Skip to content

Drive Telegram authentication and subscriptions through the browser - #2228

Merged
umputun merged 1 commit into
masterfrom
e2e-telegram-coverage
Sep 7, 2026
Merged

umputun merged 1 commit into
masterfrom
e2e-telegram-coverage

Conversation

@paskal

@paskal paskal commented Aug 27, 2026 •

Copy link
Copy Markdown
Collaborator

Telegram is the one authentication provider whose flow leaves the browser: the reader messages a bot, and no page can reach that. This makes the round trip drivable end to end, for both authentication and notification subscriptions.

backend/go.mod carries the released go-pkgz/notify v1.5.0 and go-pkgz/auth v2.3.0, both of which ship the settable bot API base this needs.

The fixture

e2e/telegramstub answers as the bot API for the four calls the flow makes, and takes the reader's side of the exchange through /control/send, which is the step inside Telegram that a browser cannot perform. It runs on its own instance, because adding an auth provider to the main one would change the auth panel every other case reads.

The setting it needs

Reaching a stub means the bot API base URL has to be settable, which is what --telegram.api-url adds. It serves a real operator need beyond the tests: a proxy or a self-hosted Bot API server, in places where Telegram is blocked. Both consumers honour it, the auth provider and the notification service. The value is an origin, and the bot token travels in the request path, so it has to be a host the operator controls.

Two defects the coverage found

An instance with Telegram authentication enabled and notifications failing registered the provider and then started nothing to listen with, so it accepted the configuration and stayed permanently deaf to it. And a nil *notify.Telegram was assigned into an interface, where it is not nil, so the guard downstream let it through.

What it adds to backend coverage

Measured with the e2e coverage reporting from #2232: the full browser suite run against an instrumented stack, once on #2232 alone and once with this change on top, so the only difference is this branch and its two Telegram tests.

37.9% to 40.4% of backend statements, +142 newly covered.

covered total
#2232 alone 1938 5099 37.9%
with this change 2080 5131 40.4%

The 32 extra statements in the denominator are this branch's own production code, so the gain is not an artefact of measuring less.

package before after newly covered
app/providers 0.0% 86.4% +19
app/notify 34.0% 46.4% +33
app/rest/api 40.0% 42.9% +44
app/cmd 30.6% 33.4% +34
app/store/service 48.6% 49.9% +9
app/store/engine 54.6% 55.1% +3

app/providers is the one worth pointing at. It holds a single function, DispatchTelegramUpdates, and nothing else in the suite reaches it: it was the only package at exactly 0% across the whole e2e run. The two defects above are covered rather than only fixed, at 83.3% for makeTelegramAuth and 64.7% for startTelegramAuthAndNotify.

@github-actions

github-actions Bot commented Aug 27, 2026 •

Copy link
Copy Markdown

size-limit report 📦

Path Size
public/embed.mjs 2.05 KB (0%)
public/remark.mjs 53.74 KB (+0.12% 🔺)
public/remark.css 7 KB (+0.02% 🔺)
public/last-comments.mjs 17.33 KB (0%)
public/last-comments.css 3.22 KB (0%)
public/deleteme.mjs 2.98 KB (0%)
public/counter.mjs 731 B (0%)

@paskal
paskal force-pushed the e2e-telegram-coverage branch from fbdd684 to 40cadcd Compare August 27, 2026 11:07
@codecov

codecov Bot commented Aug 27, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 73.98%. Comparing base (d8c8ba8) to head (a66bc17).
⚠️ Report is 4 commits behind head on master.

Additional details and impacted files
@@            Coverage Diff             @@
##           master    #2228      +/-   ##
==========================================
+ Coverage   73.83%   73.98%   +0.14%     
==========================================
  Files         129      129              
  Lines        3727     3736       +9     
  Branches      860      865       +5     
==========================================
+ Hits         2752     2764      +12     
+ Misses        969      966       -3     
  Partials        6        6              
Flag Coverage Δ
unit 100.00% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@paskal
paskal force-pushed the e2e-telegram-coverage branch 9 times, most recently from e986793 to dfaa780 Compare August 29, 2026 08:37
@paskal
paskal marked this pull request as ready for review August 29, 2026 23:10
@paskal
paskal requested a review from umputun as a code owner August 29, 2026 23:10
Copilot AI lite review requested due to automatic review settings August 29, 2026 23:10

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@umputun

umputun commented Aug 30, 2026

Copy link
Copy Markdown
Owner

tags are cut, so the pins can become released versions: go-pkgz/auth v2.3.0 and go-pkgz/notify v1.5.0. The auth tag is on master head 5f6d12c4, one commit past d9c7fd35, which adds a test race fix and no behaviour.

one more thing while you are in there: #2232 is merged, and coverage.sh takes both its must-produce-coverage list and its merge inputs from compose-e2e-coverage.yml alone. remark42-telegram is only in the base compose file, so without a stanza there with its own GOCOVERDIR and mount, make e2e-cover skips the Telegram instance and still reports success.

rest of the PR reads fine to me.

Telegram is the one auth provider whose flow leaves the browser: the
reader messages a bot, and no page can reach that. e2e/telegramstub
answers as the bot API for the four calls the flow makes and takes the
reader's side of the exchange through /control/send, so the round trip
becomes drivable end to end. It runs on its own instance, because adding
a provider to the main one would change the auth panel every other case
reads.

Reaching it needs the bot API base url to be settable, which is what
--telegram.api-url adds. It serves a real operator need beyond the tests,
a proxy or a self-hosted Bot API server where Telegram is blocked, and
both consumers honour it: the auth provider and the notification service.
The value is an origin, and the token travels in the request path, so it
has to be a host the operator controls.

Writing the coverage found two defects in the wiring. An instance with
telegram auth enabled and notifications failing registered the provider
and never started anything to listen, so it accepted the configuration
and stayed permanently deaf. And a nil *notify.Telegram was assigned into
an interface, where it is not nil, so the guard downstream let it through.

The subscription panel needed three fixes of its own. Resubscribing set the
step back without requesting a new token, so the panel offered a link built
from one the backend had already discarded. A failure stayed on screen after
the next call succeeded, because neither the check nor the unsubscribe
cleared it. And the message had nowhere to render outside the initial step,
so a failure in the other two was silent.

The settable API base reaches the notification service through go-pkgz/notify
v1.5.0 and the auth provider through go-pkgz/auth v2.3.0, both released.

compose-e2e-coverage.yml gains the Telegram instance. coverage.sh takes the
services it must see a profile from, and the directories it merges, from that
file alone, so an instance present only in the base stack is skipped and the
run still reports success on a total that quietly omits it.
@paskal
paskal force-pushed the e2e-telegram-coverage branch from dfaa780 to a66bc17 Compare August 30, 2026 01:21
@paskal

paskal commented Aug 30, 2026

Copy link
Copy Markdown
Collaborator Author

Both pins are the released tags now, and the branch is rebased onto master.

compose-e2e-coverage.yml gains the remark42-telegram stanza; it was being skipped exactly as you describe.

@umputun
umputun merged commit 9b3e54c into master Sep 7, 2026
23 checks passed
@umputun
umputun deleted the e2e-telegram-coverage branch September 7, 2026 19:27
@paskal paskal added this to the v1.17.0 milestone Sep 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants