Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
34 changes: 22 additions & 12 deletions examples/django/oauth_app/slack_datastores.py
Original file line number Diff line number Diff line change
Expand Up @@ -33,13 +33,9 @@ def save(self, installation: Installation):
i = installation.to_dict()
if is_naive(i["installed_at"]):
i["installed_at"] = make_aware(i["installed_at"])
if i.get("bot_token_expires_at") is not None and is_naive(
i["bot_token_expires_at"]
):
if i.get("bot_token_expires_at") is not None and is_naive(i["bot_token_expires_at"]):
i["bot_token_expires_at"] = make_aware(i["bot_token_expires_at"])
if i.get("user_token_expires_at") is not None and is_naive(
i["user_token_expires_at"]
):
if i.get("user_token_expires_at") is not None and is_naive(i["user_token_expires_at"]):
i["user_token_expires_at"] = make_aware(i["user_token_expires_at"])
i["client_id"] = self.client_id
row_to_update = (
Expand All @@ -62,9 +58,7 @@ def save_bot(self, bot: Bot):
b = bot.to_dict()
if is_naive(b["installed_at"]):
b["installed_at"] = make_aware(b["installed_at"])
if b.get("bot_token_expires_at") is not None and is_naive(
b["bot_token_expires_at"]
):
if b.get("bot_token_expires_at") is not None and is_naive(b["bot_token_expires_at"]):
b["bot_token_expires_at"] = make_aware(b["bot_token_expires_at"])
b["client_id"] = self.client_id

Expand Down Expand Up @@ -145,6 +139,24 @@ def find_installation(

if len(rows) > 0:
i = rows[0]
if user_id is not None:
# Fetch the latest bot token

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I suggest we add a bit more context to this comment to help remind future maintainers about this workaround.

Suggested change
# Fetch the latest bot token
# Above, when fetching applicable installations, we retrieved relevant installations but filtered on matching user ID
# In the case that this app uses both bot and user scopes, we also now fetch installations that match only on team/enterprise ID and contain a bot token
# If any such results are retrieved, we merged them into the user-id-filtered results.
# This is a fix for the situation described in https://github.com/slackapi/bolt-python/issues/664

latest_bot_rows = (
SlackInstallation.objects.filter(client_id=self.client_id)
.exclude(bot_token__isnull=True)
.filter(enterprise_id=e_id)
.filter(team_id=t_id)
.order_by(F("installed_at").desc())[:1]
)
if len(latest_bot_rows) > 0:
b = latest_bot_rows[0]
i.bot_id = b.bot_id
i.bot_user_id = b.bot_user_id
i.bot_scopes = b.bot_scopes
i.bot_token = b.bot_token
i.bot_refresh_token = b.bot_refresh_token
i.bot_token_expires_at = b.bot_token_expires_at

return Installation(
app_id=i.app_id,
enterprise_id=i.enterprise_id,
Expand Down Expand Up @@ -191,9 +203,7 @@ def issue(self) -> str:
return state

def consume(self, state: str) -> bool:
rows = SlackOAuthState.objects.filter(state=state).filter(
expire_at__gte=timezone.now()
)
rows = SlackOAuthState.objects.filter(state=state).filter(expire_at__gte=timezone.now())
if len(rows) > 0:
for row in rows:
row.delete()
Expand Down
4 changes: 3 additions & 1 deletion examples/django/oauth_app/slack_listeners.py
Original file line number Diff line number Diff line change
Expand Up @@ -13,11 +13,12 @@
from .slack_datastores import DjangoInstallationStore, DjangoOAuthStateStore

logger = logging.getLogger(__name__)
client_id, client_secret, signing_secret, scopes = (
client_id, client_secret, signing_secret, scopes, user_scopes = (
os.environ["SLACK_CLIENT_ID"],
os.environ["SLACK_CLIENT_SECRET"],
os.environ["SLACK_SIGNING_SECRET"],
os.environ.get("SLACK_SCOPES", "commands").split(","),
os.environ.get("SLACK_USER_SCOPES", "search:read").split(","),
)

app = App(
Expand All @@ -26,6 +27,7 @@
client_id=client_id,
client_secret=client_secret,
scopes=scopes,
user_scopes=user_scopes,
# If you want to test token rotation, enabling the following line will make it easy
# token_rotation_expiration_minutes=1000000,
installation_store=DjangoInstallationStore(
Expand Down