fix(webhook): refuse to start without a secret token

Webhook mode passed the secret token to the axum listener only when WEBHOOK_SECRET_TOKEN was set, and docker-compose defaults it to empty (an empty string counts as unset) — the default deployment therefore ran its listener on a public port with no check on X-Telegram-Bot-Api-Secret-Token, so anyone could POST forged updates and impersonate admins (/bot_dict, /clear_cache, /test). Startup now fails when webhook mode has no secret; .env.example and AGENTS.md spell out the requirement.
This commit is contained in:
2026-09-24 00:48:21 +08:00
parent 3ebc1e4a8f
commit 4c1fa857c4
3 changed files with 10 additions and 5 deletions
+2
View File
@@ -54,6 +54,8 @@ WEBHOOK=false
# WEBHOOK_PORT=8443
# WEBHOOK_URL=https://your.domain/
# Validation token Telegram echoes back as X-Telegram-Bot-Api-Secret-Token.
# Required when WEBHOOK=true: the bot refuses to start without one (use a
# random value of 16+ chars — without it the listener accepts any request).
# WEBHOOK_SECRET_TOKEN=
# Self-signed certificate path, used only for Telegram-side validation (TLS is
# terminated by the reverse proxy); unneeded with acme-companion. Not passed by