Telemax/certs
Folist f6ee386a61 Аудит безопасности: HTTPS-панель, скоуп доверия CA, сериализация MAX-запросов
- redactSecrets: маскируются password/trackId/phone и любые строки от 512
  символов — пароль MAX больше не попадает в лог веб-панели открытым текстом
- Веб-панель по умолчанию работает по HTTPS с самоподписанным сертификатом
  (генерируется при первом старте в .data/tls); старые http-ссылки получают
  301-редирект на том же порту (polyglot по первому байту; resume строго в
  process.nextTick — иначе TLS-хендшейк зависает); /apikey даёт https-ссылку;
  PANEL_TLS=off для установки за своим reverse proxy
- Сертификаты Минцифры больше не доверяются всему контейнеру через
  NODE_EXTRA_CA_CERTS — src/max/ca.ts скоупит их только на соединения с MAX
  (ca в tls.connect + undici-агент для CDN-загрузок); Telegram и GitHub
  проверяются только по стандартным корням Mozilla
- Запросы одного опкода к MAX сериализуются (request() в client.ts) — два
  конкурентных MSG_SEND больше не перепутают messageId-связки редактирования
  и удаления
- Починена гонка первого чтения в ChatMapStore: конкурентные обращения
  форкали кэш, и часть upsert'ов молча терялась на диске
- Graceful shutdown по SIGTERM/SIGINT; в панели — реконнект WebSocket и
  периодическое обновление метрик; сравнение id в patchCachedChatLastMessage
  переведено на String() (BigInt-чаты не совпадали)
- Удалён мёртвый код: эндпоинты /api/debug/*, getPollVoters,
  createTelegramBot, цепочка historySynced, getChats(marker)
- React/Tailwind/lucide перенесены в devDependencies — рантайм-образ легче;
  vitest 4, npm audit: 0 уязвимостей; chmod 600 для .env в setup.sh/update.sh
- Новые тесты: redactSecrets, сторы (эвикшн/нормализация/конкурентность),
  сериализация запросов — всего 41
2026-08-14 21:13:26 +03:00
..
README.md Аудит безопасности: HTTPS-панель, скоуп доверия CA, сериализация MAX-запросов 2026-08-14 21:13:26 +03:00
russian_trusted_root_ca.crt Initial public release: MAX <-> Telegram bridge 2026-08-13 16:00:10 +03:00
russian_trusted_sub_ca.crt Initial public release: MAX <-> Telegram bridge 2026-08-13 16:00:10 +03:00

Russian Trusted CA bundle

russian_trusted_root_ca.crt and russian_trusted_sub_ca.crt are the official CA certificates from the Russian Ministry of Digital Development (Минцифры), downloaded from the well-known public distribution at gu-st.ru (the same files used broadly for accessing gosuslugi.ru and other .ru government-linked HTTPS services).

Needed because MAX's TLS certificate (*.oneme.ru) chains through this CA, which isn't in any standard public trust store (Mozilla/Debian/etc.) — without it, rejectUnauthorized: true fails with "unable to get local issuer certificate" (confirmed live on first Docker deploy, 2026-08-08).

Before trusting these files, their subject/issuer fields were checked against the actual certificate chain MAX presents (openssl s_client -connect 155.212.204.150:443 -servername api2.oneme.ru) — the sub CA's issuer matches the root CA's subject, and the root CA's issuer matches MAX leaf cert's issuer field exactly.

Scope of trust

These CAs are deliberately NOT installed system-wide (update-ca-certificates) or process-wide (NODE_EXTRA_CA_CERTS): either would make every TLS connection from the container — Telegram Bot API, GitHub — accept certificates issued by a state CA, which is exactly the MITM exposure such a CA enables. Instead, src/max/ca.ts reads these PEMs at runtime and applies them only to the two places that actually talk to MAX: the raw TCP client (tls.connect in src/max/client.ts) and the CDN up/downloads (maxFetch). Everything else is verified against Node's bundled Mozilla roots only.