mirror of
https://github.com/TheFunny/TelegramTwitterMediaBot.git
synced 2026-09-23 23:32:05 +00:00
d60f84986496d3bad09dde6a0b1c74f6417f2a90
6
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
64cf43dc01
|
perf: degrade a link-cache entry instead of dropping it on a failed send
`link_cache` exists so a repeat link costs nothing: no source request, no download, no upload. It was written only on a *successful* send, and a send that failed permanently deleted the entry — so the user's immediate retry, the one case where they are most likely to try again, re-fetched everything: site requests, a download, and for a ugoira or a bsky video a full ffmpeg encode. Invalidation is right about the cause (the cached Telegram file id is what went stale) and wrong about the cure (the media and its URLs are usually fine). Cached media now carries the source URL it was sent from, and a permanent failure *degrades* the entry: the file ids are cleared, the URLs and the caption fields stay, and the next request sends from those URLs — Telegram fetches the media (or the upload fallback does) with no source round trip. That is the same media a fresh fetch would have produced (site CDN URLs are stable per post), and it is bounded: an entry that is already degraded, or one from before this field existed, is removed instead, so a dead post still ends up re-fetched and reported rather than retried forever. Verified: a cached send that fails permanently leaves the entry with its URL and no file id, a second failure drops it, and a degraded entry sends the media with no fetch at all (the mock records no reply, which is what the fetch-error path would have produced). 124 bot tests + 91 x-media tests pass, including a direct test of the two payload shapes. `cargo fmt --check`, `cargo clippy --workspace --all-targets --locked -- -D warnings` and `cargo test --workspace --locked` clean. |
||
|
|
024dfd50b3
|
fix: bound the inline state map, test the 300s sweep, add a bot-wide send budget
Three gaps the last audit list named, all in the "resource growth, background timers and limits nobody watches" class. **Idle inline-query entries are pruned.** `DebounceStates` had no eviction at all: one entry per user who ever used inline mode, forever, while the rate limiter's buckets and the chat store both prune in the 300s sweep. Entries now carry a `last_seen` stamp and `prune_idle_states()` drops the ones idle past 300s — the window Telegram caches an inline answer for (`cache_time(300)`), after which a repeat reaches the bot again and has to be answered fresh, so the entry would only suppress a fetch the user is waiting for. The boundary is tested through `prune_idle_at(now, idle_for)` so it does not depend on ageing a monotonic clock. **The 300s sweep is a function, and tested.** It was an inline `tokio::spawn` block: the expiry edit (the only part that talks to Telegram) had no test at all. It is now `periodic_sweep(sender, chat_store, link_cache, task_queue, config, stop)`, which also prunes the inline entries, driven in a test with `start_paused` — the loop's own timer fires the tick, exactly one expired prompt is rewritten in place, a live one keeps its record and buttons. The interval is pinned as a constant because no assertion on the edits can see it (a shorter one produces the same single edit; the paused clock can jump past the boundary while a tick's DB work is in flight). To make the edit reachable at all, `edit_message_text` joined the `MediaSender` trait (Bot impl + mock recording), which is also what keeps `main.rs`'s remaining `Bot` calls unambiguous. `main.rs` leaves the "untested modules" list except for startup/shutdown and the dispatcher tree. **The bot-wide send budget exists.** Telegram throttles a bot in total (~30 msg/s) as well as per chat; only the per-chat bucket existed, so a batch forward fanned out over many chats was unguarded and earned 429s the queue then retried. `acquire_global` charges the same spend against a single shared bucket at the three paced sites (`send_media_group`, `send_animation`, `copy_messages`). The unpaced ones (`send_message`, the edits, the toasts) stay unpaced on purpose: they are one call per action, far below the ceiling, and pacing a user-visible reply would delay it. Not covered: that the send paths call it (they need a real `Bot`), which is the same structural gap as the dispatcher tree. Also: the startup token-exchange decision is now `startup_validation(result)` instead of living inside the `Site::validate` future, so "a 5xx while the container comes up must not disable pixiv" is asserted as a decision — the message the admin gets plus `enabled()` unchanged. The rejected-credential half is deliberately not exercised: it calls `disable()`, a process-wide flag with no reset, and a test touching it would order-couple every other pixiv test. Verified: `cargo fmt`, `cargo clippy --workspace --all-targets --locked -- -D warnings`, `cargo test --workspace --locked` (184 passed, 14 ignored) — plus mutations, each confirmed to fail the relevant test: the sweep not being driven on its timer, the interval shortened to 60s, and (earlier) the queue sweep's missing wake-up. Dropped an empty leftover `crates/x-media/tests/` directory while there (never tracked by git). |
||
|
|
3828d5b483
|
test: share the handler/cache fixtures from ctx::test_support
The same fixtures were rebuilt in five test modules: a `CachedPost` literal in `link_cache.rs`, `handlers/urls.rs` and twice in `send/mod.rs`, the edit-before-forward prompt in `handlers/mod.rs` and `handlers/callback.rs`, and a scripted API error in both handler modules. They now live in `ctx::test_support` next to `TestStores`: - `cached_photo()` — the canonical cached post (photo + file id at `https://x.com/u/status/1`, key `twitter:1`); tests mutate the fields they care about, as the caption-quote test already did. - `seed_prompt(template, created_at)` + `PROMPT_ID`/`FORWARDED_ID` — the prompt record, the chat template and the bound forward channel. The two former copies differed only in which knob the caller set (the callback tests backdate it for the expiry cases, the reply tests pick the template), so the union is one helper. - `api_error(message)` — construction only; each test module keeps its own message constant, because the wording is what that module's path answers with (`chat not found` vs `message not found`). `send/mod.rs`'s `cached_sequence_cache_data()` (which re-extracted the post out of the task it had just built) is gone: the two settle tests seed the cache from the same builder the task uses. No behaviour change: the values are the ones the tests used except `file_id` (`AgAC-file-id` everywhere, asserted in the link-cache round-trip) and `sensitive` (the unasserted `true` in the link-cache fixture), and every test still passes unchanged. Verified: `cargo fmt`, `cargo clippy --workspace --all-targets --locked -- -D warnings` and `cargo test --workspace --locked` (180 passed, 14 ignored). |
||
|
|
af96caff40
|
feat(send): quote a long post's text in an expandable blockquote
A post whose text (the split `title` plus `content`, joined by
`site::compose_text`) reaches `CAPTION_QUOTE_TEXT_CHARS` — default 200,
`0` disables — now has that text wrapped in `<blockquote expandable>`
inside its caption, leaving the URL and author line outside the quote.
