What's Changed
New features
- Two ways of getting updates: a webhook, or a long polling script run from cron for an instance not reachable from the Internet — it needs no certificate and no inbound access.
- Account linking by a PIN code: the bot shows a code in the chat, the user enters it on the Telegram page of My Account; wrong codes are rate limited. The confirmation link stays available, alone or next to the code.
- Unlinking a Telegram account from the chat (
/stop), by the user on the Telegram page of My Account or by an administrator; the binding is released when the MantisBT user is deleted. - Broadcast messages with files to the Telegram chats of the members of chosen projects, with per-user and per-project permissions.
- Guided issue creation covering every field of the report form: custom fields of all types, the monitors of the new issue (#38), the required fields first, going back to any answered step, skipping optional fields, an inline calendar for dates and field labels in bold on the dialog card.
- Update an issue from the chat: pick it by project and filter, then change its status the way the status change page of MantisBT does.
- Integration with the Calendar plugin 3.0.0+: create events from the chat, notifications about created, changed and deleted events, membership changes and replies with an optional
.icsfile, reminders, replies to invitations and snoozing from the buttons under a notification. - The answer of the bot about added content links to the new note or issue,
/startshows the linked MantisBT account, a refused file type is answered with the allowed extensions. - The bot speaks the language of the user: a chat not linked yet gets the language of its Telegram client, a linked one the language of the MantisBT account, and the "auto" preference follows the Telegram client as well (#49).
- Translations updated: English, Russian, Spanish.
Security fixes
- Private notes no longer leak into notifications: a notification could carry the latest note of an issue regardless of its view state, together with its time tracking. Only the notes visible to the recipient are used now. Earlier versions are affected as well.
- The account linking link can no longer be forged: it carried only the public Telegram user id, so a link with a foreign id sent to a MantisBT user bound the sender's Telegram to that account with one click. The link now carries a one-time token valid for 15 minutes, the confirmation page names the Telegram account being linked, "No" cancels the link, and an existing binding is never replaced silently — neither by a link nor by a PIN code.
- The bot token no longer reaches the chat, the logs or the webhook URL: the text of an exception, which for a network error quotes the request URL with the token, is replaced by a general message, and the details are logged with the token masked. The webhook is verified by a random secret in the
X-Telegram-Bot-Api-Secret-Tokenheader. - Inline buttons are checked on the server the way a web form is: an issue, a project or a value is accepted only when it would be offered to the user now.
- The status change from the chat applies the checks of the core:
update_bug_status_threshold, the workflow, the resolution rules, the version and handler thresholds, all read for the project of the issue. - A note added by replying to a notification follows
default_bugnote_view_statusand the note thresholds of the issue. - Saving the plugin settings asks for re-authentication and checks
manage_plugin_threshold, the binding confirmation carries a CSRF token, the redirects after saving the preferences are sanitized, and the settings and the data of the Telegram API are escaped on output. - Updates from groups and channels are ignored: the bot works in private chats only.
- Files received from Telegram are kept in a private temporary directory and removed right after use; the debug log accepts only a
.logor.txtfile outside the web root. - The release archive no longer contains the utility scripts, tests and SQL dumps of the dependencies, and the release workflow pins its actions by commit.
Fixes
- The schema step failing on MantisBT 2.27.3 and higher (
APPLICATION ERROR #2503 ERROR_PLUGIN_UPGRADE_FAILED). - Followed the core changes of MantisBT 2.28: disabled categories, profiles, textarea length, integer category id.
- Compatibility with PHP 8.4; the deprecation notices of the bundled Telegram library no longer reach the pages.
- The due date picked in the chat was silently dropped when the issue was created.
- An issue draft is bound to the message it was started from: a second "Create issue" card no longer drives the same draft.
- The debug log of the Telegram connection works again.
- A notification about a note consisting of files only lists the attached files (#56).
- The handler list no longer fails with
400 Bad Requestwhen a project has many users: the user lists are shown page by page (#39). - The long polling script no longer carries the context of one update — the current project, a notification flag — over to the next one.
- A self-signed webhook certificate is passed to Telegram correctly; the plugin entries of the issue history are localizable.
Upgrade notes
- The upgrade migrates the schema of the plugin and cannot be undone by putting the old files back — back up the database before it; the upgrade asks to confirm the backup before any change. Replace the contents of
plugins/TelegramBotcompletely with the folder from the archive, then click Upgrade against TelegramBot on the Manage Plugins page. - Save the plugin settings once after the upgrade: in the Webhook mode this reinstalls the webhook without the bot token in its URL. Until then the old webhook keeps working and the settings page shows a warning.
- Issue a new bot token with @Botfather and enter it in the settings: earlier versions put the token into the webhook URL, so it may be stored in the access logs of the web server.
- An issue draft started in the chat before the upgrade loses its attached file — send the file again.
- The 1.6 line is closed: users of 1.6.0 should upgrade to 2.0.0.
Requirements
- MantisBT 2.26.0 or newer, verified up to 2.28.4. PHP as required by the MantisBT release: 7.2.5 for 2.26.x, 7.4.0 for 2.27.0 and newer; tested up to PHP 8.4.
- The Calendar integration is optional and requires Calendar 3.0.0 or newer; an older Calendar is ignored.
- For MantisBT 2.14 – 2.25.x use release-1.5.1.
Download
TelegramBot-release-2.0.0.zip in the Assets below — it already contains the dependencies.
Full Changelog: release-1.6.0...release-2.0.0