feat: Telegram V3 — Mini App cockpit (initData auth + /tg surface) (#554)

* feat(telegram): Mini App auth — initData validation mints the cloud-auth session cookie

* feat(panel): /tg Mini App cockpit — approvals, inbox, read-only board, A2A chat

* fix(telegram,panel): unconditional webapp-auth rate limit, future-dated initData rejection, anchored /tg matcher

* docs(map,rag): Telegram Mini App auth route, initData validator, (tg) surface

---------

Co-authored-by: Renn F <rennf93@users.noreply.github.com>
This commit is contained in:
Renzo F
2026-07-18 02:47:59 +02:00
committed by GitHub
co-authored by Renn F
parent 3b88c706dd
commit c40a7a39c3
33 changed files with 1725 additions and 27 deletions
+3 -1
View File
@@ -34,7 +34,9 @@ class _BrokenRedis:
def _app(redis: Any) -> FastAPI:
app = FastAPI()
app.state.login_redis = redis
app.add_middleware(LoginRateLimiter, prefix="/auth", max_attempts=3, window=60)
app.add_middleware(
LoginRateLimiter, paths=("/auth/login",), max_attempts=3, window=60
)
@app.post("/auth/login")
async def login() -> dict[str, bool]: