Telegram github commits and releases
4.55K subscribers
601 files
20.3K links
Broadcast from the most important Telegram clients' repositories
Download Telegram
TGX-Android/Telegram-X/main4d6207e2 files, +45/-20
Fix `0 months` in `MessageGiftedPremium` and `MessagePremiumGiftCode`

TGX-Android/Telegram-X/maine9016591 files, +2/-1
Fix clipped buttons on calls screen

TGX-Android/Telegram-X/mainb8ee9ae2 files, +12/-3
Fix `MessageManagedBotCreated`

TGX-Android/Telegram-X/mainf43724a6 files, +59/-11
Fix strings in gifts

TGX-Android/Telegram-X/main6c4dc942 files, +12/-0
Support `PREMIUM_SUB_ACTIVE_UNTIL_` error

TGX-Android/Telegram-X/mainca180471 files, +7/-4
Display unpinned message in `Recent Actions`

TGX-Android/Telegram-X/mainbf670922 files, +2/-1
Optimize scrolling comments

TGX-Android/Telegram-X/main0d3ddc11 files, +1/-1
Version bump to `1806`

#tgxandroid
🫡3
telegramdesktop/tdesktop/dev2804e773 files, +524/-27
Added ability to select text in marquee label.

telegramdesktop/tdesktop/dev42510922 files, +14/-1
Added stop of marquee label scrolling for inactive window.

telegramdesktop/tdesktop/dev1b906a32 files, +39/-0
Added selection clearing on click outside marquee label.

telegramdesktop/tdesktop/dev4f8cd5d2 files, +2/-2
Update submodules.

telegramdesktop/tdesktop/devbaef81d8 files, +46/-13
Fix admin log section.

#tdesktop
🫡3
New telegramdesktop/tdesktop release: v7.1.2 (stable)

- Show who reacted preview next to the cursor.
- Improve restoring of opened windows and chats on relaunch.
- Don't hide content from screenshots while the app is passcode-locked.
- Fix saving of words with the system spellchecker.
- Fix sorting of unmuted unread chats in folders.
- Fix quote staying above the field after sending a message.
- Fix some WEB proxies not working on Windows.
- Warn about possible risks when adding a WEB proxy.
- Crash fixes.

#tdesktop
🫡3
telegramdesktop/tdesktop/dev9f9e3f71 files, +2/-2
Fix build with Qt 5.

telegramdesktop/tdesktop/dev37723376 files, +27/-15
Version 7.1.2.

- Show who reacted preview next to the cursor.
- Improve restoring of opened windows and chats on relaunch.
- Don't hide content from screenshots while the app
is passcode-locked.
- Fix saving of words with the system spellchecker.
- Fix sorting of unmuted unread chats in folders.
- Fix quote staying above the field after sending a message.
- Fix some WEB proxies not working on Windows.
- Warn about possible risks when adding a WEB proxy.
- Crash fixes.

#tdesktop
🫡3
telegramdesktop/tdesktop/public-canaryd33839d3 files, +0/-0
Delete unused account_check icon rasters

Task: 2026/08/18/delete-orphaned-account-check-icon

telegramdesktop/tdesktop/public-canaryfa5df572 files, +11/-2
Correct shared media index writes and viewer counts

Task: 2026/08/18/repair-shared-media-index-and-count-bookkeeping

telegramdesktop/tdesktop/public-canary96cc3091 files, +16/-3
Re-index a sent message only when its thread moves

Task: 2026/08/18/repair-shared-media-index-and-count-bookkeeping

telegramdesktop/tdesktop/public-canary77449fe2 files, +60/-6
Derive the pinned bar's topic root from the thread

Task: 2026/08/19/align-replies-thread-shared-media-attribution

telegramdesktop/tdesktop/public-canary22129a72 files, +1/-1
Pair the uploaded media edit's shared media removal

Task: 2026/08/19/pair-media-edit-removal-with-index-add

telegramdesktop/tdesktop/public-canaryaa882151 files, +20/-5
Drop a sent message from the shared media lists it left

Task: 2026/08/19/match-sent-message-removal-to-written-mask

telegramdesktop/tdesktop/public-canary4e4eab31 files, +3/-3
Don't keep a media reference across rich page changes

Task: 2026/08/19/refetch-saved-media-after-rich-page-changes

telegramdesktop/tdesktop/public-canary38cd5395 files, +30/-13
Don't lower shared media counts for unindexed messages

Task: 2026/08/20/stop-unmatched-removal-lowering-shared-media-counts

telegramdesktop/tdesktop/public-canary06488a97 files, +40/-56
Tie stored pinned index writes to the pinned flag

Task: 2026/08/19/unify-pinned-index-writers

telegramdesktop/tdesktop/public-canary12cc6d02 files, +52/-1
Write the pinned thread index only in forum peers

