slackapi / slackapi/bolt-python

Enhancement: Assistant should inherit global middleware for security and consistency

未关闭
#1,346 2 条评论 0 个 reaction 已指派 1 人 在 GitHub 查看

@hello-ashleyintech 已经在做这个了。

开始于 2025年8月6日。

auto-triage-skip enhancement
主要语言
Python
星标
1.3k
派生
288
平均合并
1 天 8 小时
30 天内合并 PR
10

描述

Problem

Assistant handlers bypass global middleware entirely, creating a significant security gap and architectural inconsistency. Assistant events, assistant.user_message, assistant.thread_started etc. skip critical middleware that regular events receive, including:

  • SSL certificate verification
  • Request signature verification
  • Authorization middleware
  • URL verification
  • Custom middleware

This forces developers to manually implement security checks in each assistant handler, which is error-prone and violates the principle of secure-by-default design.

# These handlers get full middleware protection:
@app.event("app_mention")
async def handle_mention(event, say, context):
    # Already authenticated via middleware
    pass

# These handlers bypass ALL middleware (security vulnerability):

@assistant.user_message
async def handle_message(event, say, context):
    # No authentication, no SSL check, no signature verification!
    pass

Developer Experience: Developers must remember to add security manually to every assistant handler:

# Current: Manual security in every handler (error-prone)
@assistant.user_message(middleware=[auth_middleware, ssl_middleware])
async def handle_message(event, say, context):
    pass
Category
  • slack_bolt.App and/or its core components
  • slack_bolt.async_app.AsyncApp and/or its core components
  • Adapters in slack_bolt.adapter
  • Others
Requirements

Proposed Solution
Enhance Assistant/AsyncAssistant to automatically inherit the app's global middleware when handlers are registered. This would:

  1. Maintain backwards compatibility - existing explicit middleware still works
  2. Provide opt-in enhancement - controlled via auto_inherit_app_middleware=True parameter
  3. Apply middleware in correct order - app middleware first, then handler-specific middleware
Benefits
  1. Security by default - Assistant events get same protection as regular events
  2. Architectural consistency - All Slack events treated uniformly
  3. Developer productivity - No more manual security boilerplate
  4. Backwards compatible - Existing code continues working unchanged
  5. Performance neutral - Middleware already exists, just applied consistently

贡献指南

打开贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。