Repository navigation
Make cookies extraction on AWS Lambda compatible with its format v1.0 - #379
Conversation
|
Hi @tattee, thank you very much for takin the time to make this pull request. Before my code review, I have two things to ask:
Even if your changes are great, we are unable to merge them without signed CLA. I would appreciate it if you could understand this. |
|
HI @tattee, thanks for taking the time to make this pull request. Can you check this issue #332 (comment) ? This project supports only AWS lambda event payload format v2.0 as the HTTP API is the currently recommended way plus it is the greatest fit for running Bolt apps. With that being said, we are open to support format v1.0 as well. If you have more time, could you help us add the support by making the following additional work?
|
112257a to
8310008
Compare
405d5bd to
06711f9
Compare
|
@seratch thank you for telling me the issue #322. I understand that this is not ideal... |
|
@tattee Thanks for taking the time to work on it. Ideally, we should have some tests for My previous comment might not be clear enough but the tests we need this time is the same patterns with the ones for the already supported AWS payload format. Considering the number of existing test methods, adding the same to the same file may not be great. How about having |
|
@seratch In my understanding, the format of the events in test_oauth are v2.0 (first one) and v1.0 (second one) respectively, and the processes in the tests are almost same. If my concern does not make sense, please ignore it. |
|
Ah thanks. I totally forgot these tests already support both formats. So, this means that only cookies extraction is not yet fully supported for both formats, right? In the case, trying to check |
|
|
||
| @mock_lambda | ||
| def test_oauth_redirect(self): | ||
| app = App( |
There was a problem hiding this comment.
If we have a mock state_store, which returns a fixed value "uuid4-value", the test can be better. Can you check this?
There was a problem hiding this comment.
Sorry, I could not understand where to check.
I would be grateful if you could give me specific instructions.
(I'm not familiar with @mock_lambda in moto, and you said about it??)
There was a problem hiding this comment.
@tattee Thanks for asking this! I thought that we need to implement state_store with issue/consume methods (returning a fixed value "uuid4-value" means having the issue method). But, for this test, having only consume method is required. Thus, the following diff should work for you!
diff --git a/tests/adapter_tests/aws/test_aws_lambda.py b/tests/adapter_tests/aws/test_aws_lambda.py
index b92300e..1b0166c 100644
--- a/tests/adapter_tests/aws/test_aws_lambda.py
+++ b/tests/adapter_tests/aws/test_aws_lambda.py
@@ -3,6 +3,7 @@ from time import time
from urllib.parse import quote
from moto import mock_lambda
+from slack_sdk.oauth import OAuthStateStore
from slack_sdk.signature import SignatureVerifier
from slack_sdk.web import WebClient
@@ -321,6 +322,10 @@ class TestAWSLambda:
@mock_lambda
def test_oauth_redirect(self):
+ class TestStateStore(OAuthStateStore):
+ def consume(self, state: str) -> bool:
+ return state == "uuid4-value"
+
app = App(
client=self.web_client,
signing_secret=self.signing_secret,
@@ -328,6 +333,7 @@ class TestAWSLambda:
client_id="111.111",
client_secret="xxx",
scopes=["chat:write", "commands"],
+ state_store=TestStateStore(),
),
)
@@ -340,7 +346,7 @@ class TestAWSLambda:
"isBase64Encoded": False,
}
response = SlackRequestHandler(app).handle(event, self.context)
- assert response["statusCode"] == 401
+ assert response["statusCode"] == 200
assert response["headers"]["content-type"] == "text/html; charset=utf-8"
assert response.get("body") is not None
@@ -353,6 +359,6 @@ class TestAWSLambda:
"isBase64Encoded": False,
}
response = SlackRequestHandler(app).handle(event, self.context)
- assert response["statusCode"] == 401
+ assert response["statusCode"] == 200
assert response["headers"]["content-type"] == "text/html; charset=utf-8"
assert response.get("body") is not None
tattee
left a comment
There was a problem hiding this comment.
I checked your comments, and left replies.
Best regards,
|
|
||
| @mock_lambda | ||
| def test_oauth_redirect(self): | ||
| app = App( |
There was a problem hiding this comment.
Sorry, I could not understand where to check.
I would be grateful if you could give me specific instructions.
