Files
Paymahn Moghadasian 9c72a44222 fix(provider): classify token kind by source, not prefix
An egress proxy can hand the CLI an opaque sentinel and swap the real
credential onto the wire, so the token value says nothing about the
credential kind. Sniffing `xoxb-`/`xoxp-` prefixes then misread a bot
token as a browser session, which:

  - rebased the standard API onto https://<team>.slack.com/api/
  - routed conversations/users through the edge client (same domain)
  - offered session-only tools (saved items, unreads)

Behind Sinatra's egress proxy every one of those calls was rejected
403 host_not_allowed, since the allowlist only knows slack.com.

tokenKind now derives the kind from which variable supplied the token
(config.Apply exports profile credentials into the same variables) and
only falls back to the prefix. The per-workspace domain is applied to
the standard client for session tokens only — it also silently
overrode GovSlack before.

Verified against a TLS-intercepted fake Slack whose auth.test returns
a team URL: with SLACK_MCP_XOXB_TOKEN=sin_… every request now stays on
slack.com; before the fix conversations.replies and users.info went to
sinatra-dev.slack.com.
2026-09-11 09:10:53 -05:00
..
2026-05-15 00:42:57 +02:00