|
|
|
|
|
by GauntletWizard
877 days ago
|
|
Slack has the permissions because you have enabled Google drive integration, and authenticated your Google account to give that integration permissions to act as you. If you don't enable Google drive integration, you don't get a preview. If you do enable the Google drive integration, slack uses your permissions to generate a screenshot, and send that to the other users. It is you and your effective permissions that are sending a screenshot, bypassing other security. It is not intuitive if you are not used to how security really works, which is that permissions are granted to masks that you wear, not to any real person. When you give slack permissions to use the drive integration, you are giving them a copy of your mask, and they are you, even unexpectedly. You have a (subconscious) reflex to automatically create and share screenshots of documents that you link, that you have trained via slack's hook. Remove that integration, and everything works as expected. |
|