slackapi / slackapi/bolt-python

Enhancement: Assistant should inherit global middleware for security and consistency

Đang mở
#1,346 2 bình luận 0 reaction 1 người được giao Xem trên GitHub

@hello-ashleyintech đang làm issue này rồi.

Từ ngày 6/8/2025.

auto-triage-skip enhancement
Ngôn ngữ chính
Python
Star
1.3k
Fork
288
Merge trung bình
1 ngày 8 giờ
Pull request đã merge (30 ngày)
10

Mô tả

Problem

Assistant handlers bypass global middleware entirely, creating a significant security gap and architectural inconsistency. Assistant events, assistant.user_message, assistant.thread_started etc. skip critical middleware that regular events receive, including:

  • SSL certificate verification
  • Request signature verification
  • Authorization middleware
  • URL verification
  • Custom middleware

This forces developers to manually implement security checks in each assistant handler, which is error-prone and violates the principle of secure-by-default design.

# These handlers get full middleware protection:
@app.event("app_mention")
async def handle_mention(event, say, context):
    # Already authenticated via middleware
    pass

# These handlers bypass ALL middleware (security vulnerability):

@assistant.user_message
async def handle_message(event, say, context):
    # No authentication, no SSL check, no signature verification!
    pass

Developer Experience: Developers must remember to add security manually to every assistant handler:

# Current: Manual security in every handler (error-prone)
@assistant.user_message(middleware=[auth_middleware, ssl_middleware])
async def handle_message(event, say, context):
    pass
Category
  • slack_bolt.App and/or its core components
  • slack_bolt.async_app.AsyncApp and/or its core components
  • Adapters in slack_bolt.adapter
  • Others
Requirements

Proposed Solution
Enhance Assistant/AsyncAssistant to automatically inherit the app's global middleware when handlers are registered. This would:

  1. Maintain backwards compatibility - existing explicit middleware still works
  2. Provide opt-in enhancement - controlled via auto_inherit_app_middleware=True parameter
  3. Apply middleware in correct order - app middleware first, then handler-specific middleware
Benefits
  1. Security by default - Assistant events get same protection as regular events
  2. Architectural consistency - All Slack events treated uniformly
  3. Developer productivity - No more manual security boilerplate
  4. Backwards compatible - Existing code continues working unchanged
  5. Performance neutral - Middleware already exists, just applied consistently

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.