fix(webhooks): harden webhook config and secret handling
This commit is contained in:
@@ -43,10 +43,19 @@ async def build_and_start_web_app(
|
||||
telegram_uses_webhook_mode = bool(settings.WEBHOOK_BASE_URL)
|
||||
|
||||
if telegram_uses_webhook_mode:
|
||||
telegram_webhook_path = f"/{settings.BOT_TOKEN}"
|
||||
app.router.add_post(telegram_webhook_path, SimpleRequestHandler(dispatcher=dp, bot=bot))
|
||||
telegram_webhook_path = settings.telegram_webhook_path
|
||||
app.router.add_post(
|
||||
telegram_webhook_path,
|
||||
SimpleRequestHandler(
|
||||
dispatcher=dp,
|
||||
bot=bot,
|
||||
secret_token=settings.TELEGRAM_WEBHOOK_SECRET,
|
||||
),
|
||||
)
|
||||
logging.info(
|
||||
f"Telegram webhook route configured at: [POST] {telegram_webhook_path} (relative to base URL)"
|
||||
"Telegram webhook route configured at: [POST] %s (secret_token=%s)",
|
||||
telegram_webhook_path,
|
||||
"set" if settings.TELEGRAM_WEBHOOK_SECRET else "not_set",
|
||||
)
|
||||
|
||||
from bot.handlers.user.payment import yookassa_webhook_route
|
||||
@@ -59,7 +68,7 @@ async def build_and_start_web_app(
|
||||
cp_path = settings.cryptopay_webhook_path
|
||||
if cp_path.startswith("/"):
|
||||
app.router.add_post(cp_path, cryptopay_webhook_route)
|
||||
logging.info(f"CryptoPay webhook route configured at: [POST] {cp_path}")
|
||||
logging.info("CryptoPay webhook route configured at: [POST] %s", cp_path)
|
||||
|
||||
fk_path = settings.freekassa_webhook_path
|
||||
if fk_path.startswith("/"):
|
||||
|
||||
Reference in New Issue
Block a user