From 26d746abee2bb4400d7da06a9bb9ad3e02e33d6a Mon Sep 17 00:00:00 2001 From: Astra Date: Mon, 21 Sep 2026 15:46:50 +0100 Subject: [PATCH] Revert "rpc: show the real signup email in an email-signup account's own self view" This reverts commit 95c08f54bfcecf6c47e0e52e7382cf39f90637ea. --- internal/rpc/convert_users.go | 13 +------- internal/rpc/convert_users_test.go | 51 ------------------------------ 2 files changed, 1 insertion(+), 63 deletions(-) delete mode 100644 internal/rpc/convert_users_test.go diff --git a/internal/rpc/convert_users.go b/internal/rpc/convert_users.go index 80dd6381..8f27212b 100644 --- a/internal/rpc/convert_users.go +++ b/internal/rpc/convert_users.go @@ -13,24 +13,13 @@ func tgSelfUser(u domain.User) *tg.User { if u.Deleted { return &tg.User{ID: u.ID, Deleted: true} } - phone := u.Phone - if u.SignupEmail != "" { - // Self view only: an email-signup account's users.phone is a random, - // meaningless "888" display number (see internal/domain/emailphone.go - // and cmd/createuser) -- showing the real signup email in its place is - // what the account's own My Account / Edit Profile screen should - // display. Never do this in tgUser (how *other* viewers see this - // account): the phone field there is already privacy-gated, and this - // would leak the email past that gate to anyone allowed to see a phone. - phone = u.SignupEmail - } out := &tg.User{ ID: u.ID, AccessHash: u.AccessHash, FirstName: u.FirstName, LastName: u.LastName, Username: u.Username, - Phone: phone, + Phone: u.Phone, Self: true, Verified: u.Verified, Scam: u.Scam, diff --git a/internal/rpc/convert_users_test.go b/internal/rpc/convert_users_test.go deleted file mode 100644 index 7c33c288..00000000 --- a/internal/rpc/convert_users_test.go +++ /dev/null @@ -1,51 +0,0 @@ -package rpc - -import ( - "testing" - - "telesrv/internal/domain" -) - -// TestTgSelfUserShowsSignupEmailInPlaceOfDisplayPhone locks in that an -// email-signup account's own "My Account" view shows the real signup email -// instead of the meaningless random "888" display phone (see -// internal/domain/emailphone.go, cmd/createuser) -- matching what an -// official client's Edit Profile screen is expected to display. -func TestTgSelfUserShowsSignupEmailInPlaceOfDisplayPhone(t *testing.T) { - u := domain.User{ - ID: 42, - FirstName: "Ducky", - Phone: "88890942435", - SignupEmail: "ducky@zio.sh", - } - out := tgSelfUser(u) - if out.Phone != "ducky@zio.sh" { - t.Fatalf("tgSelfUser.Phone = %q, want signup email %q", out.Phone, "ducky@zio.sh") - } -} - -// TestTgSelfUserKeepsPhoneWithoutSignupEmail confirms an ordinary phone -// account's self view is unaffected. -func TestTgSelfUserKeepsPhoneWithoutSignupEmail(t *testing.T) { - u := domain.User{ID: 42, FirstName: "Real", Phone: "15550001234"} - out := tgSelfUser(u) - if out.Phone != "15550001234" { - t.Fatalf("tgSelfUser.Phone = %q, want unchanged phone %q", out.Phone, "15550001234") - } -} - -// TestTgUserNeverLeaksSignupEmail confirms the privacy boundary: how *other* -// viewers see this account must never substitute the email for the phone -- -// only the account's own self view (tgSelfUser) does that. -func TestTgUserNeverLeaksSignupEmail(t *testing.T) { - u := domain.User{ - ID: 42, - FirstName: "Ducky", - Phone: "88890942435", - SignupEmail: "ducky@zio.sh", - } - out := tgUser(u) - if out.Phone != "88890942435" { - t.Fatalf("tgUser.Phone = %q, want raw display phone %q (email must not leak to other viewers)", out.Phone, "88890942435") - } -}