Releases: mantisbt-plugins/TelegramBot
Release list
release-2.0.0
What's Changed
New features
- Two ways of getting updates: a webhook, or a long polling script run from cron for an instance not reachable from the Internet — it needs no certificate and no inbound access.
- Account linking by a PIN code: the bot shows a code in the chat, the user enters it on the Telegram page of My Account; wrong codes are rate limited. The confirmation link stays available, alone or next to the code.
- Unlinking a Telegram account from the chat (
/stop), by the user on the Telegram page of My Account or by an administrator; the binding is released when the MantisBT user is deleted. - Broadcast messages with files to the Telegram chats of the members of chosen projects, with per-user and per-project permissions.
- Guided issue creation covering every field of the report form: custom fields of all types, the monitors of the new issue (#38), the required fields first, going back to any answered step, skipping optional fields, an inline calendar for dates and field labels in bold on the dialog card.
- Update an issue from the chat: pick it by project and filter, then change its status the way the status change page of MantisBT does.
- Integration with the Calendar plugin 3.0.0+: create events from the chat, notifications about created, changed and deleted events, membership changes and replies with an optional
.icsfile, reminders, replies to invitations and snoozing from the buttons under a notification. - The answer of the bot about added content links to the new note or issue,
/startshows the linked MantisBT account, a refused file type is answered with the allowed extensions. - The bot speaks the language of the user: a chat not linked yet gets the language of its Telegram client, a linked one the language of the MantisBT account, and the "auto" preference follows the Telegram client as well (#49).
- Translations updated: English, Russian, Spanish.
Security fixes
- Private notes no longer leak into notifications: a notification could carry the latest note of an issue regardless of its view state, together with its time tracking. Only the notes visible to the recipient are used now. Earlier versions are affected as well.
- The account linking link can no longer be forged: it carried only the public Telegram user id, so a link with a foreign id sent to a MantisBT user bound the sender's Telegram to that account with one click. The link now carries a one-time token valid for 15 minutes, the confirmation page names the Telegram account being linked, "No" cancels the link, and an existing binding is never replaced silently — neither by a link nor by a PIN code.
- The bot token no longer reaches the chat, the logs or the webhook URL: the text of an exception, which for a network error quotes the request URL with the token, is replaced by a general message, and the details are logged with the token masked. The webhook is verified by a random secret in the
X-Telegram-Bot-Api-Secret-Tokenheader. - Inline buttons are checked on the server the way a web form is: an issue, a project or a value is accepted only when it would be offered to the user now.
- The status change from the chat applies the checks of the core:
update_bug_status_threshold, the workflow, the resolution rules, the version and handler thresholds, all read for the project of the issue. - A note added by replying to a notification follows
default_bugnote_view_statusand the note thresholds of the issue. - Saving the plugin settings asks for re-authentication and checks
manage_plugin_threshold, the binding confirmation carries a CSRF token, the redirects after saving the preferences are sanitized, and the settings and the data of the Telegram API are escaped on output. - Updates from groups and channels are ignored: the bot works in private chats only.
- Files received from Telegram are kept in a private temporary directory and removed right after use; the debug log accepts only a
.logor.txtfile outside the web root. - The release archive no longer contains the utility scripts, tests and SQL dumps of the dependencies, and the release workflow pins its actions by commit.
Fixes
- The schema step failing on MantisBT 2.27.3 and higher (
APPLICATION ERROR #2503 ERROR_PLUGIN_UPGRADE_FAILED). - Followed the core changes of MantisBT 2.28: disabled categories, profiles, textarea length, integer category id.
- Compatibility with PHP 8.4; the deprecation notices of the bundled Telegram library no longer reach the pages.
- The due date picked in the chat was silently dropped when the issue was created.
- An issue draft is bound to the message it was started from: a second "Create issue" card no longer drives the same draft.
- The debug log of the Telegram connection works again.
- A notification about a note consisting of files only lists the attached files (#56).
- The handler list no longer fails with
400 Bad Requestwhen a project has many users: the user lists are shown page by page (#39). - The long polling script no longer carries the context of one update — the current project, a notification flag — over to the next one.
- A self-signed webhook certificate is passed to Telegram correctly; the plugin entries of the issue history are localizable.
