Important
This is a security release. Upgrade if your app passes file URLs from messages or events to GetFile. Full details are in CHANGELOG.md.
Security
GetFile, GetFileContext and UploadToURL now send the token only to https URLs on slack.com, slack-gov.com and their subdomains, and to the host set with OptionAPIURL. Any other URL returns an error before a request is made.
The url_private of a remote or external file (File.IsExternal) points outside Slack, so GetFile(file.URLPrivate) sent the token to that host. See GHSA-3q3v-34v2-g88f.
A test that points GetFile at an httptest server must also pass that server to OptionAPIURL:
api := slack.New("xoxb-test", slack.OptionAPIURL(ts.URL+"/"))
err := api.GetFile(ts.URL+"/files-pri/T1-F1/a.txt", &buf)Thanks to @Lordseriouspig (what a handle... 😂) for the report.
Full Changelog: v0.30.0...v0.30.1