feat(receivers): expose invalidRequestSignatureHandler on HTTPReceiver (closes #2156) - #3052
Open
aniruddhaadak80 wants to merge 1 commit into
Conversation
closes slackapi#2156) Adds an optional invalidRequestSignatureHandler to HTTPReceiver and ExpressReceiver, mirroring the pattern introduced in AwsLambdaReceiver (slackapi#2154). The handler is invoked when a request fails signature verification, allowing custom logging/metrics before the 401 response is returned.
|
|
Thanks for the contribution! Before we can merge this, we need @aniruddhaadak80 to sign the Salesforce Inc. Contributor License Agreement. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What Problem This Solves
The
invalidRequestSignatureHandleroption was added toAwsLambdaReceiverin PR #2154 but is not available onHTTPReceiver/ExpressReceiver. Issue #2156 requests this same capability for the HTTP-based receivers, useful for adding custom logging, metrics, or alerting when Slack request signatures fail verification.Why This Change Was Made
Users deploying bolt apps with HTTP receivers have no way to hook into the signature verification failure path. They can only see the default warning log. Adding the handler lets users emit custom telemetry, count failures, or trigger alerts.
What Changed
invalidRequestSignatureHandlertoRequestVerificationOptionsinHTTPModuleFunctions.tsverifySlackRequestin a try/catch that invokes the handler (when set) before re-throwing the error so the 401 response still happensinvalidRequestSignatureHandleronHTTPReceiverOptionsinHTTPReceiver.tsparseAndVerifyHTTPRequestReceiverInvalidRequestSignatureHandlerArgsinterface exposesrawBody,signature,requestTimestampSec, andrequestfor use in custom handlersHow Tested
tsc --noEmit)test/unit/middleware/builtin.spec.ts(165,29)is unrelated to this change (it was already modified in the fetchM test/unit/middleware/builtin.spec.ts)Fixes #2156