Files
PaperClipAI/server
DottaandPaperclip f47614046d fix(slack): upload agent avatars directly during Cloud setup (#15566)
## Thinking Path

> - Paperclip helps people manage AI agents for work.
> - Slack setup creates a dedicated bot for an agent.
> - The setup should upload that agent's avatar.
> - The current upload asks Slack to fetch an image from the board
origin.
> - Cloud requires a tenant session at that origin, so Slack receives
HTTP 401.
> - This change renders the PNG on the server and uploads the file
directly.

## Linked Issues or Issue Description

Refs #15413.

**What happened?**

Automatic Slack setup left the app and bot with default icons on Cloud
staging. An unauthenticated request to the exact avatar URL returned
HTTP 401 with `tenant_session_required`. Local setup did not expose this
Cloud ingress requirement.

**Expected behavior**

New Slack bots receive the assigned agent's 512-pixel avatar with the
Paperclip dark background.

**Steps to reproduce**

1. Create a Slack app through automatic setup on a Cloud tenant.
2. Complete installation.
3. Inspect the bot avatar in Slack. The previous URL-based upload cannot
fetch the image without a tenant session.

## What Changed

- Render the assigned agent's preset PNG with the existing bounded
worker pool.
- Send PNG bytes as multipart `file` data to `apps.icon.set` instead of
passing a board URL.
- Keep the temporary token in the Authorization header. Let fetch set
the multipart boundary.
- Recheck management permission and credential-lease ownership after
rendering. Close the worker pool during chat service shutdown.
- Cover actual PNG dimensions, uploaded bytes, failure recovery, and
secret-safe responses. Update deployment documentation.

## Verification

- Passed: 84 focused tests across automatic Slack registration and
on-demand agent avatars.
- Passed: full repository build.
- Passed: full repository typecheck. All 54 current-head GitHub checks
passed, including the complete test matrix, all browser shards, build,
typecheck, canary, and security checks. Greptile completed on
`79e79f6fc` with 5/5 and no actionable findings or open review threads.
- The Cloud fetch failure was reproduced without browser credentials. No
Cloud access rule was changed.
- A real Slack upload with this new path still requires deployment and a
fresh automatic setup. Existing apps retain the manual avatar-upload
fallback.

## Risks

- The renderer can time out or Slack can reject the upload. Both
failures preserve the saved app and leave installation usable.
- The renderer adds a bounded, lazy worker pool to Slack registration.
Shutdown closes it.
- No migration, bot permissions, credential retention, or Cloud
authentication behavior changes.

## Model Used

OpenAI Codex, GPT-6 family, with reasoning, repository tools, code
execution, and browser inspection. The runtime does not expose a more
specific authoring model ID or context-window size.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-10-08 08:12:18 -05:00
..