Closed AbstractBeliefs closed 7 years ago
Anyone who discovers where you're hosting the gateway can trigger messages with spoofed sender/content. Might be worth looking at ways to verify the endpoint was hit by Slack rather than anyone else.
Repro on request, let me know what suits you.
Thanks. I'll add some code to verify the token that Slack sends along with the web hook.
Anyone who discovers where you're hosting the gateway can trigger messages with spoofed sender/content. Might be worth looking at ways to verify the endpoint was hit by Slack rather than anyone else.
Repro on request, let me know what suits you.