Telegram Mini App v1: initData auth bridge into the existing site
- POST /api/public/tg-webapp-auth: HMAC-verifies WebApp initData against the companion bot token (12h freshness, timing-safe), maps chat -> member via tg-links.json, mints a message session -> linked members land on /my/<id> with zero login - /app entry page (vendored telegram-web-app.js keeps CSP script-src 'self'); unlinked users get the one-time wallet-link instructions - tg-app.js on all pages: no-op in browsers; inside the webview lazy-loads the SDK, expands, themes header/background #071421, wires native BackButton - Bot menu button set programmatically to open /app; /start + help mention it - Synced chat.js canned answer + AI system prompt (Mini App facts) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
@@ -82,4 +82,4 @@
|
||||
<script src="/qrlib.js"></script>
|
||||
<script src="/fast-start.js"></script>
|
||||
<script src="/chat.js" defer></script>
|
||||
<script src="/translate.js" defer></script></body></html>
|
||||
<script src="/translate.js" defer></script><script src="/tg-app.js" defer></script></body></html>
|
||||
|
||||
Reference in New Issue
Block a user