Skip to content

fix: SslCheck rejected requests with a matching verification token - #1589

Open
sahiljagtap08 wants to merge 1 commit into
slackapi:mainfrom
sahiljagtap08:fix/ssl-check-verification-token
Open

sahiljagtap08 wants to merge 1 commit into
slackapi:mainfrom
sahiljagtap08:fix/ssl-check-verification-token

Conversation

@sahiljagtap08

@sahiljagtap08 sahiljagtap08 commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Summary

When an App or AsyncApp is built with verification_token, the SslCheck middleware got the check backwards:

  • an ssl_check request whose token matched returned 401
  • a request whose token did not match returned 200
  • a request with no token field raised KeyError, which became a 500

The helper returned True on a match, while the caller treated True as the error case. The existing tests never set verification_token, so this was not covered.

Changes in slack_bolt/middleware/ssl_check/:

  • The error response is returned only when a token is configured and the request's token is missing or wrong.
  • The token is read with body.get() so a missing token is rejected instead of crashing.
  • The async middleware inherits the helper, so it gets the same fix with a matching one-line change.

Testing

Added test_ssl_check_with_verification_token to both tests/scenario_tests/test_ssl_check.py and tests/scenario_tests_async/test_ssl_check.py. Each covers a matching token (200), a wrong token (401), and a missing token (401). The sync test fails on main and passes with this change. Ran ./scripts/format.sh, ./scripts/lint.sh, ./scripts/run_mypy.sh, and the ssl_check test files.

Category

  • slack_bolt.App and/or its core components
  • slack_bolt.async_app.AsyncApp and/or its core components
  • Adapters in slack_bolt.adapter
  • Others

Requirements

  • I've read and understood the Contributing Guidelines and have done my best effort to follow them.
  • I've read and agree to the Code of Conduct.
  • I've run ./scripts/install_all_and_run_tests.sh after making the changes.

Fixes #1595

When an App was built with verification_token, the ssl_check middleware
returned 401 for requests whose token matched and 200 for requests
whose token did not. A request without a token field raised KeyError.
The helper returned True on a match while the caller treated True as
an error.

- Return the error response only when the token is missing or wrong
- Use body.get() so a missing token is rejected instead of crashing
- Add sync and async tests covering matching, wrong, and missing tokens

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

SslCheck returns 401 for a matching verification_token and 200 for a wrong one

1 participant