52f898ca6f
Tests · Go / test (push) Successful in 7s
Tests · Integration / integration (push) Successful in 11s
Tests · UI / test (push) Successful in 20s
Tests · Go / test (pull_request) Successful in 6s
Tests · Integration / integration (pull_request) Successful in 11s
Tests · UI / test (pull_request) Successful in 19s
Link an email (confirm-code) or Telegram (web Login Widget) to the current account; if the identity already has its own account, merge the two into the one in use (the current account is primary, except a guest initiator whose durable counterpart wins). The merge runs in one transaction (internal/accountmerge): stats + hint wallet summed, paid_account ORed, identities/games/chat/complaints transferred, friends/blocks de-duplicated, the secondary kept as a merged_into tombstone so a shared finished game's no-cascade FKs hold; a shared active game blocks the merge. - migration 00009: accounts.paid_account, merged_into, merged_at (+ jetgen) - internal/link orchestrator; session.RevokeAllForAccount on merge - connector ValidateLoginWidget RPC + loginwidget HMAC validator - edge ops link.email.request/confirm/merge, link.telegram.confirm/merge; supersedes the Stage 8 email.bind.* surface (request never reveals 'taken' before the code is verified, so a probe cannot enumerate addresses) - UI Profile link section + irreversible-merge dialog; Telegram web sign-in - focused regression tests (merge core, guest inversion, active-game refusal, finished-shared-game kept), gateway transcode + connector + UI codec/e2e - docs: PLAN, ARCHITECTURE 3/4/9, FUNCTIONAL(+ru), module READMEs
105 lines
3.4 KiB
Go
105 lines
3.4 KiB
Go
// Package connector is the gateway's gRPC client for the Telegram connector
|
|
// side-service: it validates Mini App initData and delivers out-of-app push. The
|
|
// connector lives on the trusted internal network, so the connection uses insecure
|
|
// (plaintext) transport credentials (ARCHITECTURE.md §12).
|
|
package connector
|
|
|
|
import (
|
|
"context"
|
|
"errors"
|
|
"fmt"
|
|
|
|
"google.golang.org/grpc"
|
|
"google.golang.org/grpc/codes"
|
|
"google.golang.org/grpc/credentials/insecure"
|
|
"google.golang.org/grpc/status"
|
|
|
|
telegramv1 "scrabble/pkg/proto/telegram/v1"
|
|
)
|
|
|
|
// ErrInvalidInitData is returned by ValidateInitData when the connector rejects the
|
|
// launch data (a gRPC InvalidArgument), letting the transcode layer surface a stable
|
|
// result code.
|
|
var ErrInvalidInitData = errors.New("connector: invalid telegram init data")
|
|
|
|
// ErrInvalidLoginWidget is returned by ValidateLoginWidget when the connector
|
|
// rejects the Login Widget data (a gRPC InvalidArgument).
|
|
var ErrInvalidLoginWidget = errors.New("connector: invalid telegram login widget data")
|
|
|
|
// User is a validated Mini App identity.
|
|
type User struct {
|
|
ExternalID string
|
|
Username string
|
|
FirstName string
|
|
LanguageCode string
|
|
}
|
|
|
|
// Client wraps the connector's Telegram gRPC service.
|
|
type Client struct {
|
|
conn *grpc.ClientConn
|
|
c telegramv1.TelegramClient
|
|
}
|
|
|
|
// New dials the connector gRPC endpoint.
|
|
func New(addr string) (*Client, error) {
|
|
conn, err := grpc.NewClient(addr, grpc.WithTransportCredentials(insecure.NewCredentials()))
|
|
if err != nil {
|
|
return nil, fmt.Errorf("connector: dial %s: %w", addr, err)
|
|
}
|
|
return &Client{conn: conn, c: telegramv1.NewTelegramClient(conn)}, nil
|
|
}
|
|
|
|
// Close releases the gRPC connection.
|
|
func (c *Client) Close() error { return c.conn.Close() }
|
|
|
|
// ValidateInitData verifies Mini App launch data and returns the user identity,
|
|
// mapping a connector InvalidArgument to ErrInvalidInitData.
|
|
func (c *Client) ValidateInitData(ctx context.Context, initData string) (User, error) {
|
|
resp, err := c.c.ValidateInitData(ctx, &telegramv1.ValidateInitDataRequest{InitData: initData})
|
|
if err != nil {
|
|
if status.Code(err) == codes.InvalidArgument {
|
|
return User{}, ErrInvalidInitData
|
|
}
|
|
return User{}, err
|
|
}
|
|
return User{
|
|
ExternalID: resp.GetExternalId(),
|
|
Username: resp.GetUsername(),
|
|
FirstName: resp.GetFirstName(),
|
|
LanguageCode: resp.GetLanguageCode(),
|
|
}, nil
|
|
}
|
|
|
|
// ValidateLoginWidget verifies Telegram Login Widget data and returns the user
|
|
// identity, mapping a connector InvalidArgument to ErrInvalidLoginWidget. It backs
|
|
// the link.telegram edge operation (Stage 11).
|
|
func (c *Client) ValidateLoginWidget(ctx context.Context, data string) (User, error) {
|
|
resp, err := c.c.ValidateLoginWidget(ctx, &telegramv1.ValidateLoginWidgetRequest{Data: data})
|
|
if err != nil {
|
|
if status.Code(err) == codes.InvalidArgument {
|
|
return User{}, ErrInvalidLoginWidget
|
|
}
|
|
return User{}, err
|
|
}
|
|
return User{
|
|
ExternalID: resp.GetExternalId(),
|
|
Username: resp.GetUsername(),
|
|
FirstName: resp.GetFirstName(),
|
|
}, nil
|
|
}
|
|
|
|
// Notify delivers an out-of-app notification for a push event; delivered reports
|
|
// whether a message was actually sent.
|
|
func (c *Client) Notify(ctx context.Context, externalID, kind string, payload []byte, language string) (bool, error) {
|
|
resp, err := c.c.Notify(ctx, &telegramv1.NotifyRequest{
|
|
ExternalId: externalID,
|
|
Kind: kind,
|
|
Payload: payload,
|
|
Language: language,
|
|
})
|
|
if err != nil {
|
|
return false, err
|
|
}
|
|
return resp.GetDelivered(), nil
|
|
}
|