(I'm not familiar with @mock_lambda in moto, and you said about it??)
Changed the way to judge payload format Co-authored-by: Kazuhiro Sera <seratch@gmail.com>
seratch
left a comment
There was a problem hiding this comment.
Thanks for updating this PR. Once the test is improved, we can merge your PR 👍
|
|
||
| @mock_lambda | ||
| def test_oauth_redirect(self): | ||
| app = App( |
There was a problem hiding this comment.
@tattee Thanks for asking this! I thought that we need to implement state_store with issue/consume methods (returning a fixed value "uuid4-value" means having the issue method). But, for this test, having only consume method is required. Thus, the following diff should work for you!
diff --git a/tests/adapter_tests/aws/test_aws_lambda.py b/tests/adapter_tests/aws/test_aws_lambda.py
index b92300e..1b0166c 100644
--- a/tests/adapter_tests/aws/test_aws_lambda.py
+++ b/tests/adapter_tests/aws/test_aws_lambda.py
@@ -3,6 +3,7 @@ from time import time
from urllib.parse import quote
from moto import mock_lambda
+from slack_sdk.oauth import OAuthStateStore
from slack_sdk.signature import SignatureVerifier
from slack_sdk.web import WebClient
@@ -321,6 +322,10 @@ class TestAWSLambda:
@mock_lambda
def test_oauth_redirect(self):
+ class TestStateStore(OAuthStateStore):
+ def consume(self, state: str) -> bool:
+ return state == "uuid4-value"
+
app = App(
client=self.web_client,
signing_secret=self.signing_secret,
@@ -328,6 +333,7 @@ class TestAWSLambda:
client_id="111.111",
client_secret="xxx",
scopes=["chat:write", "commands"],
+ state_store=TestStateStore(),
),
)
@@ -340,7 +346,7 @@ class TestAWSLambda:
"isBase64Encoded": False,
}
response = SlackRequestHandler(app).handle(event, self.context)
- assert response["statusCode"] == 401
+ assert response["statusCode"] == 200
assert response["headers"]["content-type"] == "text/html; charset=utf-8"
assert response.get("body") is not None
@@ -353,6 +359,6 @@ class TestAWSLambda:
"isBase64Encoded": False,
}
response = SlackRequestHandler(app).handle(event, self.context)
- assert response["statusCode"] == 401
+ assert response["statusCode"] == 200
assert response["headers"]["content-type"] == "text/html; charset=utf-8"
assert response.get("body") is not None|
It's a nice idea to add TestStateStore for consume method. |
|
@tattee Thanks for the comment! You can run pytest for this project this way. Also, there is a tiny script too. |
Codecov Report
@@ Coverage Diff @@
## main #379 +/- ##
==========================================
+ Coverage 91.55% 91.59% +0.04%
==========================================
Files 167 167
Lines 5375 5378 +3
==========================================
+ Hits 4921 4926 +5
+ Misses 454 452 -2
Continue to review full report at Codecov.
|
|
Thank you for telling me how to execute test scripts. |
|
this is great- thank you! i realize now that this closes the loop on this exchange we had a while ago around v1 vs v2 support, glad to see this PR & release |
|
@seratch I too deployed a Bolt-python app to AWS Lambda, integrated with REST (format v1.0) based API GW. In the process of the verification of oauth redirect, the app could not be installed properly. Taking a look at the CloudWatch logs I could see the multivalueheader in the request had the key "cookie" instead of "Cookie" as is expected by "to_bolt_request". if cookies is None or len(cookies) == 0:
# In the case of format v1
multiValueHeaders = event.get("multiValueHeaders", {})
cookies = multiValueHeaders.get("Cookie", [])After modifying the following line to account for lower case "cookie", everything worked fine: cookies = multiValueHeaders.get("cookie", [])Recommend this "get" operation be modified to be case-insensitive as it is blocking oauth install at the moment. |
|
@naveensan1 Thanks for sharing this! This makes sense 👍 If you have a chance, would you mind sending a pull request to fix this? |
I tried to deploy a slack bolt application on AWS Lambda with SQLAlchemy.
In the process of the verification of oauth redirect, the app could not be installed properly.
I found that the slack request handler could not extract cookie from the lambda event.
So, I modified the to_bolt_request to meet the format of the lambda event.