fix(webhook): refuse to start without a secret token

Webhook mode passed the secret token to the axum listener only when WEBHOOK_SECRET_TOKEN was set, and docker-compose defaults it to empty (an empty string counts as unset) — the default deployment therefore ran its listener on a public port with no check on X-Telegram-Bot-Api-Secret-Token, so anyone could POST forged updates and impersonate admins (/bot_dict, /clear_cache, /test). Startup now fails when webhook mode has no secret; .env.example and AGENTS.md spell out the requirement.
This commit is contained in:
2026-09-24 00:48:21 +08:00
parent 3ebc1e4a8f
commit 4c1fa857c4
3 changed files with 10 additions and 5 deletions
+7 -4
View File
@@ -231,13 +231,16 @@ async fn main() {
// secret token included) — no explicit registration here.
let listen = CONFIG.webhook_listen.expect("WEBHOOK_LISTEN is not set");
let port = CONFIG.webhook_port.expect("WEBHOOK_PORT is not set");
let mut options = webhooks::Options::new((listen, port).into(), url);
// No secret, no webhook: without one the axum listener accepts any
// POST, and a forged update can impersonate anyone — admins included.
let secret = CONFIG
.webhook_secret_token
.clone()
.expect("WEBHOOK_SECRET_TOKEN is not set (required in webhook mode)");
let mut options = webhooks::Options::new((listen, port).into(), url).secret_token(secret);
if let Some(cert) = &CONFIG.webhook_cert {
options = options.certificate(InputFile::file(cert));
}
if let Some(secret) = &CONFIG.webhook_secret_token {
options = options.secret_token(secret.clone());
}
let mut listener = webhooks::axum(bot.clone(), options)
.await