Skip to content

Commit 611ec65

Browse files
authored
Merge pull request #236 from ManasMadan/feat-implement-slack-command-bot-node
#228 - Basic Hello World Slack Command Bot
2 parents 534298b + fdc6070 commit 611ec65

7 files changed

Lines changed: 308 additions & 0 deletions

File tree

node/slack-command-bot/.gitignore

Lines changed: 130 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,130 @@
1+
# Logs
2+
logs
3+
*.log
4+
npm-debug.log*
5+
yarn-debug.log*
6+
yarn-error.log*
7+
lerna-debug.log*
8+
.pnpm-debug.log*
9+
10+
# Diagnostic reports (https://nodejs.org/api/report.html)
11+
report.[0-9]*.[0-9]*.[0-9]*.[0-9]*.json
12+
13+
# Runtime data
14+
pids
15+
*.pid
16+
*.seed
17+
*.pid.lock
18+
19+
# Directory for instrumented libs generated by jscoverage/JSCover
20+
lib-cov
21+
22+
# Coverage directory used by tools like istanbul
23+
coverage
24+
*.lcov
25+
26+
# nyc test coverage
27+
.nyc_output
28+
29+
# Grunt intermediate storage (https://gruntjs.com/creating-plugins#storing-task-files)
30+
.grunt
31+
32+
# Bower dependency directory (https://bower.io/)
33+
bower_components
34+
35+
# node-waf configuration
36+
.lock-wscript
37+
38+
# Compiled binary addons (https://nodejs.org/api/addons.html)
39+
build/Release
40+
41+
# Dependency directories
42+
node_modules/
43+
jspm_packages/
44+
45+
# Snowpack dependency directory (https://snowpack.dev/)
46+
web_modules/
47+
48+
# TypeScript cache
49+
*.tsbuildinfo
50+
51+
# Optional npm cache directory
52+
.npm
53+
54+
# Optional eslint cache
55+
.eslintcache
56+
57+
# Optional stylelint cache
58+
.stylelintcache
59+
60+
# Microbundle cache
61+
.rpt2_cache/
62+
.rts2_cache_cjs/
63+
.rts2_cache_es/
64+
.rts2_cache_umd/
65+
66+
# Optional REPL history
67+
.node_repl_history
68+
69+
# Output of 'npm pack'
70+
*.tgz
71+
72+
# Yarn Integrity file
73+
.yarn-integrity
74+
75+
# dotenv environment variable files
76+
.env
77+
.env.development.local
78+
.env.test.local
79+
.env.production.local
80+
.env.local
81+
82+
# parcel-bundler cache (https://parceljs.org/)
83+
.cache
84+
.parcel-cache
85+
86+
# Next.js build output
87+
.next
88+
out
89+
90+
# Nuxt.js build / generate output
91+
.nuxt
92+
dist
93+
94+
# Gatsby files
95+
.cache/
96+
# Comment in the public line in if your project uses Gatsby and not Next.js
97+
# https://nextjs.org/blog/next-9-1#public-directory-support
98+
# public
99+
100+
# vuepress build output
101+
.vuepress/dist
102+
103+
# vuepress v2.x temp and cache directory
104+
.temp
105+
.cache
106+
107+
# Docusaurus cache and generated files
108+
.docusaurus
109+
110+
# Serverless directories
111+
.serverless/
112+
113+
# FuseBox cache
114+
.fusebox/
115+
116+
# DynamoDB Local files
117+
.dynamodb/
118+
119+
# TernJS port file
120+
.tern-port
121+
122+
# Stores VSCode versions used for testing VSCode extensions
123+
.vscode-test
124+
125+
# yarn v2
126+
.yarn/cache
127+
.yarn/unplugged
128+
.yarn/build-state.yml
129+
.yarn/install-state.gz
130+
.pnp.*
Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
{
2+
"trailingComma": "es5",
3+
"tabWidth": 2,
4+
"semi": true,
5+
"singleQuote": true
6+
}

