Harden Telegram bot cleanup commands

This commit is contained in:
ShukeBta
2026-06-16 18:52:04 +08:00
parent 829b88036a
commit 6e7854e8f6
7 changed files with 252 additions and 30 deletions
+16 -1
View File
@@ -167,7 +167,11 @@ func TestTelegramGroupHidesAdminPanelFromRegularUsers(t *testing.T) {
func TestTelegramGroupAdminMenuDoesNotExposeButtonsInGroup(t *testing.T) {
ctx := t.Context()
_, bot := newBotTestService(t)
repos, bot := newBotTestService(t)
admin := &model.User{Username: "root", PasswordHash: "x", Role: "admin", IsActive: true}
if err := repos.User.Create(ctx, admin); err != nil {
t.Fatal(err)
}
channel := &model.NotifyChannel{Name: "Telegram", Type: "telegram", Enabled: true, Config: `{"group_chat_id":"-100123","admin_user_ids":"9001"}`}
msg := &TelegramMessage{
From: TelegramUser{ID: 9001, Username: "admin", FirstName: "Admin"},
@@ -189,6 +193,17 @@ func TestTelegramGroupAdminMenuDoesNotExposeButtonsInGroup(t *testing.T) {
if !strings.Contains(reply.Text, "请私聊 Bot") || telegramReplyHasButtonPrefix(reply, "adm_") {
t.Fatalf("group admin callback should not render admin panel publicly: %#v", reply)
}
reply, err := bot.executeCommand(ctx, channel, msg, "/users")
if err != nil {
t.Fatal(err)
}
if !strings.Contains(reply.Text, "用户管理") {
t.Fatalf("bound group admin text command should run, got %q", reply.Text)
}
if len(reply.Buttons) != 0 {
t.Fatalf("group admin text command must not expose inline buttons publicly: %#v", reply.Buttons)
}
}
func TestTelegramPollingChannelHintWinsForPrivateMessages(t *testing.T) {