Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Slack Conversations API #40

Open
kbetsis opened this issue Apr 27, 2020 · 1 comment
Open

Slack Conversations API #40

kbetsis opened this issue Apr 27, 2020 · 1 comment

Comments

@kbetsis
Copy link

kbetsis commented Apr 27, 2020

Awesome work and really nice options available through the provider list. Everything works with no problems at all.

One comment, which i see making huge difference, security wise.

The SLACK Webhook provider requires the existence of a slack channel.
As you can understand posting a token for a user reset to a channel is like asking for someone to test which user was it through simple brute force.

A better approach would be through the use of Slack's conversation API (https://api.slack.com/methods/conversations.open) which offers the capability to direct message the password request token to the user.

@larrabee
Copy link
Owner

Hello.
Unfortunately we do not use Slack and this functionality is not written by me. If you use Slack and can make the PR with changes, it will be cool.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants