Skip to content

fix(teams): authenticate Bot Connector attachments - #59

Merged
Proxicon merged 1 commit into
devfrom
fix/teams-bot-connector-attachment-auth
Sep 4, 2026
Merged

Proxicon merged 1 commit into
devfrom
fix/teams-bot-connector-attachment-auth

Conversation

@Proxicon

@Proxicon Proxicon commented Sep 4, 2026

Copy link
Copy Markdown
Owner

Summary

  • The Teams downloader requests the existing Bot Framework app token only for Bot Connector attachment hosts.
  • It requests https://api.botframework.com/.default and adds a Bearer header to the attachment GET.
  • It keeps the existing teams-attachments client. HTTPS-only, redirect block, byte limit, staging, and scan controls stay active.
  • SharePoint, OneDrive, and other trusted signed URLs receive no Bot Framework token.
  • The change adds no Graph permission, credential configuration, actor contract, or persistence field.

Tests

  • Bot Connector authorization header and app scope.
  • Token exclusion from logs, actor input, metadata, and URLs.
  • Unsigned and signed non-Connector URL behavior.
  • Connector 200 byte limit, 401 stable rejection, token failure, raw URL boundary, and redirect block.

Validation

  • dotnet restore Netclaw.slnx
  • dotnet build Netclaw.slnx --no-restore -m:1 /nodeReuse:false
  • dotnet test Netclaw.slnx --no-build --no-restore -m:1 /nodeReuse:false
  • Focused Teams suite: 242 passed.
  • Focused downloader suite: 20 passed.
  • dotnet slopwatch analyze
  • pwsh ./scripts/Add-FileHeaders.ps1 -Verify

The full build reports one existing Aspire CLI bundle warning.

Scope check

git diff --name-only dev...HEAD contains only the Teams daemon downloader, Teams tests, and Teams documentation.

@Proxicon
Proxicon merged commit e52499d into dev Sep 4, 2026
17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant