From 82e0cc7059948dfc1385a02ebe35f456d3c89552 Mon Sep 17 00:00:00 2001 From: Aleksey Filippov Date: Wed, 3 Dec 2025 12:25:51 +0300 Subject: [PATCH] =?utf8?q?=D0=A3=D0=B4=D0=B0=D0=BB=D0=B5=D0=BD=D0=B8=D0=B5?= =?utf8?q?=20=D0=B8=D0=B7=20=D0=B4=D0=BE=D0=BA=D1=83=D0=BC=D0=B5=D0=BD?= =?utf8?q?=D1=82=D0=BE=D0=B2=20=D1=82=D0=BE=D0=BA=D0=B5=D0=BD=D0=BE=D0=B2?= MIME-Version: 1.0 Content-Type: text/plain; charset=utf8 Content-Transfer-Encoding: 8bit --- erp24/docs/api/api2/INTEGRATION_GUIDE.md | 4 ++-- erp24/docs/services/P3_FINAL_COMPLETION_REPORT.md | 4 ++-- erp24/docs/services/TelegramTarget.md | 12 ++++++------ 3 files changed, 10 insertions(+), 10 deletions(-) diff --git a/erp24/docs/api/api2/INTEGRATION_GUIDE.md b/erp24/docs/api/api2/INTEGRATION_GUIDE.md index 2fdd4a0d..54b44e78 100644 --- a/erp24/docs/api/api2/INTEGRATION_GUIDE.md +++ b/erp24/docs/api/api2/INTEGRATION_GUIDE.md @@ -54,7 +54,7 @@ Content-Type: application/json **Ответ**: ```json { - "access-token": "eyJ0eXAiOiJKV1QiLCJhbGc..." + "access-token": "111111111Gc..." } ``` @@ -79,7 +79,7 @@ Content-Type: application/json **Вариант 1: Заголовок (рекомендуется)** ```http POST /api2/client/balance -X-ACCESS-TOKEN: eyJ0eXAiOiJKV1QiLCJhbGc... +X-ACCESS-TOKEN: 11111111QiLCJhbGc... Content-Type: application/json { diff --git a/erp24/docs/services/P3_FINAL_COMPLETION_REPORT.md b/erp24/docs/services/P3_FINAL_COMPLETION_REPORT.md index 2212dc01..c7ec313f 100644 --- a/erp24/docs/services/P3_FINAL_COMPLETION_REPORT.md +++ b/erp24/docs/services/P3_FINAL_COMPLETION_REPORT.md @@ -104,8 +104,8 @@ **Строки:** 13-14 **Проблема:** ```php -public $botToken = "8063257458:AAGnMf4cxwJWlYLF1wS_arn4PrOaLs9ERQQ"; // ❌ Hardcoded! -public $chatId ="-1001861631125"; // ❌ Hardcoded! +public $botToken = "11111111"; // ❌ Hardcoded! +public $chatId ="11111111"; // ❌ Hardcoded! ``` **Влияние:** Credentials в коде → утечка в Git → компрометация Telegram бота diff --git a/erp24/docs/services/TelegramTarget.md b/erp24/docs/services/TelegramTarget.md index dd4bf038..c2e5a655 100644 --- a/erp24/docs/services/TelegramTarget.md +++ b/erp24/docs/services/TelegramTarget.md @@ -14,8 +14,8 @@ ## ⚠️ КРИТИЧЕСКАЯ ПРОБЛЕМА БЕЗОПАСНОСТИ ```php -public $botToken = "8063257458:AAGnMf4cxwJWlYLF1wS_arn4PrOaLs9ERQQ"; // ПУБЛИЧНЫЙ КОД! -public $chatId = "-1001861631125"; // ПУБЛИЧНЫЙ КОД! +public $botToken = "1111111"; // ПУБЛИЧНЫЙ КОД! +public $chatId = "111111111"; // ПУБЛИЧНЫЙ КОД! ``` **HARDCODED CREDENTIALS** в исходном коде → критическая уязвимость безопасности! @@ -155,8 +155,8 @@ return [ #### 1. Hardcoded Telegram credentials ```php -public $botToken = "8063257458:AAGnMf4cxwJWlYLF1wS_arn4PrOaLs9ERQQ"; -public $chatId = "-1001861631125"; +public $botToken = "1111111111"; +public $chatId = "11111111"; ``` **Риски:** @@ -237,8 +237,8 @@ return [ ]; // .env: -TELEGRAM_BOT_TOKEN=8063257458:AAGnMf4cxwJWlYLF1wS_arn4PrOaLs9ERQQ -TELEGRAM_CHAT_ID=-1001861631125 +TELEGRAM_BOT_TOKEN=11111111 +TELEGRAM_CHAT_ID=111111111 ``` ### 2. Отправлять ВСЕ сообщения -- 2.39.5