Applied at the send boundary (`send_media_sequence`, `send_animation` and
the inline answers), where the caption is already truncated and the same
cache snapshot supplies the text, so a fresh send, a link-cache resend
and a queued retry all decide identically. The text is located as what
follows the author link, with the visible prefix accepted as a match
because `truncate_caption` may cut inside it — that keeps the longest
posts, the ones that most need folding, quoted. Captions whose layout
moves the text elsewhere (pixiv's title-inside-a-link, a `/set_format`
that puts `{title}`/`{content}` first) stay unquoted rather than risking
a blockquote nested in a tag, and a caption that already carries one is
never wrapped again.
Telegram measures a caption *after entities parsing*, so the tags cost no
length and the 1024-character limit cannot be breached; retries replay
the unwrapped caption, so a threshold change takes effect immediately.
The edit-before-forward rewrite stays unquoted by design.
Verified against Telegram: a media-group caption built this way comes
back with `caption_entities` `url` @0, `text_link` @50,
`expandable_blockquote` @56 — the quote starts after the author line.
|
||
|
|
0a9ff58a69
|
refactor: cover the edit/answer surface in MediaSender, test the button flows
docs/architecture-refactor.md §3 sketched the trait with "按需扩展: edit_message_caption / delete_message / answer_callback_query …", but only the five send methods landed, so `callback.rs` and the edit-before-forward caption swap were stuck on the concrete `Bot` and remained untested (AGENTS.md still lists callback.rs as untestable). - `MediaSender` gains `answer_callback_query`, `edit_message_caption` (HTML parse mode baked in, every caller uses it) and `delete_message`; the mock records call order plus the texts, captions and answer toasts, so tests can assert what the user saw. - `send_message` now returns the sent message id instead of the whole `Message`: the only consumer of the value is the edit-before-forward prompt (which keys its record by it), and returning a `Message` forced every mock to build a teloxide type. `reply`/`reply_html` follow. - `callback.rs`: the dptree entry only unpacks the update; `handle_callback` takes plain values + `&AppContext`. `handlers/mod.rs::edit_message_handler` likewise takes the values the reply carries. Admin/setup APIs (`get_chat`, `get_chat_administrators`, `get_me`, `set_my_commands`) stay on the concrete `Bot`: they are not user flows worth a trait. - The scripted mock moves to `parking_lot::Mutex` (no poisoning unwraps). Tests: +11 (template button, forward ok/no-channel/retryable, expired+unknown prompt, caption swap via template, escaping of user text into the caption, failed swap still consuming the reply, prompt record written by post_send). fmt/clippy clean, 70 + 69 tests pass. |
||
|
|
c2d7c8406e
|
refactor: finish the phase-B seam for the post-send path, funnel settlement
docs/architecture-refactor.md §3 stopped half-done: `url_media` got an injected `AppContext`, but `send.rs`'s post-send half kept reaching for the process-wide `CHAT_STORE`/`TASK_QUEUE`/`LINK_CACHE` statics, so the whole shell after a successful send (edit-before-forward prompt, channel forward, retry enqueue, cache write) had no test and no way to get one. - `ctx.rs` now owns `AppContext` (sender + the three stores + config) with `from_statics` for production and a `CONTEXT` static for the spawned worker closures; `handlers/urls.rs` drops its private copy and the duplicated assembler, and the queue handler/dead-letter callbacks take the context (main wires them with `CONTEXT`). - `send_media_sequence`/`send_animation`/`forward_messages`/`post_send_actions` take `&AppContext`; the cache write goes through the injected cache. - New `settle_task(ctx, task, Sent|Failed)` is the single place that ends a task: release its keep-alive temp media, and drop the link-cache entry only on failure. All five former call sites funnel through it — the earlier keep-alive leak existed precisely because one of them had to remember. `invalidate_cache`/`invalidate_cache_with` (static + injected pair, the latter only existing because of the former) collapse into one private fn. - `ctx::test_support::TestStores` gives tests a tempdir store set + context; `handlers/urls.rs` tests use it instead of hand-rolled setup. Tests: +5 (post-send forward ok / queued / notified, settle Sent/Failed); the post-send and settle paths were previously untested. fmt/clippy clean, 60 + 69 tests pass. |