Status (2026-09-24): Application code for Slack /whois, contact export, and guest-email migration invitations is already gone on main. This checklist is the remaining ops / artifact work. Do not rewrite git history from this list.
Verified against main after #308 (Slack removal) and #299 (contact-export removal).
| Path / concern | Live on main? |
Notes |
|---|---|---|
/api/slack/whois |
No | Route, tests, and docs/slack-integration.md deleted in #308 |
SLACK_* in .env.example |
No | Three vars removed in #308 |
| Slack npm dependency | No | Never a package dependency; signing was env-only |
src/data/legacy-friends.json |
No | Deleted in #299 |
| Invite-friends migration UI / mutations | No | Banner, mutations, and plans removed; /circles/invite-friends only redirects to /dashboard |
| Guest-email invitation actions | No | No invitationSent / emailSent writers in src/ |
| CI / GitHub Actions Slack secrets | No | Workflows do not reference SLACK_* |
Circle invitations remain Clerk org invitations (supported). Pickup “invitation” links use join tokens — unrelated to the retired contact-export flow.
In the Blitzer Vercel project, for Production, Preview, and Development (and any custom environments):
- Remove
SLACK_SIGNING_SECRET - Remove
SLACK_WHOIS_TEAM_ID - Remove
SLACK_WHOIS_USER_IDS
Redeploy is optional; unused env vars do not restore the deleted route. Removing them avoids confusion and secret sprawl.
Also check any local .env / .env.local / teammate machines / password managers for the same three keys.
The Slack app is external to the repo. Deleting the Next route does not uninstall the app or remove the slash command.
- Open the Slack app used for Blitzer
/whois - If that app exists only for Blitzer reports: uninstall it from the workspace (or delete the Slack app)
- If the app is shared with other tools: remove only the
/whoisslash command and any Request URL pointing at…/api/slack/whois - Confirm a test
/whoisin Slack no longer hits a live Blitzer handler (expect Slack “failed” / dead endpoint, not a Blitzer stats reply)
- No further README /
.env.exampleSlack scrub needed on currentmain(done in #308)
src/data/legacy-friends.json (emails/usernames) was deleted from the tree in #299 but still exists in older commits. Forks, CI caches, local clones, and any exported artifacts may still hold copies.
| Action | Safe without extra process? |
|---|---|
| Leave history as-is; rely on private-repo access control | Yes — default |
| Rotate / treat listed emails as already exposed to repo collaborators | Owner judgment |
git filter-repo / BFG / force-push rewrite |
No — coordinated decision only; breaks SHAs, open PRs, and clones |
| Ask GitHub Support for blob purge after a rewrite | Only after a planned rewrite |
This checklist does not authorize history rewrite.
Still in schema.prisma, unused by the app:
OrganizationMembershiptable (Clerk is source of truth; no sync)GuestUser.invitationSent,invitationSentAt,emailSent
Dropping these needs a dedicated migration review. Not required for Slack/contact ops cleanup.
Older plans/specs still mention Slack /whois or invite-previous-friends. They are design history, not live contracts. Leaving them is fine; rewriting or deleting them is optional hygiene, not security cleanup.
- Contact import / guest-email migration invitations
- Slack
/whoisor operator Slack telemetry - Treating
docs/superpowersinvite/Slack plans as the current product contract
- Three
SLACK_*vars are gone from all Vercel envs (and local copies you care about). - Slack
/whoisis uninstalled or deconfigured so it cannot call Blitzer. - Owner has either accepted “history remains” for
legacy-friends.jsonor opened a separate, explicit history-remediation plan.