Upgrade notes
- The upgrade migrates the schema of the plugin and cannot be undone by putting the old files back — back up the database before it; the upgrade asks to confirm the backup before any change. Replace the contents of
plugins/TelegramBotcompletely with the folder from the archive, then click Upgrade against TelegramBot on the Manage Plugins page. - Save the plugin settings once after the upgrade: in the Webhook mode this reinstalls the webhook without the bot token in its URL. Until then the old webhook keeps working and the settings page shows a warning.
- Issue a new bot token with @Botfather and enter it in the settings: earlier versions put the token into the webhook URL, so it may be stored in the access logs of the web server.
- An issue draft started in the chat before the upgrade loses its attached file — send the file again.
- The 1.6 line is closed: users of 1.6.0 should upgrade to 2.0.0.
Requirements
- MantisBT 2.26.0 or newer, verified up to 2.28.4. PHP as required by the MantisBT release: 7.2.5 for 2.26.x, 7.4.0 for 2.27.0 and newer; tested up to PHP 8.4.
- The Calendar integration is optional and requires Calendar 3.0.0 or newer; an older Calendar is ignored.
- For MantisBT 2.14 – 2.25.x use release-1.5.1.
Download
TelegramBot-release-2.0.0.zip in the Assets below — it already contains the dependencies.
Full Changelog: release-1.6.0...release-2.0.0
release-1.6.0
Installation Requirements
This version of the plugin is only for mantisbt >= 2.26.0 and up to mantisbt 2.27.2.
For mantisbt below version 2.26 use plugin version 1.5.1 (https://github.com/mantisbt-plugins/TelegramBot/releases/tag/release-1.5.1)
This version cannot be installed on mantisbt >= 2.27.3. The ADOdb library shipped with those releases no longer accepts one of the schema steps of the plugin, so a fresh installation stops with APPLICATION ERROR #2503 ERROR_PLUGIN_UPGRADE_FAILED. An instance where this version is already installed keeps working after the core is updated - the schema step was applied long before - but the plugin cannot be installed anew there. The 1.6 line receives no further releases; the fix is part of the upcoming version 2.0.0, which supports mantisbt 2.26 and higher.
Instructions for updating an already installed plugin
- Completely replace the contents of the plugins/TelegramBot folder with the contents of a similar folder from this release;
- Go to the "Manage Plugins" menu and click "Update" against the TelegramBot plugin.
What's Changed
- Added compatibility with mantisbt-2.26 and higher;
- Fixed bug of binding telegram user with 64x bit uid;
- Fixed compatibility issues with php 8.x;
- Fixed some parts of the code that caused errors in the plugin if the mantisbt configuration was set to strictly deal with non-essential errors;
- Restored ability to accept files as content to notes and create new issues;
Full Changelog: release-1.5.0...release-1.6.0
release-1.5.1
Installation Requirements
This version of the plugin is only for mantisbt below version 2.26.0.
For mantisbt >= 2.26 use plugin version 2.x (https://github.com/mantisbt-plugins/TelegramBot/releases/latest)
Instructions for updating an already installed plugin
- Completely replace the contents of the plugins/TelegramBot folder with the contents of a similar folder from this release;
- Go to plugins setting and click "Update" on the TelegramBot plugin;
- Go to the "Manage Plugins" menu and click "Update" against the TelegramBot plugin.
What's Changed
- Fixed bug of binding telegram user with 64x bit uid;
- Fixed compatibility issues with php 8.x;
- Fixed some parts of the code that caused errors in the plugin if the mantisbt configuration was set to strictly deal with non-essential errors;
- Restored ability to accept files as content to notes and create new issues;
Full Changelog: release-1.5.0...release-1.5.1
release-1.5.0
Added configuration page for notifications.
Added WebhookInfo diagnostic information display.
Improved error handling inbound requests through hook.php.
Added additional levels of logging connections and authorization process.
Added a hint in the proxy server address field.
release-1.4.1: Fixed error in localization files.
This caused incorrect behavior when sending notifications in some languages, as well as not the ability to customize the notification details for each user.
release-1.4.0
Added proxy and debug connections setting.
release-1.3.3: Added new function and bug fixes.
- POSTGRES support. - SOCKS5 support.
release-1.3.1: Added new functional, bug fixed
- Respond to chat alerts about events using the built-in function "Reply to message" - #4 Too many messages when a task status changes.
release-1.2.1: Small update
- Added translation into Spanish ( thanks to @manuel-jrs ); - Minor bug fixes.
release-1.2.0: Stable
Added notification of the message when: - creating an bug - change the status of the bug - adding a comment to the bug - mention of the user in the commentary