eve
Version:
Filesystem-first framework for durable backend AI agents that run anywhere.
49 lines (48 loc) • 2.18 kB
TypeScript
/**
* Slack inbound-webhook verification.
*
* The native channel replaces `createSlackAdapter`'s built-in HMAC
* check with a self-contained verifier:
*
* 1. If the caller supplied a {@link SlackWebhookVerifier} (e.g.
* Connect's OIDC-based forwarder), delegate to it.
* 2. Otherwise, recompute the Slack v0 HMAC and compare with
* `X-Slack-Signature`. Rejects requests older than five minutes to
* foil replay attacks.
*
* Returns the verified raw body string on success so the caller can
* parse it without re-reading the request stream.
*/
/**
* Caller-supplied inbound webhook verifier. Used as an alternative to
* HMAC verification — e.g. Connect supplies a verifier that
* authenticates Connect-forwarded webhooks with Vercel OIDC instead
* of Slack's signing secret.
*
* Contract (matches the chat SDK's `SlackAdapterConfig.webhookVerifier`):
*
* - **Throw / reject** → the channel responds 401 to Slack.
* - **Return a falsy value** (`null` / `undefined` / `false` / `""` /
* `0`) → the channel responds 401 to Slack. This lets verifiers
* signal rejection without throwing — e.g. Connect's `vercelOidc()`
* returns `null` on a failed OIDC check.
* - **Return a truthy non-string value** → verification accepted.
* - **Return a string** → verification accepted, and the string
* replaces the raw body for downstream parsing. Useful when the
* verifier canonicalizes or substitutes the verified payload.
*/
export type SlackWebhookVerifier = (request: Request, body: string) => unknown | Promise<unknown>;
export interface SlackVerifyOptions {
readonly signingSecret: string | undefined;
readonly webhookVerifier: SlackWebhookVerifier | undefined;
/** Max allowed clock skew, in seconds. Defaults to 5 minutes. */
readonly maxSkewSeconds?: number;
}
/**
* Verifies an inbound Slack webhook and returns its raw body.
*
* Throws when neither a signing secret nor a custom verifier is
* available, when signature/timestamp checks fail, or when the
* caller-supplied verifier rejects.
*/
export declare function verifySlackRequest(request: Request, options: SlackVerifyOptions): Promise<string>;