Bind one decision owner.
Multiple surfaces may display status, but they do not automatically gain response authority.
A trusted immutable binding selects the only answerer allowed to settle this approval.
Authenticate the whole authority edge.
approlechatapprovalexpiryMake click and timeout one race.
Both paths compare-and-set the same pending revision. Only one transition succeeds.
A late click or timer observes the terminal record and cannot return a second outcome.
Message patching reflects the result; patch failure can never reopen or change it.
Card UX cannot carry hidden authority.
Do not claim the approver reviewed exact command arguments when the seam did not provide them.
Patch the exact original card family. Never guess a different schema after an error.
Package the integration outside managed DSH files.
Register one scoped answerer through the supported out-of-tree plugin boundary.
Pin the dsh-im callback contract, compatible versions, card schema, and removal path.
Core owns identity and settlement; the Feishu adapter owns webhook auth and card UX.
Six high-value proof gates.
- 01Every Session has at most one approval decision owner.
- 02Forwarded cards cannot authorize an unapproved principal.
- 03Click and timeout settle through one atomic compare-and-set.
- 04Duplicate, retried, reordered, and late callbacks fail closed.
- 05Patch failure cannot change the terminal tool decision.
- 06Web-only, Feishu-only, and simultaneous-observer fixtures preserve one owner.
Primary evidence.
- Feishu approval-card proposal #4733
- rc.2 channel-neutral approval seam
- rc.2 replay and settlement tests
- SDK interaction proposal #4708
Keep the complete interaction contract.
The canonical guide covers SDK requests, channel ownership, authenticated card authority, atomic settlement, schema-stable projection, restart recovery, packaging, and thirty-six conformance gates.
Read the complete guide