fix(slack): scope Socket Mode app token per profile - #59869
Closed
kohoj wants to merge 1 commit into
Closed
Conversation
Contributor
|
Merged via PR #65629 — your commit was cherry-picked onto current main with your authorship preserved in git log (rebase merge). Your scope-authoritative |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Fixes #59739.
In multiplex gateway mode, each profile gets its own secret scope, but the Slack adapter still read
SLACK_APP_TOKENfrom processos.environwhen opening Socket Mode. That lets secondary profiles authenticate their websocket with the default profile's app-level token while their bot token is correctly profile-scoped, so the adapter logs as connected but Slack delivers the secondary app's events to no gateway connection.Root Cause
SlackAdapter.connect()used the scopedPlatformConfig.tokenfor the bot token but bypassedagent.secret_scopefor the app token:In a multiplexer, process env can hold another profile's secrets by design, and
_profile_runtime_scope()installs the active profile's.envintoget_secret()instead.Fix
Resolve the Socket Mode app token through
get_secret("SLACK_APP_TOKEN"). This preserves legacy single-profile behavior becauseget_secret()falls back toos.environwhen multiplexing is inactive, while making the active profile scope authoritative when multiplexing is on.Tests
scripts/run_tests.sh tests/gateway/test_slack.py -q$HOME/.hermes/hermes-agent/venv/bin/python -m ruff check plugins/platforms/slack/adapter.py tests/gateway/test_slack.py