Repository navigation
Solution for the use cases behind firewalls is needed #108
Description
Activity
Thanks for sharing your thoughts! I do understand your point here.
As you mentioned, currently, incoming requests by checking
x-slack-signatureheader value is the only way to go. https://api.slack.com/authentication/verifying-requests-from-slackbut it can't be used as a firewall rule, so it may be a prohibitive constraint for many possible integrations
The Slack team is currently working on a new solution for the use cases behind firewalls. https://trello.com/c/YMq4fN75/70-support-for-apps-to-receive-platform-data-behind-a-firewall
I cannot tell when we can deliver the solution's GA version yet but please stay tuned to the updates.
- addedenhancementNew feature or requestNew feature or requestquestionFurther information is requestedFurther information is requested
on Sep 30, 2020 Thank you for the response, hopefully they prioritize it so I can take full advantage of the sdk.
Thanks for your awesome port of bolt's sdk too. Its declarative api is what inspired me to write slackifyReacted by Kazuhiro SeraThe Slack team is currently working on a new solution for the use cases behind firewalls. https://trello.com/c/YMq4fN75/70-support-for-apps-to-receive-platform-data-behind-a-firewall
This feature "Socket Mode" was announced at Frontiers. We're going to implement Socket Mode support in Bolt for Python soon. https://slack.com/blog/transformation/people-partners-systems-slack
Reacted by Nahuel AmbrosiniThat's great news! I will try it as soon as it's released :)
- changed the title
[-]Block requests not coming from slack servers[/-][+]Socket Mode support[/+]on Oct 23, 2020 - removedquestionFurther information is requestedFurther information is requested
on Oct 23, 2020 - changed the title
[-]Socket Mode support[/-][+]Solution for the use cases behind firewalls is needed[/+]on Oct 23, 2020 Socket Mode is the solution for this. As we can discuss this topic at #159 , let me close this issue now. Thanks for taking the time to share your thoughts here!
Problem
Inability to easily identifying requests coming from slack
Motivation
As slack is used in many work environments with strict security policies, it is a strong requisite to only expose the server/function to known hosts/ips.
Enhancement Proposal
It may result useful to provide an utility function or perhaps document how we can validate that the request comes indeed from slack. This would allow to open server's to certain IPs or lambdas to only trigger under certain conditions.
This would greatly reduce the attack surface on slack apps integrations.
Workaround
Currently, the promoted way of validating requests authenticity is by validating it against signing secret of the app. This is really useful, but it can't be used as a firewall rule, so it may be a prohibitive constraint for many possible integrations