Files
telegram-shop/VERSION.md
NW bd3391c111 fix(bot): issue #127 — active-state sync, disabled-entity handling, double-tap lock, state reset
- BUG-01: getActiveLocationById + product availability checks (loc_active/cat_active) — disabled locations/categories filtered from bot menus
- BUG-02: graceful redirect to main menu (location_disabled notice) when entity disabled mid-flow, no crash in handleDistrictSelection/handleProductSelection/handleBuyProduct/handlePay
- BUG-03: per-user callback lock (LOCK_MS 1500ms debounce) in utils/callbackLock.js — duplicate taps dropped
- BUG-04: resetUserContext clears tracked photo/product messages + userStates on main-menu navigation and /start
- fix: handlePay uses validated numeric quantity (was raw string) for price/stock/purchase writes
- tests: 7 new (botBugFixes.test.js), updated userProductHandler tests — 30 total pass
- bump v1.2.2
2026-08-04 15:21:55 +01:00

3.0 KiB

Telegram Shop — Version History

How to update version

  1. Edit this file (VERSION.md)
  2. Add new entry under ## Changelog
  3. Bump version in src/admin/views/partials/app-sidebar.ejs
  4. Commit all changes together

Current Version

v1.2.2 — 2026-08-04

Changelog

v1.2.2 — 2026-08-04

  • fix: BUG-01 — disabled locations/categories/subcategories filtered from bot menus (getActiveLocationById, is_active checks)
  • fix: BUG-02 — graceful handling of disabled entity during purchase flow (location_disabled notice + main-menu redirect, no crash)
  • fix: BUG-03 — per-user callback lock (1500ms debounce) prevents duplicate messages on double-tap
  • fix: BUG-04 — resetUserContext clears stale inline keyboards/state on main-menu navigation and /start
  • fix: handlePay uses validated numeric quantity for price/stock/purchase writes (was raw string)

v1.2.1 — 2026-07-18

  • refactor: Removed deposit amount-selection step (redundant); deposit_wallet_ now goes directly to Mercuryo instructions
  • feat: Updated Mercuryo button text to include VISA/Mastercard branding in all locales
  • feat: Added deposit_important5 note about Mercuryo authorization limits and top-up reserve
  • fix: Enforced description + photo required in admin product create/update routes (products.js, catalogProducts.js)
  • fix: Added defensive guards in bot purchase display — description fallback and no-photo placeholder (userProductHandler.js)
  • feat: Added i18n keys products.no_description and products.no_photo in en/es/de
  • fix: Marked description and photo fields as required in admin forms (product-edit.ejs, products.ejs, catalog modal)
  • feat: Added edit + enable/disable (toggle is_active) UI for locations, categories, and subcategories in admin views (locations.ejs, categories.ejs, catalog.js buildTreeHtml)
  • feat: Added Categories nav item in admin sidebar (generated-navigation.ejs)

v1.2.0 — 2026-07-08

  • fix: Disabled CSRF checks in admin panel for Tor / onion zone compatibility
  • fix: Fixed "Invalid wallet type" error in Telegram bot purchase flow (main/bonus types added to validator)
  • feat: Added version history modal in admin sidebar

v1.1.0 — 2026-07-02

  • feat: Mercuryo gateway integration, crypto QR deposit, mono products, wallet auto-refresh
  • fix: CSRF cookie sameSite=false for Tor, auth cookie fix, async handlers
  • feat: Draggable dashboard panels + business KPI redesign
  • fix: SmartAdmin template redesign + security hardening

v1.0.0 — 2026-06-24

  • feat: Initial release — Telegram shop bot with admin panel
  • feat: Crypto wallets (BTC, LTC, ETH, USDT, USDC)
  • feat: Product catalog with locations, categories, subcategories
  • feat: Purchase system with hidden content delivery
  • feat: Admin panel with dashboard, wallets, users, purchases, audit log
  • feat: Tor proxy support (.onion access)
  • feat: i18n localization (en/es/de)