Files
pezkuwi-telegram-miniapp/scripts/setup-telegram-webhook.sh
T
pezkuwichain 0dd4d3d62b fix(security): remove hardcoded bot token from webhook setup script
Token was committed in plaintext since the initial commit in a public
repo and was used to deface the bot profile. Script now requires
BOT_TOKEN via environment variable instead.
2026-07-11 13:42:51 -07:00

38 lines
1.1 KiB
Bash
Executable File

#!/bin/bash
# PezkuwiChain Telegram Bot Webhook Setup
# Run this script from a machine that can access Telegram API
# Usage: BOT_TOKEN="..." ./scripts/setup-telegram-webhook.sh
if [ -z "$BOT_TOKEN" ]; then
echo "Error: BOT_TOKEN environment variable is not set."
echo "Usage: BOT_TOKEN=\"<token>\" ./scripts/setup-telegram-webhook.sh"
exit 1
fi
WEBHOOK_URL="https://vbhftvdayqfmcgmzdxfv.supabase.co/functions/v1/telegram-bot"
echo "Setting up Telegram webhook..."
echo "Bot Token: ${BOT_TOKEN:0:10}..."
echo "Webhook URL: $WEBHOOK_URL"
echo ""
# Delete any existing webhook
echo "Removing existing webhook..."
curl -s "https://api.telegram.org/bot$BOT_TOKEN/deleteWebhook" | jq .
# Set new webhook
echo ""
echo "Setting new webhook..."
curl -s "https://api.telegram.org/bot$BOT_TOKEN/setWebhook" \
-d "url=$WEBHOOK_URL" \
-d "allowed_updates=[\"message\",\"callback_query\"]" | jq .
# Verify webhook
echo ""
echo "Verifying webhook..."
curl -s "https://api.telegram.org/bot$BOT_TOKEN/getWebhookInfo" | jq .
echo ""
echo "Done! Test the bot by sending /start to @pezkuwichain_bot"