github slack-go/slack v0.30.1

3 hours ago

Important

This is a security release. Upgrade if your app passes file URLs from messages or events to GetFile. Full details are in CHANGELOG.md.

Security

GetFile, GetFileContext and UploadToURL now send the token only to https URLs on slack.com, slack-gov.com and their subdomains, and to the host set with OptionAPIURL. Any other URL returns an error before a request is made.

The url_private of a remote or external file (File.IsExternal) points outside Slack, so GetFile(file.URLPrivate) sent the token to that host. See GHSA-3q3v-34v2-g88f.

A test that points GetFile at an httptest server must also pass that server to OptionAPIURL:

api := slack.New("xoxb-test", slack.OptionAPIURL(ts.URL+"/"))
err := api.GetFile(ts.URL+"/files-pri/T1-F1/a.txt", &buf)

Thanks to @Lordseriouspig (what a handle... 😂) for the report.

Full Changelog: v0.30.0...v0.30.1

Don't miss a new slack release

NewReleases is sending notifications on new releases.