Skip to content

Fix an issue where different user's token may exist in context - #244

Merged
seratch merged 1 commit into
slackapi:mainfrom
seratch:user-token-in-context
Feb 21, 2021
Merged

seratch merged 1 commit into
slackapi:mainfrom
seratch:user-token-in-context

Conversation

@seratch

@seratch seratch commented Feb 21, 2021

Copy link
Copy Markdown
Contributor

This pull request resolves a bug where different user's user token (xoxp- prefixed token) may exist in context.user_token while context.user_id is consistent with an incoming request. This issue affects only when an app uses an InstallationStore. As this issue can be critical in some situations, I will release a patch version shortly.

Category (place an x in each of the [ ])

  • slack_bolt.App and/or its core components
  • slack_bolt.async_app.AsyncApp and/or its core components
  • Adapters in slack_bolt.adapter
  • Document pages under /docs
  • Others

Requirements (place an x in each [ ])

Please read the Contributing guidelines and Code of Conduct before creating this issue or pull request. By submitting, you are agreeing to those rules.

  • I've read and understood the Contributing Guidelines and have done my best effort to follow them.
  • I've read and agree to the Code of Conduct.
  • I've run ./scripts/install_all_and_run_tests.sh after making the changes.

@seratch seratch added bug Something isn't working area:async area:sync labels Feb 21, 2021
@seratch seratch self-assigned this Feb 21, 2021
@seratch seratch added this to the 1.4.1 milestone Feb 21, 2021
@codecov

codecov Bot commented Feb 21, 2021

Copy link
Copy Markdown

Codecov Report

Merging #244 (8cff029) into main (a69abb5) will increase coverage by 0.00%.
The diff coverage is 100.00%.

Impacted file tree graph

@@           Coverage Diff           @@
##             main     #244   +/-   ##
=======================================
  Coverage   91.36%   91.36%           
=======================================
  Files         160      160           
  Lines        4967     4971    +4     
=======================================
+ Hits         4538     4542    +4     
  Misses        429      429           
Impacted Files Coverage Δ
slack_bolt/authorization/async_authorize.py 86.95% <100.00%> (+0.28%) ⬆️
slack_bolt/authorization/authorize.py 86.95% <100.00%> (+0.28%) ⬆️

Continue to review full report at Codecov.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update a69abb5...8cff029. Read the comment docs.

@seratch
seratch merged commit 32f47c4 into slackapi:main Feb 21, 2021
@seratch
seratch deleted the user-token-in-context branch February 21, 2021 03:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:async area:sync bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant