feat(telegram): port wave-1 fixes + @api set_secret write-door (DPLAN-0220)

Surfaced by a full completeness audit of the telegram skill against
TELEGRAM_PORT_MAP.md (366 tags, ~83% ported, 452/452 tests green).

@api — in-process set_secret(provider, slug, value, *, as_json) writer
mirroring get_secret (0o600 files / 0o700 dirs, no stdout echo). The store
was read-only; this is the GAP1 enabler the telegram mother-bot needs to
persist a created bot's config. 515 @api tests, seedgo 100%.

@skills telegram wave-1 (fix-forward, no deletions):
- GAP2: bot_factory + telegram-bot@.service launched a non-existent
  ~/.venv/bin/python3; now sys.executable -m ...base_bot (+ lib/__init__.py
  and lib/telegram/__init__.py for package resolution).
- Reboot survival: enable_service now installs the unit to
  ~/.config/systemd/user/ + daemon-reload (was never installed).
- GAP9: gitignore lib/telegram/.local/ so runtime state stops leaking to git.
- prax-monitor: log_streamer now resolves repo-root system_logs (honoring
  AIPASS_TEST_LOG_DIR) instead of a hardcoded ~/system_logs.

Verified: telegram 452/452 green (twice), base_bot imports via -m.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QEQZXCtgnF3NQtcttTErpq
This commit is contained in:
AIOSAI
2026-06-24 16:39:08 -07:00
co-authored by Claude Opus 4.8
parent 882da7cdfc
commit 0096aef1d2
11 changed files with 304 additions and 17 deletions
+29 -2
View File
@@ -9,17 +9,19 @@
"""
Secrets Module
Cross-branch in-process API for reading secrets from the provider store.
Cross-branch in-process API for the secrets provider store.
Consumers import directly instead of shelling out to the CLI.
Functions:
get_secret() - Read a secret by provider/slug
set_secret() - Write a secret to the provider store
list_secrets() - List available slugs for a provider
handle_command() - Route CLI commands (seedgo module discovery)
"""
import sys
from typing import Any, List, Optional
from pathlib import Path
from typing import Any, List, Optional, Union
from aipass.prax import logger # noqa: F401 — seedgo imports standard
from aipass.cli.apps.modules import console, header
@@ -42,6 +44,7 @@ def print_introspection():
console.print("[cyan]Available Workflows:[/cyan]")
console.print(" • get_secret() - Read secret by provider/slug")
console.print(" • set_secret() - Write secret to provider store")
console.print(" • list_secrets() - List slugs for a provider")
console.print()
@@ -96,6 +99,30 @@ def get_secret(provider: str, slug: str, as_json: bool = False) -> Optional[Any]
return result
def set_secret(provider: str, slug: str, value: Union[str, dict], *, as_json: bool = False) -> Path:
"""
Write a secret to the provider store.
This is the sanctioned cross-branch write path. Consumers call this
instead of shelling out to the CLI.
Args:
provider: Provider directory name (e.g., 'telegram')
slug: Secret identifier (without .json extension)
value: Secret value — string or dict
as_json: If True, json.dump the value; else write as plain string
Returns:
Path to the written file
Raises:
OSError: If directory creation or file write fails
"""
result = _handler.set_secret(provider, slug, value, as_json=as_json)
json_handler.log_operation("secrets_set", {"provider": provider, "slug": slug, "wrote": str(result)})
return result
def list_secrets(provider: str) -> List[str]:
"""
List available secret slugs for a provider.