Security News
Research
Data Theft Repackaged: A Case Study in Malicious Wrapper Packages on npm
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
ringcentral-bot-framework
Advanced tools
Welcome to the RingCentral Chatbot Framework for Python. This framework dramatically simplifies the process of building a bot to work with Glip, RingCentral's group chat system. It is intended to do most of the heavy lifting for developers, allowing them to focus primarily on the logic and user experience of their bot.
bot.py
Let's get a local chatbot server up and running so that you can understand how the framework functions. Our first chatbot will be a simple parrot bot that will repeat things back to you. Before we get started, let's get your development environment setup with everything you need.
This framework requires Python3.6+ and Pip3.
First we install virtualenv which will create an isolated environment in which to install and run all the python libraries needed by this framework. Using virtualenv will ensure that the libraries installed for this project do not conflict or disrupt the other python projects you are working on.
# init project
bin/init
source venv/bin/activate
Next, we need to run ngrok, a tool for routing web requests to a localhost. This is what will allow your local bot in development to receive webhooks from RingCentral. ngrok is a node app and is installed and start as follows:
./bin/proxy
After ngrok has started, it will display the URL when the ngrok proxy is operating. It will say something like:
Forwarding https://xxxxx.ngrok.io -> localhost:9898
Make note of this URL, as you will need it in the next step.
You will need to create your Bot App in RingCentral. Clicking the link, "Create Bot App" below will do this for you. Remember to select messagging bot
bot and for All RingCentral customers
, When you click it, you will to enter in the OAuth Redirect URI
for the bot. This will be the ngrok URL above, plus /bot-oauth
. For example:
https://xxxxxx.ngrok.io/bot-oauth
When you are finished creating your Bot Application, make note of the Client ID and Client Secret. We will use those values in the next step.
A sample .env file can be found in .env.sample
. Create a copy of this file:
cp .sample.env .env
Then look for the following variables, and set them accordingly:
RINGCENTRAL_BOT_SERVER
RINGCENTRAL_BOT_CLIENT_ID
RINGCENTRAL_BOT_CLIENT_SECRET
This bot framework loads all bot behaviors from a file called config.py
. Let's copy the parrot bot config to get started.
cp sample-bots/parrot.py ./bot.py
# rcs is cli server module from ringcentral_chatbot_server
rcs bot.py
When the server is up and running, you can add the bot to your sandbox Glip account. Navigate the dashboard for the app you created above. Select "Bot" from the left-hand sidebar menu. Save a preferred name for your bot, then click the "Add to Glip" button.
After the bot is added, we can message with it. Login to our sandbox Glip. Then start a chat with the bot using the name you chose in the previous step.
You should now be in private chat session with the bot. It should greet you with a message similar to:
Hello, I am a chatbot. Please reply "ParrotBot" if you want to talk to me.
Type @ParrotBot Polly want a cracker?
and let's see what happens.
Now you know how it works, you may try to init a bot project in one line script:
# make sure you have python3.6+ and pip3 installed
# use wget
wget -qO- https://raw.githubusercontent.com/ringcentral/ringcentral-chatbot-factory-py/master/bin/init.sh | bash
# or with curl
curl -o- https://raw.githubusercontent.com/ringcentral/ringcentral-chatbot-factory-py/master/bin/init.sh | bash
A video to show the process: https://youtu.be/x5sTrj5xSN8
The following bots were created using this framework, and should serves as guides as you develop your own original bot.
Check sample-bots/parrot-adaptive-card.py as an example,
bot.sendAdaptiveCard
to send AdaptiveCardbot.updateAdaptiveCard
to update AdaptiveCardSince we support adaptive cards
, we also support interactive messages when using adaptive cards actions, so bot can get interactive messages directly from user actions, you need goto app setting page in developer.ringcentral.com
, enable Interactive Messages
, and set https://xxxxx.ngrok.io/interactive
as Outbound Webhook URL
Check sample-bots/interactive.py as an example, define your own onInteractiveMessage
function to handle interative messages.
@Bot __rename__ newName
to rename bot to newName
@Bot __setAvatar__
and image attachment to set bot profile image.The ringcentral-chatbot-factory-py was created to help speed up the process of creating additional Glip bots. To use it, install it, then run the rcf
command as shown below:
pip3 install ringcentral_chatbot_factory
rcf my-ringcentral-chat-bot
Then just answer the prompts. Then follow the directions in my-ringcentral-chat-bot/README.md
to get up and running.
bin/test
Visit https://github.com/zxdong262/ringcentral-chatbot-python/issues
The core bot framework logic is implanted from ringcentral-ai-bot written by @tylerlong
MIT
FAQs
RingCentral Chatbot Framework for Python
We found that ringcentral-bot-framework demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Research
The Socket Research Team breaks down a malicious wrapper package that uses obfuscation to harvest credentials and exfiltrate sensitive data.
Research
Security News
Attackers used a malicious npm package typosquatting a popular ESLint plugin to steal sensitive data, execute commands, and exploit developer systems.
Security News
The Ultralytics' PyPI Package was compromised four times in one weekend through GitHub Actions cache poisoning and failure to rotate previously compromised API tokens.