rpc: show the real signup email in an email-signup account's own self view

An email-signup account's users.phone is a random, meaningless "888"
placeholder (see internal/domain/emailphone.go, cmd/createuser) -- the
account's own My Account / Edit Profile screen should show the email it
was actually created with instead, matching what an official client
displays there.

Only tgSelfUser substitutes signup_email for the phone; tgUser (how other
viewers see this account) is untouched, since the phone field there is
already privacy-gated and substituting the email would leak it past that
gate to anyone allowed to see a phone.
This commit is contained in:
Astra 2026-09-16 12:08:48 +01:00
parent d1af032fbf
commit 95c08f54bf
2 changed files with 63 additions and 1 deletions

View file

@ -13,13 +13,24 @@ func tgSelfUser(u domain.User) *tg.User {
if u.Deleted {
return &tg.User{ID: u.ID, Deleted: true}
}
phone := u.Phone
if u.SignupEmail != "" {
// Self view only: an email-signup account's users.phone is a random,
// meaningless "888" display number (see internal/domain/emailphone.go
// and cmd/createuser) -- showing the real signup email in its place is
// what the account's own My Account / Edit Profile screen should
// display. Never do this in tgUser (how *other* viewers see this
// account): the phone field there is already privacy-gated, and this
// would leak the email past that gate to anyone allowed to see a phone.
phone = u.SignupEmail
}
out := &tg.User{
ID: u.ID,
AccessHash: u.AccessHash,
FirstName: u.FirstName,
LastName: u.LastName,
Username: u.Username,
Phone: u.Phone,
Phone: phone,
Self: true,
Verified: u.Verified,
Scam: u.Scam,