Skip to content

v0.6.8 — Custom paths for WEB!

Latest

Choose a tag to compare

@github-actions github-actions released this 30 Sep 16:15
a9f43cf

Released 2026-09-30.

Custom paths for WEB!

The optional web-proxy.base-path serves WEB under a custom URL path.
Separate instances can share the same public hostname and HTTPS port.

Path hosting requires matching Telego and Nginx configuration.
For example, base-path = "telegram/test" uses the Nginx route location ^~ /telegram/test/.
Nginx forwards that route to the private WEB listener and preserves the complete path.
The proxy_pass value must have no URI suffix or trailing slash.

The generate command accepts --web-base-path with --web-host.
Generated links use the path-bound capability format.
Requests with recognized WEB credentials cannot reach the ordinary website through an incorrect path.

Existing root links retain their credential format. Path links require a Telegram client with WEB base-path support.
A base-path change requires new links and a service restart.

The WEB guide describes the path configuration and Nginx requirements.

Recovery and carrier changes

  • The gateway installer and examples now select websocket, which shares one connection across Telegram streams.
  • Repeat installations preserve the saved carrier. Explicit carrier values remain unchanged, and an absent carrier still selects https.
  • websocket-lanes remains available for separate stream queues. It requires more connections and handshakes, and does not guarantee higher throughput.
  • A client CLOSE now cancels a pending WebSocket lane immediately. The bridge releases its socket, timer, queued data, and lane reservation.
  • Established bridges can recover within the page after a carrier failure or server restart. Each attempt has a 15-second total limit.
  • Recovery closes retired streams and discards their queued data. Telegram opens replacements without a second WELCOME.
  • An online or visible-page event can start recovery after 30 seconds without stream activity.

Carrier selection stays explicit. Recovery uses the configured carrier and returns control to Telegram if the attempt fails.
Recovery does not move active MTProto streams or replay data across sessions.
Detailed browser reports remain disabled unless the log level is debug or trace.

Reliability fixes

  • WebSocket input stays within its memory limit during uplink backpressure.
  • Late frames from closed streams cannot enter a replacement session.
  • Excess streams close individually while existing streams continue, including WebSocket lanes that await socket closure.
  • Automatic configuration reload survives atomic file replacement and changes to symlink targets.
  • Restart warnings remain visible until the process restarts or the configuration returns to its active values.
  • DC socket closure no longer uses positive linger, which can block an event loop during network failures.
  • TLS handshakes read cached certificates and ServerHello templates without network fetches. Background refresh retains the last valid template after failure.
  • Metrics listeners now return bind errors and apply HTTP timeouts even when diagnostics are disabled.

Configuration changes

Telego now rejects unknown TOML keys, negative limits, and invalid TLS ports.
Correct fields named in configuration errors before restarting. Zero retains its documented default or unlimited meaning.
Invalid metrics paths return an error instead of causing a startup panic.

Security fixes

  • The Nginx fallback preserves URL escape sequences. Encoded path characters can no longer become query delimiters or extra upstream headers.
  • WEB credential detection recognizes equivalent query, bearer, and base64 spellings. These requests receive sanitized fallback instead of forwarding credentials to the ordinary website.
  • ServerHello refresh rejects malformed upstream responses before they enter the cache. Failed refresh no longer causes a parser panic or replaces a valid template.
  • Middle-End rejects nonpublic server addresses before any direct connection, SOCKS request, or NAT discovery.
  • The SYN limiter matches the original published Docker port after address translation. Rule removal preserves rules for other ports.

The credential protection also covers recently retired session tokens. Carrier authentication still requires canonical credentials.
The WEB credential fixes require both the Telego update and the Nginx configuration change below.

Nginx upgrade step

Existing WEB installations need the corrected Nginx fallback configuration. Updating the Telego binary or container does not update Nginx.

Add the $telego_sanitized_uri map to the Nginx http block:

map $request_uri $telego_sanitized_uri {
    ~^(/[^?]*) $1;
    default /;
}

In @telego_sanitized, replace proxy_pass http://public_site$uri; with:

proxy_pass http://public_site$telego_sanitized_uri;

Run nginx -t in the Nginx service environment. If validation succeeds, reload Nginx with nginx -s reload.

The updated gateway and manual templates include this correction.

After the upgrade, reconnect WEB clients to load the updated browser code.

Full changelog: v0.6.7…v0.6.8