-from flask import current_app
-from slack import WebClient
-from slack.signature import SignatureVerifier
+import hashlib
+import hmac
import os
-import requests
-slack_signing_secret = os.environ['SLACK_SIGNING_SECRET']
-slack_bot_token = os.environ['SLACK_BOT_TOKEN']
+slack_signing_secret = bytes(os.environ['SLACK_SIGNING_SECRET'], 'utf-8')
-signature_verifier = SignatureVerifier(slack_signing_secret)
-slack_client = WebClient(slack_bot_token)
+def slack_is_valid_request(slack_signature, timestamp, body):
+ """Returns True if the timestamp and body correspond to signature.
-def slack_is_valid_request(request):
- """Returns true if request actually came from Slack.
+ This implements the Slack signature verification using the slack
+ signing secret (obtained via an SSM parameter in code above)."""
- By means of checking the requests signature together with the slack
- signing key.
+ content = "v0:{}:{}".format(timestamp, body).encode('utf-8')
- Note: If flask is in debug mode, this function will always return true."""
+ signature = 'v0=' + hmac.new(slack_signing_secret,
+ content,
+ hashlib.sha256).hexdigest()
- if current_app.debug:
+ if hmac.compare_digest(signature, slack_signature):
return True
-
- data = request.get_data()
- headers = request.headers
-
- return signature_verifier.is_valid_request(data, headers)
-
-def slack_send_reply(request, text):
- """Send a Slack message as a reply to a specified request.
-
- If the request is associated with a direct message, the reply is
- made by using the "response_url" from the request. Otherwise, the
- reply will be sent to the channel associated with the request.
-
- Note: If flask is in debug mode, this function will just print the
- text to stdout."""
-
- app = current_app
- channel_name = request.form.get('channel_name')
- response_url = request.form.get('response_url')
- channel = request.form.get('channel_id')
-
- if (app.debug):
- print("Sending message to channel '{}': {}".format(channel, text))
- return
-
- if (channel_name == "directmessage"):
- resp = requests.post(response_url,
- json = {"text": text},
- headers = {"Content-type": "application/json"})
- if (resp.status_code != 200):
- app.logger.error("Error posting request to Slack: " + resp.text)
else:
- slack_send_message(channel, text)
-
-def slack_send_message(channel, text):
- """Send a Slack message to a specified channel."""
-
- slack_client.chat_postMessage(channel=channel, text=text)
+ print("Bad signature: {} != {}".format(signature, slack_signature))
+ return False