docs(en): onboarding pages, and a webhook token validation fix - #42
Merged
Merged
Conversation
English pages, first batch — the path a newcomer actually walks: Getting started, Webhook, Debugging a webhook, F.A.Q. Two fixes found while translating, both in the Russian docs too: - The quick start told readers to subscribe to telegram.OnLogCommon and telegram.OnLogError. Neither exists; the events live on telegram.Events as OnCommonLog and OnErrorLog. The first code a newcomer copies did not compile. - ValidateTelegramBotAttribute in the ASP.NET webhook example accepted every request. A stray semicolon after the if turned the secret-token comparison into an empty statement, so return true ran unconditionally. BotController checks the token again before handling an update, so the example itself was not exploitable, but the filter is what people copy into their own projects, and alone it protected nothing. The same code was printed in the documentation. The English pages use the dotnet CLI rather than the IDE screenshots, so they carry no assets and no Russian-language UI, and the obsolete nuget.voids.site workaround is dropped — Telegram.Bot has been back on nuget.org since version 22. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
First batch of English documentation, plus two defects found while translating.
English pages
The path a newcomer actually walks, in order:
getting-started/README.mdgetting-started/webhook/README.mdgetting-started/webhook/debugging-webhook.mdfaq.mdJsonExceptionthat cost a day to diagnoseThese use the
dotnetCLI instead of IDE screenshots, so they need no assets and show no Russian-language UI. The obsoletenuget.voids.siteworkaround is dropped — Telegram.Bot has been back on nuget.org since version 22, which the Russian page itself says at the bottom.Two defects found while translating
The quick start did not compile. It told readers to write:
Neither member exists. The events live on
telegram.EventsasOnCommonLogandOnErrorLog. This is the first code anyone copies. Fixed in the Russian page; the English page is correct from the start.ValidateTelegramBotAttributeaccepted every request.The semicolon makes the
ifbody empty, soreturn trueruns unconditionally on the first bot in the list. Any request carrying theX-Telegram-Bot-Api-Secret-Tokenheader passed the filter, whatever the header held — and the secret token is the only thing proving a webhook request came from Telegram.BotControllercompares the token again before handling an update, so the shipped example was not itself exploitable. But this filter is precisely what people lift into their own projects, and on its own it protected nothing. The same code was printed on the webhook documentation page, so it is fixed in both, and the English page now carries a warning explaining the shape of the bug.Verification
docs/enresolve; all 6SUMMARY.mdentries point at files that exist.Still to do
PRBotBuilderis not translated yet — the getting-started page links to the Russian one meanwhile. The remaining ~135 pages follow in further batches; the API reference is 90 of them but only about a tenth of the prose.🤖 Generated with Claude Code