Session Persistence

There is no browser session. Identity comes from Slack request payloads and OAuth state binds a browser callback to a Slack user.

  • DRAFT_DATABASE_PATH selects SQLite draft storage. Empty uses an in-memory singleton and loses drafts at process restart.

  • AUTHORIZATION_DATABASE_PATH selects SQLite for encrypted GitHub authorizations and OAuth state. Empty uses memory and loses connections/state at restart.

  • CONFLUENCE_TOKEN_DIRECTORY stores encrypted PAT files; the default is /tmp/knowledge-assistant/confluence and is ephemeral unless mounted.

The SQLite implementation is documented for a single-process deployment. The Helm chart uses one replica and maps the two database paths to /data; it does not currently set CONFLUENCE_TOKEN_DIRECTORY to that persistent volume. Confluence PAT persistence in Kubernetes therefore requires an explicit deployment change.

DRAFT_TTL_SECONDS is configured and placed on draft records, but the repository contains no background purge job. Retention/deletion schedules are TO_BE_CONFIRMED.