feat(userbot): prereqs at startup, SPA path guard, provision lock
ci / lint-prettier (push) Failing after 8s
ci / lint-ruff (push) Successful in 4s
ci / lint-yaml (push) Failing after 7s
ci / lint-dockerfiles (push) Successful in 4s
ci / validate (push) Successful in 5s
deploy / redeploy (push) Failing after 0s
ci / build (push) Has been skipped
ci / deploy-userbot-panel (push) Has been skipped

- ensure_prerequisites runs on startup, not per-request; kube config
  errors surface as 503 PanelError
- serialize provisioning with a lock; drop per-endpoint prereq checks
- guard SPA fallback against path traversal (relative_to)
- add backend tests for auth flow, k8s service, spa routing; ci comment
  for legacy userbot deployments
This commit is contained in:
forust committed 2026-09-06 20:39:12 +02:00
1 parent 861d89d36a
commit d9f1c8325a
10 files changed
+191 -34

No files matched your search

+8 -1
View File
@@ -39,13 +39,20 @@ class AuthorizedAccount:
class TelegramAuthService:
def __init__(self, ttl_seconds: int = 600) -> None:
def __init__(self, ttl_seconds: int = 600, max_flows: int = 50) -> None:
self.ttl = timedelta(seconds=ttl_seconds)
self.max_flows = max_flows
self.flows: dict[str, AuthFlow] = {}
self._lock = asyncio.Lock()
async def start_phone(self, account: PhoneStart) -> str:
await self._cleanup_expired()
async with self._lock:
if len(self.flows) >= self.max_flows:
raise PanelError(
429,
"Too many pending authorization flows; try again later",
)
flow_id = secrets.token_urlsafe(24)
telegram = Client(
f"auth-{flow_id}",