node/slack-command-bot/README.md

Lines changed: 56 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,56 @@
1+
# 🤖 Node.js Slack Command Bot Function
2+
3+
Simple command bot using Slack API
4+
5+
## 🧰 Usage
6+
7+
### POST /
8+
9+
A endpoint for you slack command that returns a hello world! message as response.
10+
11+
#### Parameters
12+
13+
| Name | Description | Location | Type | Sample Value |
14+
| ------------------------- | -------------------------------- | -------- | ------ | ----------------------------------------------------------------------------------------- |
15+
| x-slack-signature | Signature of the request payload | Header | string | `v0=a...3` |
16+
| x-slack-request-timestamp | Timestamp of the request payload | Header | string | `1531420618` |
17+
| JSON Body | Request payload | Body | Object | See [Slack docs](https://api.slack.com/interactivity/slash-commands#app_command_handling) |
18+
19+
**Response**
20+
21+
Sample `200` Response:
22+
23+
```text
24+
Hello, World!
25+
```
26+
27+
Sample `400` Response:
28+
29+
```json
30+
{
31+
"ok": false,
32+
"error": "Missing required fields: x-slack-signature"
33+
}
34+
```
35+
36+
## ⚙️ Configuration
37+
38+
| Setting | Value |
39+
| ----------------- | ------------- |
40+
| Runtime | Node (18.0) |
41+
| Entrypoint | `src/main.js` |
42+
| Build Commands | `npm install` |
43+
| Permissions | `any` |
44+
| Timeout (Seconds) | 15 |
45+
46+
## 🔒 Environment Variables
47+
48+
### SLACK_SIGNING_SECRET
49+
50+
Signing secret of you slack app.
51+
52+
| Question | Answer |
53+
| ------------- | ---------------------------------------------------------------------------------- |
54+
| Required | Yes |
55+
| Sample Value | `b33...156` |
56+
| Documentation | [Slack Docs](https://api.slack.com/interactivity/slash-commands#creating_commands) |

node/slack-command-bot/package-lock.json

Lines changed: 39 additions & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,16 @@
1+
{
2+
"name": "slack-command-bot",
3+
"version": "1.0.0",
4+
"description": "",
5+
"main": "src/main.js",
6+
"type": "module",
7+
"scripts": {
8+
"format": "prettier --write ."
9+
},
10+
"dependencies": {
11+
"crypto": "^1.0.1"
12+
},
13+
"devDependencies": {
14+
"prettier": "^3.0.0"
15+
}
16+
}

node/slack-command-bot/src/main.js

Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,19 @@
1+
import { throwIfMissing, throwIfRequestNotValid } from './utils.js';
2+
3+
export default async ({ req, res, log, error }) => {
4+
throwIfMissing(process.env, ['SLACK_SIGNING_SECRET']);
5+
6+
try {
7+
throwIfMissing(req.headers, [
8+
'x-slack-request-timestamp',
9+
'x-slack-signature',
10+
]);
11+
throwIfRequestNotValid(req);
12+
} catch (err) {
13+
error(err.message);
14+
return res.send({ ok: false, error: err.message }, 400);
15+
}
16+
17+
log('Valid Request');
18+
return res.send('Hello World!');
19+
};
Lines changed: 42 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,42 @@
1+
import crypto from 'crypto';
2+
3+
/**
4+
* Throws an error if any of the keys are missing from the object
5+
* @param {*} obj
6+
* @param {string[]} keys
7+
* @throws {Error}
8+
*/
9+
export function throwIfMissing(obj, keys) {
10+
const missing = [];
11+
for (let key of keys) {
12+
if (!(key in obj) || !obj[key]) {
13+
missing.push(key);
14+
}
15+
}
16+
if (missing.length > 0) {
17+
throw new Error(`Missing required fields: ${missing.join(', ')}`);
18+
}
19+
}
20+
21+
/**
22+
* Throws an error if incoming request is not valid
23+
* @param {*} req
24+
* @throws {Error}
25+
*/
26+
export function throwIfRequestNotValid(req) {
27+
const timestamp = req.headers['x-slack-request-timestamp'];
28+
const signature = req.headers['x-slack-signature'];
29+
30+
if (Math.abs(Date.now() / 1000 - timestamp) > 60 * 5) {
31+
throw new Error('Invalid request: replay attack');
32+
}
33+
34+
const signatureBaseString = `v0:${timestamp}:${req.bodyRaw}`;
35+
const hmac = crypto.createHmac('sha256', process.env['SLACK_SIGNING_SECRET']);
36+
hmac.update(signatureBaseString);
37+
38+
const expectedSignature = `v0=${hmac.digest('hex')}`;
39+
if (expectedSignature !== signature) {
40+
throw new Error('Invalid request: incorrect signature');
41+
}
42+
}

0 commit comments

Comments
 (0)