mirror of
https://github.com/tiennm99/tiennm99bot.git
synced 2026-10-11 03:13:46 +00:00
Plan for internal/modules/sticker: public, multi-pack-per-user Telegram sticker set management using @Stickers command names, single-shot reply+args instead of a conversational flow. Six phases, 117 tasks. Phase 1 covers two shared-code prerequisites the module would otherwise expose: no panic barrier on the update path, and a test harness that cannot return structured API results. Researched against the live Bot API and red-teamed by three adversarial reviewers; 16 findings accepted, recorded in plan.md. Notable corrections: - MODULES is not opt-in; an empty value loads every module, so the factories() entry is itself the enablement - getStickerSet exposing no owner does not force "orphans cannot be adopted"; a write-ahead intent record makes recovery sound - the file-download URL embeds the bot token and reaches the dispatcher log through url.Error, which logging file_id does not prevent - /packlist ran ten API calls under a 60s per-call ceiling, a worse stall than the photo pipeline the plan had been guarding - the /delsticker probe deleted a live pack's record on any transient error - /help has 884 runes of headroom for nine new commands