feature
This commit is contained in:
@@ -17,18 +17,20 @@ class TelegramWebhookController extends Controller
|
||||
$chatId = $message['chat']['id'] ?? ($update['callback_query']['message']['chat']['id'] ?? null);
|
||||
$text = is_string($message['text'] ?? null) ? $message['text'] : null;
|
||||
|
||||
$secret = (string) config('coruna.telegram.webhook_secret', '');
|
||||
$header = (string) $request->header('X-Telegram-Bot-Api-Secret-Token', '');
|
||||
|
||||
Log::info('telegram webhook hit', [
|
||||
'ip' => $request->ip(),
|
||||
'update_id' => $update['update_id'] ?? null,
|
||||
'chat_id' => $chatId,
|
||||
'text' => $text,
|
||||
'has_secret_header' => $request->headers->has('X-Telegram-Bot-Api-Secret-Token'),
|
||||
'has_secret_header' => $header !== '',
|
||||
'secret_configured' => $secret !== '',
|
||||
]);
|
||||
|
||||
$secret = (string) config('coruna.telegram.webhook_secret', '');
|
||||
if ($secret !== '') {
|
||||
$header = (string) $request->header('X-Telegram-Bot-Api-Secret-Token', '');
|
||||
if (! hash_equals($secret, $header)) {
|
||||
if ($header === '' || ! hash_equals($secret, $header)) {
|
||||
Log::warning('telegram webhook rejected: bad secret', [
|
||||
'ip' => $request->ip(),
|
||||
'update_id' => $update['update_id'] ?? null,
|
||||
@@ -42,6 +44,7 @@ class TelegramWebhookController extends Controller
|
||||
Log::info('telegram webhook handled', [
|
||||
'update_id' => $update['update_id'] ?? null,
|
||||
'chat_id' => $chatId,
|
||||
'handler' => $bot->currentHandler()?->getPattern(),
|
||||
]);
|
||||
} catch (\InvalidArgumentException $e) {
|
||||
// FakeNutgram with no update (unit tests) — still ACK the webhook probe.
|
||||
|
||||
Reference in New Issue
Block a user