KeiSeiKit-1.0/_primitives/_rust/kei-telegram-webhook/src/context.rs
Parfii-bot 4dfe63b4e2 feat(kei-telegram-webhook): inbound Telegram webhook handler
Sibling to kei-notify-telegram (outbound only). This crate is the inbound
half of the Telegram Bot API integration — receives POST /webhook from
Telegram, verifies secret token, parses Update, emits typed WebhookEvent.

Architecture: handler-only. The crate exposes `handle_webhook` and the
parsed types; the consumer owns the axum::Router and the HTTP server.
This keeps kei-telegram-webhook composable into kei-buddy, kei-gateway,
or any other consumer without forcing a server topology.

Files (9 new, 484 LOC total, all under 200/file):
  * src/update.rs — lean Telegram Update / Message / User / Chat /
    CallbackQuery structs (only fields KeiBuddy needs: chat_id, from,
    text, message_id, date, callback_data; #[serde(default)] on optionals)
  * src/event.rs — WebhookEvent enum (Text / Callback / Other) +
    classify(update) -> WebhookEvent
  * src/handler.rs — axum handler with X-Telegram-Bot-Api-Secret-Token
    header verification (mismatch → 401)
  * src/context.rs — WebhookContext trait (consumer provides
    secret_token() + on_event())
  * src/error.rs — WebhookError via thiserror
  * src/lib.rs — module declarations + re-exports
  * Cargo.toml — workspace member, maturity = "alpha"
  * README.md — usage example (axum Router mount, 10-line snippet)

Tests (5 in src/event.rs + src/handler.rs, all pass):
  * classify_text_message — text Update → WebhookEvent::Text
  * classify_callback_query — callback Update → WebhookEvent::Callback
  * classify_other_returns_other — edited_message-only Update → Other
  * bad_secret_token_returns_401 — wrong header → 401 UNAUTHORIZED
  * good_secret_token_returns_200 — matching header → 200 OK

Verify-before-commit (RULE 0.13 §):
  * cargo check --offline -p kei-telegram-webhook: PASS
  * cargo test --offline -p kei-telegram-webhook --lib: 5 passed / 0 failed
  * cargo check --workspace --offline: PASS (no new warnings)

STATUS-TRUTH from agent: shipped=functional, stubs=0, behaviour-verified=yes.

Follow-up (deferred, not blocking):
  * axum is direct dep "0.7" in this crate + kei-cortex + kei-forge —
    workspace should adopt axum in [workspace.dependencies] for version
    unification (separate consolidation wave)
  * Unmodelled Telegram fields (edited_message, inline_query, photo,
    document, reply_markup) — extend when KeiBuddy needs them
2026-05-12 13:33:31 +08:00

24 lines
1,018 B
Rust

// SPDX-License-Identifier: Apache-2.0
//! `WebhookContext` — trait that consumer state types must implement.
//!
//! This trait is what the handler needs from the application's `axum::State`.
//! Consumers clone their state into every handler call (axum requirement).
use async_trait::async_trait;
use crate::event::WebhookEvent;
/// Contract between the handler and the consuming application.
///
/// Implement this on your axum `State` type, then pass `State<S>` to the
/// router. The handler calls [`WebhookContext::secret_token`] for HMAC-free
/// constant-time comparison and [`WebhookContext::on_event`] for dispatch.
#[async_trait]
pub trait WebhookContext: Clone + Send + Sync + 'static {
/// Return the secret token that was passed to `setWebhook`.
fn secret_token(&self) -> &str;
/// Handle a classified inbound event. Errors are logged but not surfaced
/// to Telegram — the handler always returns 200 on successful validation.
async fn on_event(&self, event: WebhookEvent);
}