Skip to content

Teams connector token is plaintext configuration.accessToken, readable on the source object; the doc prescribes a credentialRef nothing resolves #2149

Description

@WilcoLouwerse

TeamsChannelAdapter::post() (#2128) reads the Bot Framework bearer token straight from $configuration['accessToken'] (lib/Intake/Adapter/TeamsChannelAdapter.php:306). Nothing on the Teams path resolves a credentialRef. Yet docs/administrators/teams-intake.md configures "credentialRef": "teams-connector" (:33) and says the token is "resolved through credentialRef the way every other outbound credential is" (:80).

Consequences:

  1. An operator who follows the doc gets "The Teams source holds no connector access token.", so replies never send.
  2. The only working setup is to paste the bearer token into configuration.accessToken. That path is not in lib/Settings/register.d/99-source-nested-auth-writeonly.json, whose list is exact paths, so the token renders in cleartext on every read of the source object: admins via the generic OpenRegister API and exports, and anyone the source read rule is ever delegated to.

lib/Intake/Adapter/MessagingChannelAdapter.php:211 has the same read (pre-existing, #2055).

Done when

  • the Teams (and Messaging) connector token is resolved through credentialRef via the broker, or configuration.accessToken is added to x-openregister-writeonly-paths, with a fragment version bump so existing installs re-import it;
  • teams-intake.md describes the mechanism that actually works.

Review thread: #1983 (comment)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

bugSomething isn't workingtriageAwaiting triage

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions