Skip to content

Pin Telegram host-ingress verifier fail-closed - #5143

Merged
hanakannzashi merged 1 commit into
manifest-driven-ingress-contractfrom
codex/manifest-ingress-finish
Jun 24, 2026
Merged

hanakannzashi merged 1 commit into
manifest-driven-ingress-contractfrom
codex/manifest-ingress-finish

Conversation

@hanakannzashi

Copy link
Copy Markdown
Contributor

Summary

  • add a Telegram host-ingress registry regression proving shared-secret-header policy cannot be satisfied by webhook-signature verifier bindings
  • update the manifest-driven channels plan to reflect completed transport/auth and generic serve-plan work

Tests

  • cargo fmt --check
  • cargo test -p ironclaw_host_ingress_registry
  • cargo test -p ironclaw_host_api ingress --lib --tests
  • cargo test -p ironclaw_reborn_composition host_ingress_serve_plan --lib --features slack-v2-host-beta,telegram-v2-host-beta

Base: stacked on manifest-driven-ingress-contract; no #5100 Telegram community implementation files changed.

@coderabbitai

coderabbitai Bot commented Jun 23, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

🗂️ Base branches to auto review (2)
  • staging
  • reborn-integration

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 44955430-0e33-4fcb-8caa-7b877a7b8994

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added scope: docs Documentation size: S 10-49 changed lines risk: low Changes to docs, tests, or low-risk modules contributor: core 20+ merged PRs labels Jun 23, 2026

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request adds a unit test to verify that the Telegram auth binding verifier does not fall back to a webhook signature, and updates the manifest-driven channels planning document to mark Move 2 and Move 4 as completed, detailing the current state of the transport model unification and the collapse of the serve.rs per-channel sprawl. There are no review comments, and I have no feedback to provide.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

@hanakannzashi
hanakannzashi requested a review from serrrfirat June 23, 2026 06:27
@hanakannzashi
hanakannzashi merged commit ea04b3e into manifest-driven-ingress-contract Jun 24, 2026
16 checks passed
@hanakannzashi
hanakannzashi deleted the codex/manifest-ingress-finish branch June 24, 2026 10:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: low Changes to docs, tests, or low-risk modules scope: docs Documentation size: S 10-49 changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant