applyPrivacy() had '!phoneAllowed && !isContact' which meant
contacts always saw the phone number regardless of the user's
privacy settings (e.g. 'Nobody'). Removed the isContact bypass
so privacy rules are enforced for everyone.
Keep bot credentials out of durable command results, fail bot deletion closed when session revocation fails, reject invalid scam/fake states at every write boundary, and make direct collectible grants a single replayable PostgreSQL aggregate.
Also lock admin gift sender/message limits and add regression coverage for rollback, replay, moderation constraints, and credential redaction.
Admin console additions (Layer 228):
- Give Gifts: dedicated tab with sorted Lottie/TGS gift picker + inline form; grant any catalog gift to a user/channel from 777000 (no charge)
- Upgraded/collectible delivery: mint a unique gift with admin-selected model/pattern/backdrop and custom number, or random/auto (DB FK + UNIQUE(gift_id,num) enforce invariants)
- SCAM/FAKE flags for users/channels (migration 0136) with configurable profile warning (TELESRV_SCAM_WARNING/TELESRV_FAKE_WARNING)
- Support toggle, force channel settings incl. gigagroup (migration 0137), username management, cosmetic color/emoji-status
- Emoji admin tab (custom emoji list + document IDs + Lottie/TGS preview)
- Bot management; soft UI / dark theme
Wired through Router -> admin.Service -> adminapi -> BFF -> React panel (en/zh/ru).
- Add a Bots admin tab: list/search bots with a dedicated read query
(users.is_bot, excluded from the accounts list), showing owner and
system-vs-user type
- Create system bots from the admin via a new bot.create command that
reuses the existing bot provisioning flow; the token is shown once
- Delete user-created bots via a new bot.delete command backed by a
dedicated Postgres DeleteBotAccount (revokes sessions, purges private
state, releases username, drops the bots row, tombstones the user);
system service bots are rejected
- Verified badge toggling reuses the existing set-verified command
- All write paths go through the dry-run/confirm + audit command pipeline
- Rebuild dist bundle
Sync telesrv 36eda30 (feat(communities): implement Layer 228 community aggregates).
Skipped telesrv docs changes per public sync rules; normalized the public appearance seed label.
Sync telesrv b96f2dd (feat(bot): complete keyboards callbacks and durable delivery).
Skipped private docs and preserved public README files per sync rules; normalized the appearance seed log label for public naming.
Sync telesrv 4c0e2d9 (feat: complete official star gift lifecycle and admin tooling).
Public adjustments: skipped private docs/deploy-nginx/README source changes, kept iamxvbaba/td public dependency, replaced local/private sample IP and orange seed label.