bitrise-io/bitrise-webhooks

Check Slack token when receiving POST

Opened this issue · 1 comments

Slack slash commands pass a token so that the receiver can verify that the hook is really called from Slack. In the slash command setup it looks like this:

token

It would be great if we could pass this token as a config variable to the server. The config should be a list of accepted tokens as Slack defines one token per slash command - so one might need more than one.

Hi @ubuntudroid,

Thank you for the feature requests. I don't have control over when or if feature requests will be implemented but I will share this with the team.

for internal ref: https://bitfall.slack.com/archives/CSMPJ7DK2/p1595524336264900.