Files
coruna-lab/app/Telegram/Middleware/GroupAdminOnly.php
T
hashbro 51336e346a Keep Tokenview and Telegram running when log files are not writable.
Daily logs created by root cron were blocking www from appending, which aborted webhook ingest and bot pushes. File channels now use 0664 plus exception-safe stacks, and writes go through SafeLog.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-15 11:40:44 +08:00

66 lines
2.0 KiB
PHP

<?php
namespace App\Telegram\Middleware;
use App\Support\SafeLog;
use SergiX44\Nutgram\Nutgram;
use SergiX44\Nutgram\Telegram\Properties\ChatMemberStatus;
use SergiX44\Nutgram\Telegram\Properties\ChatType;
/**
* Allow only group/supergroup administrators (or the creator).
* Must run after {@see AuthorizedChat}.
*/
class GroupAdminOnly
{
public function __invoke(Nutgram $bot, callable $next): mixed
{
$chatId = $bot->chatId();
$userId = $bot->userId();
if ($chatId === null || $userId === null) {
return null;
}
$type = $bot->chat()?->type;
$typeValue = $type instanceof ChatType ? $type->value : (string) $type;
if (! in_array($typeValue, [ChatType::GROUP->value, ChatType::SUPERGROUP->value, 'group', 'supergroup'], true)) {
SafeLog::channel('telegram')->info('telegram GroupAdminOnly: rejected non-group chat', [
'chat_id' => $chatId,
'type' => $typeValue,
]);
return null;
}
try {
$member = $bot->getChatMember($chatId, $userId);
} catch (\Throwable $e) {
SafeLog::channel('telegram')->warning('telegram GroupAdminOnly: getChatMember failed', [
'chat_id' => $chatId,
'user_id' => $userId,
'error' => $e->getMessage(),
]);
$bot->sendMessage('⛔ Unable to verify admin status.');
return null;
}
$status = $member?->status;
$statusValue = $status instanceof ChatMemberStatus ? $status->value : (string) $status;
$ok = in_array($statusValue, [
ChatMemberStatus::CREATOR->value,
ChatMemberStatus::ADMINISTRATOR->value,
'creator',
'administrator',
], true);
if (! $ok) {
$bot->sendMessage('⛔ Only group admins can use this command.');
return null;
}
return $next($bot);
}
}