Is it a problem that api test returns the token?
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 30/100
Research direction
Review the API test shown in the attached screenshot and trace what token it returns and who can access it. Determine the intended security behavior and identify the relevant test or implementation entry point; done should include a confirmed decision on whether the exposure is a vulnerability and a clearly scoped change or documentation outcome.
Written by the indexing model from the issue text.
Description
This means anyone who has bot access can get its token.
- Dominant language
- Ruby
- Stars
- 18
- Forks
- 1
- PR merge metrics
- No merged PRs in 30d
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from slack-ruby/slack-api-explorer
-
new feature
Difficulty 5/5 Over a week Newbie friendliness 20/100
-
new feature
Difficulty 3/5 1-2 days Newbie friendliness 38/100
-
new feature you can help
Difficulty 5/5 Over a week Newbie friendliness 25/100
All issues in slack-ruby/slack-api-explorer
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
simp/pupmod-simp-stunnel#173 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
TheOdinProject/curriculum#31444 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100