mirror of
https://github.com/paymog/slack-cli.git
synced 2026-09-18 23:43:49 +08:00
9c72a44222
An egress proxy can hand the CLI an opaque sentinel and swap the real credential onto the wire, so the token value says nothing about the credential kind. Sniffing `xoxb-`/`xoxp-` prefixes then misread a bot token as a browser session, which: - rebased the standard API onto https://<team>.slack.com/api/ - routed conversations/users through the edge client (same domain) - offered session-only tools (saved items, unreads) Behind Sinatra's egress proxy every one of those calls was rejected 403 host_not_allowed, since the allowlist only knows slack.com. tokenKind now derives the kind from which variable supplied the token (config.Apply exports profile credentials into the same variables) and only falls back to the prefix. The per-workspace domain is applied to the standard client for session tokens only — it also silently overrode GovSlack before. Verified against a TLS-intercepted fake Slack whose auth.test returns a team URL: with SLACK_MCP_XOXB_TOKEN=sin_… every request now stays on slack.com; before the fix conversations.replies and users.info went to sinatra-dev.slack.com.