Files
Paymahn Moghadasian 272558acc5 fix: send Slack tokens as Authorization bearer headers
slack-go's postForm puts the token in an x-www-form-urlencoded `token`
field and sends no Authorization header. Slack accepts either, but a
body-carried credential is invisible to anything that inspects headers:
Sinatra's egress proxy swaps an opaque `sin_` sentinel for the real bot
token on the way out, saw no header to rewrite, passed the sentinel
through verbatim, and every sandbox call came back `invalid_auth`.

Promote the `token` form field to `Authorization: Bearer` in the shared
HTTP client, so every Web API call authenticates the way brokers, MITM
proxies, and audit tooling expect. Content-Length and GetBody are kept
honest so slack-go's retries replay the rewritten body.

Browser-session tokens (`xoxc-`, paired with the `d` cookie) stay in the
body — they are not bearer credentials and the edge API wants them there.
2026-09-11 08:33:19 -05:00
..