slackhq / goSDL

goSDL
MIT License
523 stars 83 forks source link

Authentication #13

Closed D-3lf closed 5 years ago

D-3lf commented 6 years ago

Description

Does this application use any type of authentication? If not, how is it being protected at Slack?

What type of issue is this? (place an x in one of the [ ])

Requirements (place an x in each of the [ ])


Bug Report

I do not believe this is a bug. I think there's an implementation at Slack that's not detailed in the project docs.

Reproducible in:

All versions/All OSs

Steps to reproduce:

  1. Deploy app
  2. Access main page

Expected result:

Prior to being able to interact with the application I would need to supply some type of data to verify I'm an authorized user.

Actual result:

App loaded and I was able to use it unchallenged.

Attachments:

janmasarik commented 5 years ago

You can use some simple proxy like https://github.com/bitly/oauth2_proxy