Skip to content

v0.30.1

Latest

Choose a tag to compare

@nlopes nlopes released this 04 Oct 18:43
a015532

Important

This is a security release. Upgrade if your app passes file URLs from messages or events to GetFile. Full details are in CHANGELOG.md.

Security

GetFile, GetFileContext and UploadToURL now send the token only to https URLs on slack.com, slack-gov.com and their subdomains, and to the host set with OptionAPIURL. Any other URL returns an error before a request is made.

The url_private of a remote or external file (File.IsExternal) points outside Slack, so GetFile(file.URLPrivate) sent the token to that host. See GHSA-3q3v-34v2-g88f.

A test that points GetFile at an httptest server must also pass that server to OptionAPIURL:

api := slack.New("xoxb-test", slack.OptionAPIURL(ts.URL+"/"))
err := api.GetFile(ts.URL+"/files-pri/T1-F1/a.txt", &buf)

Thanks to @Lordseriouspig (what a handle... 😂) for the report.

Full Changelog: v0.30.0...v0.30.1