fix(security): remove hardcoded bot token from webhook setup script

Token was committed in plaintext since the initial commit in a public
repo and was used to deface the bot profile. Script now requires
BOT_TOKEN via environment variable instead.
This commit is contained in:
2026-07-11 13:42:51 -07:00
parent fd6b2cc28e
commit 0dd4d3d62b
3 changed files with 11 additions and 5 deletions
+1 -1
View File
@@ -1,6 +1,6 @@
{
"name": "pezkuwi-telegram-miniapp",
"version": "1.0.236",
"version": "1.0.237",
"type": "module",
"description": "Pezkuwichain Telegram Mini App - Forum, Announcements, Rewards",
"author": "Pezkuwichain Team",
+7 -1
View File
@@ -2,8 +2,14 @@
# PezkuwiChain Telegram Bot Webhook Setup
# Run this script from a machine that can access Telegram API
# Usage: BOT_TOKEN="..." ./scripts/setup-telegram-webhook.sh
if [ -z "$BOT_TOKEN" ]; then
echo "Error: BOT_TOKEN environment variable is not set."
echo "Usage: BOT_TOKEN=\"<token>\" ./scripts/setup-telegram-webhook.sh"
exit 1
fi
BOT_TOKEN="8548408481:AAEsoyiVBllk_x0T3Jelj8N8VrUiuc9jXQw"
WEBHOOK_URL="https://vbhftvdayqfmcgmzdxfv.supabase.co/functions/v1/telegram-bot"
echo "Setting up Telegram webhook..."
+3 -3
View File
@@ -1,5 +1,5 @@
{
"version": "1.0.236",
"buildTime": "2026-06-28T18:16:24.919Z",
"buildNumber": 1782670584920
"version": "1.0.237",
"buildTime": "2026-07-11T20:42:51.109Z",
"buildNumber": 1783802571110
}