-
Notifications
You must be signed in to change notification settings - Fork 170
Expand file tree
/
Copy pathslack_controller.rb
More file actions
54 lines (43 loc) · 1.89 KB
/
Copy pathslack_controller.rb
File metadata and controls
54 lines (43 loc) · 1.89 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
class SlackController < ApplicationController
skip_before_action :verify_authenticity_token
before_action :verify_slack_request
# allow usage of short_time_simple
include ApplicationHelper
helper_method :short_time_simple
# Handle slack commands
def create
if params_hash[:command].to_s.downcase.include?("sailorslog")
user = User.find_by(slack_uid: params_hash[:user_id])
unless user
render json: {
response_type: "ephemeral",
text: "Darn it! I could not find a hackatime account linked with your slack account! please sign up and link your slack account at https://hackatime.hackclub.com/my/settings"
}
return
end
end
SlackCommand::SailorsLogJob.perform_later(params_hash)
end
private
def params_hash
@params_hash ||= params.permit(:command, :text, :response_url, :user_id, :team_id, :team_domain,
:channel_id, :channel_name, :user_name, :trigger_word).to_h
end
def verify_slack_request
return true if Rails.env.development?
signing_secret = ENV["SAILORS_LOG_SLACK_SIGNING_SECRET"]
if signing_secret.blank?
# we will never hit this in prod but this is good prep for `config.saas_mode`
Rails.logger.error "[SlackController] SAILORS_LOG_SLACK_SIGNING_SECRET is not configured"
return head(:unauthorized)
end
timestamp = request.headers["X-Slack-Request-Timestamp"]
received_signature = request.headers["X-Slack-Signature"]
if timestamp.blank? || received_signature.blank? || (Time.now.to_i - timestamp.to_i).abs > 300
return head(:unauthorized)
end
sig_basestring = "v0:#{timestamp}:#{request.raw_post}"
computed_signature = "v0=" + OpenSSL::HMAC.hexdigest("SHA256", signing_secret, sig_basestring)
head(:unauthorized) unless ActiveSupport::SecurityUtils.secure_compare(received_signature, computed_signature)
end
end