Repository navigation
Allow disabling of token auth test #158
Description
Activity
- addedenhancementNew feature or requestNew feature or requestquestionFurther information is requestedFurther information is requested
on Nov 24, 2020 @mew1033 Thanks for writing in and sharing the details! Your detailed description helped me understand what the issue you have is.
I know it's pretty easy to add a new option to turn calling
auth.testAPI off at the timing of initialization. But I would like to hold off adding such options because doing so a lot makes udnerstanding the initialization ofAppharder for developers.So, our recommendation for this use case is to use
authorizefunction with the toekn. Bolt does this under the hood for you. You can learn more about this here: https://slack.dev/bolt-python/concepts#authorizationdef authorize(enterprise_id, team_id, user_id, client: WebClient, logger): # If you want to have a cache for this call, you can do so token = secrets["SLACK_BOT_TOKEN"] return AuthorizeResult.from_auth_test_response( auth_test_response=client.auth_test(token=token), bot_token=token ) app = App( process_before_response=True, signing_secret=secrets["SLACK_SIGNING_SECRET"], authorize=authorize )
Hope this was helpful to you.
@seratch I tested your solution and it appears to work fine, thank you.
However, it also seems overly complex and very much against the "Zen" of python.I also don't agree with the assumption that adding an option to the App initialization makes it harder for developers. If the option is available, and the default is kept the same as it is now, I don't think that makes using App() more complex.
I suppose I can see that adding more options, and thus making the App() constructor slightly more complex could make reading it more difficult. But that is a (IMO) small price to pay for added functionality.Regardless, thank you for the code snippet that fixed my problem. I appreciate it!
@seratch Another argument against a required auth test: The slack_sdk itself doesn't require it. You can create a WebClient instance with a bogus token no problem. It has the functionality built in to do an auth test, but it doesn't do it until explicitly asked.
@mew1033
The reason why Bolt performsauth.testwith its default settings is to constructAuthorizeResultthat is used for the framework's functionalities. But, if your app can give sufficient information forAuthorizeResultwithout callingauth.testAPI (or storing the result somewhere accessible from your app in advance) to Bolt, calling the API in the app is not required at all.Thanks for your comments and feedback. I appreciate it. We may revisit the idea to add an option to skip the initialization but we're not going to take action at this point. Can we close this issue now?
Thanks for the quick replies. I think that this can be closed now, yes.
Reacted by Kazuhiro SeraWe revisited this feature and decide to provide an option
token_verification_enabled: bool = Trueto turn off the verification in constructor. I will come up with a pull request later.Awesome! Thank you!
- added a commit that references this issue
on Dec 18, 2020 I am going to release a new patch version soon (the last release in 2020):
https://github.com/slackapi/bolt-python/milestone/18
I've written a small app that is running in AWS lambda. I'm using the aws_lambda adapter and it is working great. However, I ran into a problem when attempting to write a test for an unrelated function in my lambda code (using pytest).
I'm setting up the App object in the global scope so that it's available for future function runs that reuse this container. This is in accordance with lambda's best practices. The problem is that I can't import my function code into my test at all unless I have a valid token, which I don't want/need to supply during testing. Here's an example:
Trying to import that file in a test fails because the app can't verify the token. Here's the error:
This can be easily reproduced by running:
app = App(signing_secret="nope", token="no_token")and observing the same error as above.I'd like to be able to temporarily disable the token auth test so I can import my code and run a test. I'm not testing any part of slack_bolt, but I've kept all my functions in a single file for simplicity's sake, and I'd like to test one of my other functions.
Category (place an
xin each of the[ ])