mirror of
https://github.com/paymog/slack-cli.git
synced 2026-09-18 23:43:49 +08:00
272558acc5
slack-go's postForm puts the token in an x-www-form-urlencoded `token` field and sends no Authorization header. Slack accepts either, but a body-carried credential is invisible to anything that inspects headers: Sinatra's egress proxy swaps an opaque `sin_` sentinel for the real bot token on the way out, saw no header to rewrite, passed the sentinel through verbatim, and every sandbox call came back `invalid_auth`. Promote the `token` form field to `Authorization: Bearer` in the shared HTTP client, so every Web API call authenticates the way brokers, MITM proxies, and audit tooling expect. Content-Length and GetBody are kept honest so slack-go's retries replay the rewritten body. Browser-session tokens (`xoxc-`, paired with the `d` cookie) stay in the body — they are not bearer credentials and the edge API wants them there.