Skip to content

auth: save the api_id/api_hash once, and refuse official clients' api_ids - #37

Open
erfnzdeh wants to merge 4 commits into
mainfrom
feat/shared-api-credentials
Open

erfnzdeh wants to merge 4 commits into
mainfrom
feat/shared-api-credentials

Conversation

@erfnzdeh

@erfnzdeh erfnzdeh commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator

Every login needed --api-id and --api-hash-env again for each account, although one app registration at my.telegram.org serves them all. This saves it once.

tlgr auth api set          # at a terminal: explains my.telegram.org, prompts, hides the hash
tlgr auth api set 1234567 --api-hash-env TLGR_API_HASH   # scripted
tlgr auth api get          # masked; configured: false plus register_url when nothing is saved
tlgr auth api unset
tlgr auth send-code +98912... --alias work               # no --api-id needed any more

What changes

  • auth api get/set/unset (local ops, no daemon). The pair is written to ~/.tlgr/api.json at 0600 and added to the secret-file audit. A typo at the prompt is asked for again instead of exiting.
  • Resolution order for auth send-code, auth qr, account add and account import: flags, the account's own config.json, TLGR_API_ID/TELEGRAM_API_*, then the saved default. The default only fills in as a pair, and only when it is the same app as an id already given, so one app's hash is never sent with another app's id.
  • Existing accounts don't move. A login still copies the pair it used into the account, so a later auth api set of a different app leaves logged-in accounts alone. An account with no credentials of its own now falls back to the default instead of refusing to start.
  • Official clients' api_ids are refused by auth api set and by every login (exit 2): Telegram Desktop and its snap build, Android, iOS, macOS, Web, Telegram X, and tdesktop's published test pair. They're public in build files (e.g. tdesktop's snap/snapcraft.yaml), and logging in with them breaks Telegram's API terms and gets accounts banned. A hash that isn't 32 hex characters is refused the same way.
  • API_ID_INVALID / API_ID_PUBLISHED_FLOOD are now CONFIG_ERROR (exit 10) with a hint, instead of exit 1 with nothing.
  • Secret flag errors say --api-hash-env, not --api_hash-env.

Docs: README quickstart and login section, AGENT.md, SECURITY.md, the plugin skill, CHANGELOG, and regenerated reference pages.

Testing

  • make lint typecheck, tools/gen_docs.py --check: clean.
  • Full suite: 13370 passed. There are 18 new tests in tests/test_ops_auth.py::TestApiDefault and tests/test_errors_map.py. They cover 0600 storage, masking, idempotence, refusing official ids and bad hashes, the non-TTY explanation, prompt retry, pairwise fallback, and send-code through a live daemon with and without a default.
  • By hand in a scratch TLGR_HOME: drove the interactive prompt through a pty. The hash wasn't echoed, and a bad api_id was asked for again.

Release

The last commit bumps to 2.1.0 and dates the changelog section (## [2.1.0] - 2026-09-28, which also carries the chat poster list and chat list entries that have been on main since 2.0.1). tools/release_notes.py v2.1.0 agrees. After merge, tagging v2.1.0 runs release.yml and publishes tlgr-cli 2.1.0 to PyPI.

A missing variable said `--api_hash-env names X`: the message used the
request field name, but the flag the user typed is --api-hash-env. The
field in the error body stays the field name.
…errors that name the fix

Both arrived as a bare RPCError and exited 1 with no hint, although the
account is fine and what needs changing is the app the login used. They
are now CONFIG_ERROR (exit 10), pointing at tlgr auth api get / set.
…efuse official clients' api_ids

Every login needed --api-id and --api-hash-env again for each account,
although one registration at my.telegram.org serves them all. auth api
set saves the pair to ~/.tlgr/api.json at 0600 (prompting at a terminal,
the hash through getpass), auth api get shows it masked, auth api unset
forgets it. send-code, qr, account add and account import fall back to
it after the flags, the account's own file and the environment, and
only as a pair. A login still copies what it used into the account, so
changing the default never moves an existing account to another app.

The api_ids of Telegram's own apps (Desktop and its snap, Android, iOS,
macOS, Web, Telegram X) are refused by auth api set and by every login:
they are published in build files and copied into tools like this one,
and logging in with them gets accounts banned. A hash that is not 32 hex
characters is refused before it can surface as API_ID_INVALID.
auth api set saves one app registration for every login, and official
clients' api_ids are refused. chat poster list resumes long walks and
chat list no longer drops dialogs at a page boundary; both sat
unreleased on main since 2.0.1.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant