fix(telegram): runner-side allowlist gate decodes JSON list strings too
The adapter fix decoded `'["-100","-200"]'` before comma-splitting, but
the runner's central gate in gateway/authz_mixin.py::_coerce_allow_set
reads the same YAML-bridged env chain (TELEGRAM_GROUP_ALLOWED_CHATS,
TELEGRAM_ALLOWED_USERS via _auth_env) and still produced
{'["1"', '"2"]'}, so a group message admitted by the adapter could
still be rejected upstream.
Move the decoder to gateway/platforms/_shared.py, which both the adapter
and authz_mixin already import from (no plugin -> gateway cycle), and
route _coerce_allow_set through it. One invariant test on the runner
side, red before this change.
This commit is contained in:
@@ -50,3 +50,16 @@ def test_comma_and_malformed_strings_keep_the_legacy_split():
|
||||
assert _adapter({"allowed_chats": "-100, -200"})._telegram_allowed_chats() == {"-100", "-200"}
|
||||
assert _adapter({"allowed_chats": ["-100", "-200"]})._telegram_allowed_chats() == {"-100", "-200"}
|
||||
assert _adapter({"allowed_chats": '["-100", "-200'})._telegram_allowed_chats() == {'["-100"', '"-200'}
|
||||
|
||||
|
||||
def test_runner_side_allow_set_decodes_json_string(monkeypatch):
|
||||
"""The runner's central gate reads the same env chain (``TELEGRAM_GROUP_ALLOWED_CHATS``
|
||||
via the YAML bridge) and must not comma-split the brackets onto the ids either."""
|
||||
from gateway.authz_mixin import _coerce_allow_set
|
||||
|
||||
monkeypatch.setenv("TELEGRAM_GROUP_ALLOWED_CHATS", '["-100","-200"]')
|
||||
from gateway.platforms._shared import platform_gate_env
|
||||
|
||||
assert _coerce_allow_set(platform_gate_env("TELEGRAM_GROUP_ALLOWED_CHATS")) == {"-100", "-200"}
|
||||
assert _coerce_allow_set("-100, -200") == {"-100", "-200"}
|
||||
assert _coerce_allow_set(["-100"]) == {"-100"}
|
||||
|
||||
Reference in New Issue
Block a user