mirror of
https://github.com/tiennm99/miti99bot.git
synced 2026-10-05 10:13:41 +00:00
Every command except /newpack drops its <pack> argument; the caller's single pack is resolved implicitly. /packlist becomes /mypack, and the store key is the user ID alone. Resolves rather than mitigates the worst red-team finding: /packlist's N+1 plus ten GetStickerSet calls under a 60s per-call ceiling is gone. /mypack is one Get and makes no API calls. resolveOwned collapses to a single Get. Both prior open questions are answered. The slug survives on /newpack alone, where it fixes the permanent share URL. Derived-from-user-id and opaque-id schemes were rejected: the first publishes the owner's Telegram ID forever, the second is unbrandable. /delpack reframed as the only way to change a pack URL, since Telegram exposes no rename-short-name method: - /renamepack's reply names the delete-and-recreate route instead of only stating the link cannot change - /delpack's confirm must state the title, the sticker count being destroyed, the link being surrendered, and that both are permanent - /repack migration rejected for this plan: up to ~121 sequential API calls exceeds handlerTimeout and stalls the bot for all users under C1. Viable only after the Phase 5 offload; recorded as a follow-up Fixes a bug in the write-ahead intent machinery: the different-slug pending branch overwrote unconditionally, permanently orphaning a set created before an interruption. It now probes GetStickerSet first and adopts when the old set exists. Adds R11 — whether a deleted slug can be reclaimed is undocumented and unresolvable without a live bot. Does not block the URL-change path, which needs a different name. Settled by a new Phase 6 smoke step. Phase 1 unchanged.