Skip to content

Solution for the use cases behind firewalls is needed #108

Description

@Ambro17

Problem

Inability to easily identifying requests coming from slack

Motivation

As slack is used in many work environments with strict security policies, it is a strong requisite to only expose the server/function to known hosts/ips.

Enhancement Proposal

It may result useful to provide an utility function or perhaps document how we can validate that the request comes indeed from slack. This would allow to open server's to certain IPs or lambdas to only trigger under certain conditions.
This would greatly reduce the attack surface on slack apps integrations.

Workaround

Currently, the promoted way of validating requests authenticity is by validating it against signing secret of the app. This is really useful, but it can't be used as a firewall rule, so it may be a prohibitive constraint for many possible integrations

Activity

  1. seratch commented on Sep 30, 2020

    @seratch
    Contributor

    Thanks for sharing your thoughts! I do understand your point here.

    As you mentioned, currently, incoming requests by checking x-slack-signature header value is the only way to go. https://api.slack.com/authentication/verifying-requests-from-slack

    but it can't be used as a firewall rule, so it may be a prohibitive constraint for many possible integrations

    The Slack team is currently working on a new solution for the use cases behind firewalls. https://trello.com/c/YMq4fN75/70-support-for-apps-to-receive-platform-data-behind-a-firewall

    I cannot tell when we can deliver the solution's GA version yet but please stay tuned to the updates.

  2. Ambro17 commented on Oct 2, 2020

    @Ambro17
    Author

    Thank you for the response, hopefully they prioritize it so I can take full advantage of the sdk.
    Thanks for your awesome port of bolt's sdk too. Its declarative api is what inspired me to write slackify

  3. seratch commented on Oct 9, 2020

    @seratch
    Contributor

    The Slack team is currently working on a new solution for the use cases behind firewalls. https://trello.com/c/YMq4fN75/70-support-for-apps-to-receive-platform-data-behind-a-firewall

    This feature "Socket Mode" was announced at Frontiers. We're going to implement Socket Mode support in Bolt for Python soon. https://slack.com/blog/transformation/people-partners-systems-slack

  4. Ambro17 commented on Oct 9, 2020

    @Ambro17
    Author

    That's great news! I will try it as soon as it's released :)

  5. added this to the 1.1.0 milestone on Oct 23, 2020
  6. changed the title [-]Block requests not coming from slack servers[/-] [+]Socket Mode support[/+] on Oct 23, 2020
  7. changed the title [-]Socket Mode support[/-] [+]Solution for the use cases behind firewalls is needed[/+] on Oct 23, 2020
  8. modified the milestones: 1.1.0, 1.2.0 on Nov 25, 2020
  9. seratch commented on Nov 25, 2020

    @seratch
    Contributor

    Socket Mode is the solution for this. As we can discuss this topic at #159 , let me close this issue now. Thanks for taking the time to share your thoughts here!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions