Skip to content

docs(en): onboarding pages, and a webhook token validation fix - #42

Merged
prethink merged 1 commit into
masterfrom
docs/en-translation-1
Aug 23, 2026
Merged

prethink merged 1 commit into
masterfrom
docs/en-translation-1

Conversation

@prethink

Copy link
Copy Markdown
Owner

First batch of English documentation, plus two defects found while translating.

English pages

The path a newcomer actually walks, in order:

Page Notes
getting-started/README.md BotFather, installation, starting the bot, adding a command, multi-bot, examples table
getting-started/webhook/README.md The full ASP.NET webhook setup
getting-started/webhook/debugging-webhook.md ngrok, rewritten as steps rather than screenshots
faq.md The existing entries, plus the callback-type JsonException that cost a day to diagnose

These use the dotnet CLI instead of IDE screenshots, so they need no assets and show no Russian-language UI. The obsolete nuget.voids.site workaround is dropped — Telegram.Bot has been back on nuget.org since version 22, which the Russian page itself says at the bottom.

Two defects found while translating

The quick start did not compile. It told readers to write:

telegram.OnLogCommon += ...;
telegram.OnLogError += ...;

Neither member exists. The events live on telegram.Events as OnCommonLog and OnErrorLog. This is the first code anyone copies. Fixed in the Russian page; the English page is correct from the start.

ValidateTelegramBotAttribute accepted every request.

if (string.Equals(secretTokenHeader, secretToken, StringComparison.Ordinal));
    return true;

The semicolon makes the if body empty, so return true runs unconditionally on the first bot in the list. Any request carrying the X-Telegram-Bot-Api-Secret-Token header passed the filter, whatever the header held — and the secret token is the only thing proving a webhook request came from Telegram.

BotController compares the token again before handling an update, so the shipped example was not itself exploitable. But this filter is precisely what people lift into their own projects, and on its own it protected nothing. The same code was printed on the webhook documentation page, so it is fixed in both, and the English page now carries a warning explaining the shape of the bug.

Verification

  • The webhook example project builds.
  • All relative links in docs/en resolve; all 6 SUMMARY.md entries point at files that exist.
  • CRLF and the absence of a BOM preserved throughout.
  • Both changelogs record the validation fix, at matching line numbers.

Still to do

PRBotBuilder is not translated yet — the getting-started page links to the Russian one meanwhile. The remaining ~135 pages follow in further batches; the API reference is 90 of them but only about a tenth of the prose.

🤖 Generated with Claude Code

English pages, first batch — the path a newcomer actually walks:
Getting started, Webhook, Debugging a webhook, F.A.Q.

Two fixes found while translating, both in the Russian docs too:

- The quick start told readers to subscribe to telegram.OnLogCommon and
  telegram.OnLogError. Neither exists; the events live on telegram.Events
  as OnCommonLog and OnErrorLog. The first code a newcomer copies did not
  compile.

- ValidateTelegramBotAttribute in the ASP.NET webhook example accepted
  every request. A stray semicolon after the if turned the secret-token
  comparison into an empty statement, so return true ran unconditionally.
  BotController checks the token again before handling an update, so the
  example itself was not exploitable, but the filter is what people copy
  into their own projects, and alone it protected nothing. The same code
  was printed in the documentation.

The English pages use the dotnet CLI rather than the IDE screenshots, so
they carry no assets and no Russian-language UI, and the obsolete
nuget.voids.site workaround is dropped — Telegram.Bot has been back on
nuget.org since version 22.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@prethink
prethink merged commit 5f9d37d into master Aug 23, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant