Slack Bolt Middleware Pipeline Design Prompt
Architect a clean, testable middleware chain for a Bolt app — auth context, tenant resolution, rate limiting, error boundaries, and structured logging — so handlers stay thin and reusable.
- Target user
- Engineers structuring a growing Slack Bolt application
- Difficulty
- Intermediate
- Tools
- Claude, ChatGPT
The prompt
You are a backend engineer who has refactored a sprawling Slack Bolt app into a clean, layered middleware pipeline that new contributors can extend without fear. I will provide: - Our current Bolt app structure (or that we're greenfield) - The runtime (Bolt for JS or Python) and how it's deployed - The cross-cutting concerns we keep copy-pasting into handlers Your job: 1. **Middleware order** — define a canonical chain and explain why order matters: request logging → idempotency/dedup → signature verification (if not Bolt-native) → tenant/team resolution → user authorization → rate limiting → handler → error boundary. Show what `await next()` placement does at each stage. 2. **Global vs listener middleware** — when to register `app.use()` global middleware vs per-listener middleware, and how to short-circuit cleanly (ack + ephemeral "not authorized") without invoking the handler. 3. **Context enrichment** — populate `context` with resolved team config, user role, feature flags, and a request-scoped logger so handlers read `context.user.role` instead of re-fetching. 4. **Idempotency** — Slack retries on slow acks (the `X-Slack-Retry-Num` header). Add middleware that no-ops on duplicate event ids using a short-TTL store, and acks within 3 seconds before doing slow work. 5. **Error boundary** — a global error handler that classifies errors (user error → ephemeral message; platform error → log + generic apology; bug → alert channel), never leaking stack traces to users. 6. **Testability** — show how to unit-test a single middleware in isolation with a faked `next`, and how to assert short-circuit behavior. 7. **Observability** — structured logs with team id, user id, event type, latency, and outcome; one log line per request that a dashboard can aggregate. Output: (a) the ordered middleware diagram, (b) each middleware as a separate module with types, (c) the app wiring that registers them, (d) a unit test for the authorization middleware, (e) a thin example handler that relies entirely on enriched context. Bias toward: thin handlers, composable single-purpose middleware, fail-closed authorization, and acking fast.
Run this prompt with AI
Test it, get an AI-improved version, or compare models — live in the Prompt Workspace. No copy-paste.
Related prompts
-
Slack Bot Multi-Region Failover & High-Availability Prompt
Design an active/standby or active/active Slack bot across regions — event de-duplication, single-writer coordination, Socket Mode failover, and clean cutover.
-
Slack Bolt 3-Second Ack Timeout Discipline Prompt
Audit and redesign Bolt listeners so every interaction acks within 3 seconds and slow work moves off the request path, eliminating dispatch_failed and operation_timeout errors.
-
Slack Bolt Listener Concurrency & Work Queue Prompt
Design concurrency control and a work queue for Bolt listeners so a burst of interactions doesn't exhaust connections, blow rate limits, or starve the event loop.
-
Slack Bookmarks API Channel Quick-Links Automation Prompt
Programmatically curate per-channel bookmark bars so every incident or service channel exposes the same runbook, dashboard, and on-call quick-links via bookmarks.add
More Slack prompts & error guides
Browse every Slack prompt and troubleshooting guide in one place.
Reading prompts? Get all 500 in one free PDF
500 battle-tested, copy-paste AI prompts engineered by a senior systems engineer — every one with fill-in placeholders and safety/back-out notes. Drop your email and it's yours.
- 500 prompts: Linux · Kubernetes · Terraform · OpenStack · GitLab · Docker · Monitoring · Incident Response
- Instant PDF download — yours free, forever
- Plus one practical AI-workflow email a week (no spam)
Single opt-in · unsubscribe anytime · no spam.