feat: new chain

This commit is contained in:
hashbro
2026-08-11 02:26:43 +08:00
parent ec2d9f2308
commit 9bf769b2bd
56 changed files with 3806 additions and 325 deletions
+26 -2
View File
@@ -2,16 +2,28 @@
namespace App\Telegram\Middleware;
use App\Telegram\TelegramBotContext;
use Illuminate\Support\Facades\Log;
use SergiX44\Nutgram\Nutgram;
use SergiX44\Nutgram\Telegram\Properties\ChatType;
/**
* Allow only the configured owner group/supergroup for the current bot context
* (official system chat or the active agent's chat_id).
*/
class AuthorizedChat
{
public function __construct(
private readonly TelegramBotContext $context,
) {}
public function __invoke(Nutgram $bot, callable $next): mixed
{
$expected = (string) config('coruna.telegram.owner_chat_id', '');
$expected = $this->context->expectedChatId();
if ($expected === '') {
Log::warning('telegram AuthorizedChat: TELEGRAM_OWNER_CHAT_ID empty');
Log::warning('telegram AuthorizedChat: chat id empty', [
'agent_id' => $this->context->agent()?->id,
]);
return null;
}
@@ -21,6 +33,18 @@ class AuthorizedChat
Log::info('telegram AuthorizedChat: chat rejected', [
'chat_id' => $chatId,
'expected' => $expected,
'agent_id' => $this->context->agent()?->id,
]);
return null;
}
$type = $bot->chat()?->type;
$typeValue = $type instanceof ChatType ? $type->value : (string) $type;
if (! in_array($typeValue, [ChatType::GROUP->value, ChatType::SUPERGROUP->value, 'group', 'supergroup'], true)) {
Log::info('telegram AuthorizedChat: not a group chat', [
'chat_id' => $chatId,
'type' => $typeValue,
]);
return null;
+30 -5
View File
@@ -2,9 +2,15 @@
namespace App\Telegram\Middleware;
use Illuminate\Support\Facades\Log;
use SergiX44\Nutgram\Nutgram;
use SergiX44\Nutgram\Telegram\Properties\ChatMemberStatus;
use SergiX44\Nutgram\Telegram\Properties\ChatType;
/**
* Allow only group/supergroup administrators (or the creator).
* Must run after {@see AuthorizedChat}.
*/
class GroupAdminOnly
{
public function __invoke(Nutgram $bot, callable $next): mixed
@@ -15,19 +21,38 @@ class GroupAdminOnly
return null;
}
$type = $bot->chat()?->type;
$typeValue = $type instanceof ChatType ? $type->value : (string) $type;
if (! in_array($typeValue, [ChatType::GROUP->value, ChatType::SUPERGROUP->value, 'group', 'supergroup'], true)) {
Log::info('telegram GroupAdminOnly: rejected non-group chat', [
'chat_id' => $chatId,
'type' => $typeValue,
]);
return null;
}
try {
$member = $bot->getChatMember($chatId, $userId);
} catch (\Throwable) {
} catch (\Throwable $e) {
Log::warning('telegram GroupAdminOnly: getChatMember failed', [
'chat_id' => $chatId,
'user_id' => $userId,
'error' => $e->getMessage(),
]);
$bot->sendMessage('⛔ Unable to verify admin status.');
return null;
}
$status = $member?->status;
$ok = $status === ChatMemberStatus::CREATOR
|| $status === ChatMemberStatus::ADMINISTRATOR
|| $status === 'creator'
|| $status === 'administrator';
$statusValue = $status instanceof ChatMemberStatus ? $status->value : (string) $status;
$ok = in_array($statusValue, [
ChatMemberStatus::CREATOR->value,
ChatMemberStatus::ADMINISTRATOR->value,
'creator',
'administrator',
], true);
if (! $ok) {
$bot->sendMessage('⛔ Only group admins can use this command.');
@@ -0,0 +1,21 @@
<?php
namespace App\Telegram\Middleware;
use App\Telegram\TelegramBotContext;
use SergiX44\Nutgram\Nutgram;
/** Blocks /transfer (and similar) on agent bots. */
class OfficialBotOnly
{
public function __invoke(Nutgram $bot, callable $next): mixed
{
if (! app(TelegramBotContext::class)->isOfficial()) {
$bot->sendMessage('⛔ /transfer 仅限官方系统群使用');
return null;
}
return $next($bot);
}
}
+25
View File
@@ -0,0 +1,25 @@
<?php
namespace App\Telegram\Middleware;
use App\Telegram\TelegramBotContext;
use SergiX44\Nutgram\Nutgram;
/** Blocks /transfer (and similar) on agent bots. */
class OfficialOnly
{
public function __construct(
private readonly TelegramBotContext $context,
) {}
public function __invoke(Nutgram $bot, callable $next): mixed
{
if (! $this->context->isOfficial()) {
$bot->sendMessage('⛔ /transfer 仅限官方机器人使用');
return null;
}
return $next($bot);
}
}