Skip to content

Browser-session API calls send a non-browser User-Agent, triggering Slack's unexpected_user_agent and force-logout #141

Description

@nitrocode

What's broken

Browser-session (xoxc/xoxd) API calls send User-Agent: agent-slack/<version> while replaying a real browser's session cookie (Cookie: d=...) and spoofing Origin/Referer as https://app.slack.com:

  • src/slack/client.ts (browserApi, browserApiMultipart)
  • src/slack/files.ts
  • src/slack/canvas.ts

All three call getUserAgent() in src/lib/version.ts, which returns `agent-slack/${getPackageVersion()}` — a value no real browser sends.

Symptom

On a workspace with enterprise session-security policies, this UA/session mismatch gets flagged as a fingerprint anomaly. Slack's response isn't just to reject the API call — it kills the session outright, which logs out the real browser tab that owned that session, with unexpected_user_agent shown in Slack's UI. This can happen mid-login, right as you're trying to authenticate in the browser.

Repro

  1. On an Enterprise Grid workspace with session security policies enabled, have an active browser session logged in to Slack.
  2. Run any agent-slack command that uses browser auth against that workspace (e.g. agent-slack auth whoami).
  3. The browser tab gets logged out with unexpected_user_agent.

Suggested fix

getUserAgent() should return a browser-shaped UA string instead of agent-slack/<version>, with an env var / CLI flag escape hatch for users who want to override it (e.g. to match their actual browser more closely, or bump past a stale hardcoded version):

  • Default to a static, current-ish Chrome/macOS UA string.
  • Allow override via AGENT_SLACK_USER_AGENT env var.
  • Allow override via a global --user-agent <string> CLI flag (wired to the env var via a commander preAction hook, since getUserAgent() is called from modules with no access to the Command instance).

Happy to open a PR with this — have a working local patch.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions