Repository navigation
Option to disable signature verification #648
Description
Activity
Wasn't able to replace it. Ended up computing the signature and sending that header.
Need to add headers
x-slack-request-timestamp(unix timestamp in seconds, should be within last 5 minutes for successful verification) andx-slack-signature. Signature can be computed asconst computeSignature = ( version: string, data: string, timestamp: number, signingSecret: string ) => { const hmac = crypto.createHmac('sha256', signingSecret); hmac.update(`${version}:${timestamp}:${data}`); return `${version}=${hmac.digest('hex')}`; };
Current version is
v0it seems.datahas to be the request body. JSON data, but stringified.- addedenhancementM-T: A feature request for new functionalityM-T: A feature request for new functionalitytestsM-T: Testing work onlyM-T: Testing work onlyand removed
on Sep 30, 2020 Wasn't able to replace it. Ended up computing the signature and sending that header.
Yes, currently it's not possible to replace/disable the logic from
ExpressReceiver. The only way to write valid tests is, as you did, to have some code populatingx-slack-signatureheader in requests.Also, I agree that this project can improve the module structure to support better and easier ways to write unit tests.
Recently, we've implemented the feature to turn the verification off in the Java SDK.
- Allow removing default middleware in Bolt java-slack-sdk#689
- Fix #689 by adding flags in AppConfig java-slack-sdk#690
- https://slack.dev/java-slack-sdk/guides/bolt-basics#customize-the-built-in-middleware-list
We can consider adding something similar in Bolt for JS too.
- added a commit that references this issue
on Aug 28, 2021
Description
Option to disable signature verification. This will be particularly useful for running tests and should be used only for tests. Since signature verification in production is a security feature.
What type of issue is this? (place an
xin one of the[ ])Requirements (place an
xin each of the[ ])Example usage:
This currently doesn't work since the verification middleware wouldn't call the next middleware since the verification would fail. And I wasn't able to replace the
verifySignatureAndParseRawBodywith a fake. I will give some more tries. But maybe it is just easier to allow disabling this middleware from app options?