Skip to content

Handling expired access token for API calls #510

Description

@mohan-raheja

I have enabled the token rotation in app config page, from the bolt documentation I have found "Bolt for Python supports and will handle token rotation automatically so long as the built-in OAuth functionality is used." My question on this is

  1. when the access token will be refreshed, will it happen if the user event triggers an api call and the user_token/bot_token gets updated if the token have already expired
  2. Does every api call made using slack_bolt checks for the token validity before hitting the endpoint.

Activity

  1. changed the title [-]Handing expired access token for API calls[/-] [+]Handling expired access token for API calls[/+] on Nov 1, 2021
  2. srajiang commented on Nov 1, 2021

    @srajiang
    Contributor

    Hi @mohan-raheja

    1. when the access token will be refreshed, will it happen if the user event triggers an api call and the user_token/bot_token gets updated if the token have already expired

    The token rotation refresh is performed at the level of the authorization of incoming requests from Slack. This check is performed as part of the middleware that runs on all incoming requests. Here’s a link to some implementation detail for refreshing bot_token for example if you’re looking into this more in-depth.

    1. Does every api call made using slack_bolt checks for the token validity before hitting the endpoint.

    As mentioned above, token rotation is performed on authorize of incoming requests from Slack. If you're having a specific issue, feel free to create a separate issue describing the behavior.

    Hope that clarifies things for you.

  3. mohan-raheja commented on Nov 3, 2021

    @mohan-raheja
    Author

    Hi @srajiang,
    Thank you for your response. It helped.
    I have one query on the token_rotation_expiration_minutes variable in auth_settings, even If I configure this while creating the App.

    App(
        signing_secret=signing_secret,
        oauth_settings=OAuthSettings(
            client_id=client_id,
            client_secret=client_secret,
            install_page_rendering_enabled=False,
            scopes=["app_mentions:read", "commands", "chat:write", "im:history"],
            user_scopes=["users:read", "users:read.email"],
            # If you want to test token rotation, enabling the following line will make it easy
            token_rotation_expiration_minutes=100,
            installation_store=DjangoInstallationStore(
                client_id=client_id,
                logger=logger,
            ),
            state_store=DjangoOAuthStateStore(
                expiration_seconds=120,
                logger=logger,
            ),
        ),
    )
    

    I am still getting the expires_in value as 43200(12hrs). Do I need to do anything else to configure the expiry time.

  4. seratch commented on Nov 3, 2021

    @seratch
    Contributor

    @mohan-raheja
    As the expires_in column value in database is calculated using the returned data in oauth.v2.access API response, it's not possible (and not recommended even with your custom logic) to modify the value.

    Instead, if you would like to fasten the rotation timing, you can set the token_rotation_expiration_minutes option to a long-enough value (say, 24 hours). I know that naming is a bit confusing but the value is "minutes before expiration": https://github.com/slackapi/bolt-python/blob/v1.9.4/slack_bolt/authorization/authorize.py#L208

    Thus, if you set a value greater than 8 hours, your app rotates the token value for every single incoming request.

    I hope this helps.

  5. mohan-raheja commented on Nov 3, 2021

    @mohan-raheja
    Author

    Hi @seratch, Got it!
    yeah "minutes_before_expiration" conveys the purpose.
    Thank you for your help.

    I am closing this issue.

  6. mohan-raheja commented on Dec 12, 2021

    @mohan-raheja
    Author

    Hi, I am reopening this issue with a question on refresh token validity

    I have enabled token_rotation, I got an error as the refresh token is invalid when making an slack api call, I understand that the access token expires and we need to generate new access token using the refresh token, but here I got an issue with the refresh token, does the refresh token expire ?

  7. seratch commented on Dec 12, 2021

    @seratch
    Contributor

    @mohan-raheja
    When you rotate a bot/user token, your app receives new tokens for both access token and refresh token.

    Bolt does the update and saves the refreshed pair for you: https://github.com/slackapi/bolt-python/blob/v1.10.0/slack_bolt/authorization/authorize.py#L200-L215

    If you have your own code to rotate tokens, your app should do the same.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    questionFurther information is requested

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions