TrimRight(envOrDefaultV1("FRONTEND_URL", "http://localhost:3000"), "/") + "/twitter/callback?state=" + url.QueryEscape(state)
requestTokenURL := envOrDefaultV1("TWITTER_OAUTH_REQUEST_TOKEN_URL", "https://api.twitter.com/oauth/request_token")
req, err := http.NewRequestWithContext(ctx, http.MethodPost, requestTokenURL, nil)
if err != nil {
return "", err
}
authHeader, err := twitterOAuth1Header(http.MethodPost, requestTokenURL, consumerKey, consumerSecret, callbackURL)
if err != nil {
return "", err
}
req.Header.Set("Authorization", authHeader)
req.Header.Set("Accept", "application/x-www-form-urlencoded")
resp, err := twitterAuthorizationHTTPClient.Do(req)
if err != nil {
return "", err
}
defer resp.Body.Close()
if resp.StatusCode < http.StatusOK || resp.StatusCode >= http.StatusMultipleChoices {
_, _ = io.Copy(io.Discard, resp.Body)
return "", fmt.Errorf("twitter request token failed: %s", resp.Status)
}
body, err := io.ReadAll(resp.Body)
if err != nil {
return "", err
}
values, err := url.ParseQuery(string(body))
if err != nil {
return "", err
}
oauthToken := strings.TrimSpace(values.Get("oauth_token"))
if oauthToken == "" {
return "", fmt.Errorf("twitter request token missing oauth_token")
}
authorizeBase := strings.TrimRight(envOrDefaultV1("TWITTER_API_BASE_URL", "https://api.twitter.com"), "/")
return authorizeBase + "/oauth/authorize?oauth_token=" + url.QueryEscape(oauthToken), nil
}
func signedTwitterState(accountID uint, secret string) (string, error) {
token := jwt.NewWithClaims(jwt.SigningMethodHS256, jwt.MapClaims{
"sub": accountID,
"iat": time.Now().Unix(),
})
return token.SignedString([]byte(secret))
}
func twitterOAuth1Header(method, rawURL, consumerKey, consumerSecret, callbackURL string) (string, error) {
nonceBytes := make([]byte, 16)
if _, err := rand.Read(nonceBytes); err != nil {
return "", err
}
params := map[string]string{
"oauth_callback": callbackURL,
"oauth_consumer_key": consumerKey,
"oauth_nonce": hex.EncodeToString(nonceBytes),
"oauth_signature_method": "HMAC-SHA1",
"oauth_timestamp": strconv.FormatInt(time.Now().Unix(), 10),
"oauth_version": "1.0",
}
params["oauth_signature"] = oauth1Signature(method, rawURL, params, consumerSecret)
keys := make([]string, 0, len(params))
for key := range params {
keys = append(keys, key)
}
sort.Strings(keys)
parts := make([]string, 0, len(keys))
for _, key := range keys {
parts = append(parts, fmt.Sprintf(`%s="%s"`, oauthPercentEncode(key), oauthPercentEncode(params[key])))
}
return "OAuth " + strings.Join(parts, ", "), nil
}
func oauth1Signature(method, rawURL string, params map[string]string, consumerSecret string) string {
keys := make([]string, 0, len(params))
for key := range params {
keys = append(keys, key)
}
sort.Strings(keys)
encodedParams := make([]string, 0, len(keys))
for _, key := range keys {
encodedParams = append(encodedParams, oauthPercentEncode(key)+"="+oauthPercentEncode(params[key]))
}
base := strings.ToUpper(method) + "&" + oauthPercentEncode(rawURL) + "&" + oauthPercentEncode(strings.Join(encodedParams, "&"))
mac := hmac.New(sha1.New, []byte(oauthPercentEncode(consumerSecret)+"&"))
_, _ = mac.Write([]byte(base))
return base64.StdEncoding.EncodeToString(mac.Sum(nil))
}
func oauthPercentEncode(value string) string {
return strings.ReplaceAll(url.QueryEscape(value), "+", "%20")
}
func envOrDefaultV1(key string, fallback string) string {
if value := strings.TrimSpace(os.Getenv(key)); value != "" {
return value
}
return fallback
}
// === OAuth Callback ===
// TwitterOAuthCallbackRequest is the DTO for Twitter OAuth callback.
+1
View File
@@ -1581,6 +1581,7 @@ func registerV1Routes(g *gin.RouterGroup, h *Handlers) {
// Notion OAuth authorization (ref: Chatwoot namespace :notion resource :authorization)
accountScoped.POST("/notion/authorization", middleware.RoleCheck("administrator"), h.NotionIntegration.Authorization)
accountScoped.POST("/twitter/authorization", middleware.RoleCheck("administrator"), h.TwitterChannel.ChatwootAuthorization)
// G16: Third-party Integrations — IntegrationHook CRUD + Slack/Shopify/Linear/Notion
// Reference: Chatwoot namespace :integrations under :account