You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Slack应用首次请求Webhook签名不匹配问题技术问询

Slack Webhook签名首次请求不匹配问题

当Slack的Zervise应用打开并访问任意标签页时,首次请求的Slack Webhook签名与服务器计算的签名不匹配,但后续请求的签名均匹配。

我们的后端服务器支持Slack使用的两种请求体类型:

  • application/json
  • application/x-www-form-urlencoded

以下是校验Slack Webhook签名的后端代码:

const slack = (req, res, next) => {
  if (
    !req.headers['x-slack-request-timestamp'] ||
    Math.abs(
      Math.floor(new Date().getTime() / 1000) -
        +req.headers['x-slack-request-timestamp']
    ) > 300
  )
    return res.status(400).send('Request too old!');

  const baseStr = `v0:${
    req.headers['x-slack-request-timestamp']
  }:${qs.stringify(req.body, {
    format: 'RFC1738',
  })}`;
  const receivedSignature = req.headers['x-slack-signature'];
  const expectedSignature = `v0=${crypto
    .createHmac('sha256', env.SLACK_SIGNING_SECRET)
    .update(baseStr, 'utf8')
    .digest('hex')}`;

  if (expectedSignature !== receivedSignature) {
    console.log('WEBHOOK SIGNATURE MISMATCH');
    return res.status(400).send('Error: Signature mismatch security error');
  }

  console.log('WEBHOOK VERIFIED');
  next();
};

我们已附上控制台日志截图,每张截图包含请求头、Slack发送的receivedSignature及服务器计算的expectedSignature。尝试使用请求原始Body计算签名,首次请求仍不匹配。

截图说明:

  1. 签名不匹配的首次请求控制台日志截图:应用打开后Slack的首次请求
  2. 签名匹配的后续请求控制台日志截图:Slack的后续请求

内容的提问来源于stack exchange,提问作者Soumya Dey

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.06 10:15:27