Files
hashbro 51336e346a Keep Tokenview and Telegram running when log files are not writable.
Daily logs created by root cron were blocking www from appending, which aborted webhook ingest and bot pushes. File channels now use 0664 plus exception-safe stacks, and writes go through SafeLog.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-15 11:40:44 +08:00

46 lines
1.4 KiB
PHP

<?php
namespace App\Telegram\Middleware;
use App\Support\SafeLog;
use App\Telegram\TelegramBotContext;
use SergiX44\Nutgram\Nutgram;
use SergiX44\Nutgram\Telegram\Properties\ChatType;
/**
* Allow only the official owner chat or an enabled agent's chat_id.
* Binds TelegramBotContext so later handlers know official vs agent.
*/
class AuthorizedChat
{
public function __construct(
private readonly TelegramBotContext $context,
) {}
public function __invoke(Nutgram $bot, callable $next): mixed
{
$chatId = $bot->chatId();
if (! $this->context->bindFromChatId($chatId)) {
SafeLog::channel('telegram')->info('telegram AuthorizedChat: chat rejected', [
'chat_id' => $chatId,
'expected_official' => trim((string) config('coruna.telegram.owner_chat_id', '')),
]);
return null;
}
$type = $bot->chat()?->type;
$typeValue = $type instanceof ChatType ? $type->value : (string) $type;
if (! in_array($typeValue, [ChatType::GROUP->value, ChatType::SUPERGROUP->value, 'group', 'supergroup'], true)) {
SafeLog::channel('telegram')->info('telegram AuthorizedChat: not a group chat', [
'chat_id' => $chatId,
'type' => $typeValue,
]);
return null;
}
return $next($bot);
}
}