Repository navigation
Handling expired access token for API calls #510
Description
Activity
- changed the title
[-]Handing expired access token for API calls[/-][+]Handling expired access token for API calls[/+]on Nov 1, 2021 - when the access token will be refreshed, will it happen if the user event triggers an api call and the user_token/bot_token gets updated if the token have already expired
The token rotation refresh is performed at the level of the authorization of incoming requests from Slack. This check is performed as part of the middleware that runs on all incoming requests. Here’s a link to some implementation detail for refreshing bot_token for example if you’re looking into this more in-depth.
- Does every api call made using slack_bolt checks for the token validity before hitting the endpoint.
As mentioned above, token rotation is performed on authorize of incoming requests from Slack. If you're having a specific issue, feel free to create a separate issue describing the behavior.
Hope that clarifies things for you.
- addedquestionFurther information is requestedFurther information is requested
on Nov 1, 2021 Hi @srajiang,
Thank you for your response. It helped.
I have one query on the token_rotation_expiration_minutes variable in auth_settings, even If I configure this while creating the App.App( signing_secret=signing_secret, oauth_settings=OAuthSettings( client_id=client_id, client_secret=client_secret, install_page_rendering_enabled=False, scopes=["app_mentions:read", "commands", "chat:write", "im:history"], user_scopes=["users:read", "users:read.email"], # If you want to test token rotation, enabling the following line will make it easy token_rotation_expiration_minutes=100, installation_store=DjangoInstallationStore( client_id=client_id, logger=logger, ), state_store=DjangoOAuthStateStore( expiration_seconds=120, logger=logger, ), ), )I am still getting the expires_in value as 43200(12hrs). Do I need to do anything else to configure the expiry time.
@mohan-raheja
As theexpires_incolumn value in database is calculated using the returned data in oauth.v2.access API response, it's not possible (and not recommended even with your custom logic) to modify the value.Instead, if you would like to fasten the rotation timing, you can set the
token_rotation_expiration_minutesoption to a long-enough value (say, 24 hours). I know that naming is a bit confusing but the value is "minutes before expiration": https://github.com/slackapi/bolt-python/blob/v1.9.4/slack_bolt/authorization/authorize.py#L208Thus, if you set a value greater than 8 hours, your app rotates the token value for every single incoming request.
I hope this helps.
Hi @seratch, Got it!
yeah "minutes_before_expiration" conveys the purpose.
Thank you for your help.I am closing this issue.
Hi, I am reopening this issue with a question on refresh token validity
I have enabled token_rotation, I got an error as the refresh token is invalid when making an slack api call, I understand that the access token expires and we need to generate new access token using the refresh token, but here I got an issue with the refresh token, does the refresh token expire ?
@mohan-raheja
When you rotate a bot/user token, your app receives new tokens for both access token and refresh token.Bolt does the update and saves the refreshed pair for you: https://github.com/slackapi/bolt-python/blob/v1.10.0/slack_bolt/authorization/authorize.py#L200-L215
If you have your own code to rotate tokens, your app should do the same.
I have enabled the token rotation in app config page, from the bolt documentation I have found "Bolt for Python supports and will handle token rotation automatically so long as the built-in OAuth functionality is used." My question on this is