The shape rule (a platform prefix plus _TOKEN/_SECRET/_PASSWORD/_KEY) also matched variables Hermes never reads: the platform list holds plain words (LOCAL, GATEWAY, WEBHOOK, SLACK), so a user's SLACK_USER_TOKEN, LOCAL_LLM_API_KEY or GATEWAY_API_KEY vanished from the terminal and terminal.env_passthrough could not bring them back. The prefix census it leaned on also failed open (an unreadable plugins dir cached an empty set). Adapter secrets now come from what adapters declare: password entries of the messaging OPTIONAL_ENV_VARS (built-ins plus every platform plugin manifest) and secret-named keys of the gateway env-override table, both Tier 1 and refused by passthrough; plus the secret-named required_env of adapters registered in the current profile scope, read per spawn without loading deferred adapters, Tier 2 only because required_env is an unchecked setup list. Secrets nothing declared get a manifest entry (TELEGRAM_WEBHOOK_SECRET, PHOTON_SIDECAR_TOKEN, A2A_PUSH_SECRET, TEAMS_GRAPH_ACCESS_TOKEN, TEAMS_INCOMING_WEBHOOK_URL) or join the policy's read-in-code list (QQ_STT_API_KEY, the two MSGRAPH names).
65 lines
2.6 KiB
YAML
65 lines
2.6 KiB
YAML
name: teams-platform
|
|
label: Microsoft Teams
|
|
kind: platform
|
|
version: 1.0.0
|
|
description: >
|
|
Microsoft Teams gateway adapter for Hermes Agent.
|
|
Connects to Microsoft Teams via the Bot Framework and relays messages
|
|
between Teams chats (personal DMs, group chats, channel posts) and
|
|
the Hermes agent. Supports Adaptive Card approval prompts.
|
|
author: Aamir Jawaid
|
|
# ``requires_env`` entries are surfaced in ``hermes config`` UI via the
|
|
# platform-plugin env var injector in ``hermes_cli/config.py``.
|
|
requires_env:
|
|
- name: TEAMS_CLIENT_ID
|
|
description: "Azure AD application (Bot Framework) client ID"
|
|
prompt: "Teams / Azure AD client ID"
|
|
url: "https://portal.azure.com/"
|
|
password: false
|
|
- name: TEAMS_CLIENT_SECRET
|
|
description: "Azure AD application client secret"
|
|
prompt: "Teams / Azure AD client secret"
|
|
url: "https://portal.azure.com/"
|
|
password: true
|
|
- name: TEAMS_TENANT_ID
|
|
description: "Azure AD tenant ID hosting the bot application"
|
|
prompt: "Teams / Azure AD tenant ID"
|
|
password: false
|
|
optional_env:
|
|
- name: TEAMS_PORT
|
|
description: "Webhook listen port (Bot Framework default: 3978)"
|
|
prompt: "Webhook port"
|
|
password: false
|
|
- name: TEAMS_HOST
|
|
description: "Webhook bind host (default: unset → dual-stack, all interfaces IPv4+IPv6)"
|
|
prompt: "Webhook host"
|
|
password: false
|
|
- name: TEAMS_ALLOWED_USERS
|
|
description: "Comma-separated Teams user IDs / UPNs allowed to talk to the bot"
|
|
prompt: "Allowed users (comma-separated)"
|
|
password: false
|
|
- name: TEAMS_ALLOW_ALL_USERS
|
|
description: "Allow any Teams user to trigger the bot (dev only)"
|
|
prompt: "Allow all users? (true/false)"
|
|
password: false
|
|
- name: TEAMS_REQUIRE_MENTION
|
|
description: "Only answer channel/group-chat messages that @mention the bot or reply to it (default false; needed once the app has RSC message-read consent)"
|
|
prompt: "Require @mention in channels and group chats? (true/false)"
|
|
password: false
|
|
- name: TEAMS_HOME_CHANNEL
|
|
description: "Default chat/channel ID for cron / notification delivery"
|
|
prompt: "Home channel (or empty)"
|
|
password: false
|
|
- name: TEAMS_HOME_CHANNEL_NAME
|
|
description: "Display name for the Teams home channel"
|
|
prompt: "Home channel display name"
|
|
password: false
|
|
- name: TEAMS_INCOMING_WEBHOOK_URL
|
|
description: "Incoming-webhook URL for meeting-summary delivery in webhook mode (the URL is the credential)"
|
|
prompt: "Incoming webhook URL (or empty)"
|
|
password: true
|
|
- name: TEAMS_GRAPH_ACCESS_TOKEN
|
|
description: "Microsoft Graph access token for meeting-summary delivery in graph mode"
|
|
prompt: "Graph access token (or empty)"
|
|
password: true
|