Task: 2026/08/20/stop-orphaning-general-id-shared-media-lists

telegramdesktop/tdesktop/public-canarya7ea40e2 files, +5/-2
Give a saved sublist its own pinned message list

Task: 2026/08/19/make-saved-sublist-pinned-bar-read-one-list

#tdesktop
🫡3
telegramdesktop/tdesktop/public-canary5cc1b1d1 files, +6/-0
Retire shared media of a deleted topic with no object

Task: 2026/08/20/retire-forum-media-lists-without-topic-objects

telegramdesktop/tdesktop/public-canary2c3422a5 files, +31/-0
Retire all topic shared media when a forum is destroyed

Task: 2026/08/20/retire-stranded-forum-media-keys-on-forum-teardown

telegramdesktop/tdesktop/public-canary5a814011 files, +6/-4
Guard the live-topic media unload against a zero root

Task: 2026/08/20/guard-live-topic-unload-against-zero-root

telegramdesktop/tdesktop/public-canary5f8c63f1 files, +6/-4
Guard the forum teardown media unload against a zero root

Task: 2026/08/20/guard-forum-teardown-unload-against-zero-root

telegramdesktop/tdesktop/public-canary3b96e2e2 files, +4/-4
Resolve the self peer sublist in the shared resolver

Task: 2026/08/20/resolve-self-peer-sublist-in-shared-resolver

telegramdesktop/tdesktop/public-canarye430baf2 files, +0/-2
Drop the write-only monoforum id from top controls

Task: 2026/08/20/retire-write-only-top-controls-monoforum-peer-id

telegramdesktop/tdesktop/public-canaryf26b5141 files, +1/-1
Read the inbox when a sublist has no parent chat

Task: 2026/08/20/restore-read-inbox-on-parentless-sublist-send

telegramdesktop/tdesktop/public-canary43046581 files, +2/-8
Use the shared sublist resolver in the player panel

Task: 2026/08/20/collapse-player-panel-sublist-onto-shared-resolver

telegramdesktop/tdesktop/public-canaryc83c8884 files, +35/-0
Request pinned messages when a pin is not loaded

Task: 2026/08/20/reach-unloaded-pin-on-complete-pinned-slice

telegramdesktop/tdesktop/public-canary334fbd86 files, +21/-10
Open a saved sublist's own shared media page

Task: 2026/08/20/open-saved-sublist-own-info-media-page

#tdesktop
🫡3
telegramdesktop/tdesktop/public-canary0bd680a9 files, +63/-43
Align sublist media count, query and window keys

Task: 2026/08/21/align-sublist-media-count-query-and-window-keys

telegramdesktop/tdesktop/public-canary7328cbe4 files, +55/-3
Keep Info pages on their topic or sublist

Task: 2026/08/21/preserve-info-thread-identity-and-lifetime

telegramdesktop/tdesktop/public-canaryf9a80111 files, +12/-10
Tear down Info after a sublist is destroyed

Task: 2026/08/21/preserve-info-thread-identity-and-lifetime

telegramdesktop/tdesktop/public-canary1d37f551 files, +14/-12
Clear Info immediately when its sublist dies

Task: 2026/08/21/preserve-info-thread-identity-and-lifetime

telegramdesktop/tdesktop/public-canary73542501 files, +9/-13
Always drop an Info wrap when its sublist dies

Task: 2026/08/21/preserve-info-thread-identity-and-lifetime

telegramdesktop/tdesktop/public-canary19829046 files, +90/-34
Reach unloaded pins on thread keys and updates

Task: 2026/08/21/reach-unloaded-pins-across-thread-and-update-paths

telegramdesktop/tdesktop/public-canarydd6e4443 files, +11/-4
Rebind Info wrap teardown when a sublist is replaced

Task: 2026/08/21/resubscribe-info-wrap-teardown-on-replaced-sublist

telegramdesktop/tdesktop/public-canaryb8e81542 files, +14/-10
Tear down Layer Info instantly when its sublist dies

Task: 2026/08/21/resubscribe-info-wrap-teardown-on-replaced-sublist

telegramdesktop/tdesktop/public-canary6078ca82 files, +17/-14
Queue Info wrap teardown off sublist destroyed()

Task: 2026/08/21/resubscribe-info-wrap-teardown-on-replaced-sublist

telegramdesktop/tdesktop/public-canaryd46d78b3 files, +19/-21
Hide Layer Info before its sublist is erased

Task: 2026/08/21/resubscribe-info-wrap-teardown-on-replaced-sublist

telegramdesktop/tdesktop/public-canary735e4532 files, +15/-18
Preserve teardown stream across Info wrap removal

Task: 2026/08/21/resubscribe-info-wrap-teardown-on-replaced-sublist

#tdesktop
🫡3
telegramdesktop/tdesktop/public-canarye6f76c21 files, +0/-1
Remove stale Info teardown implementation note

Task: 2026/08/21/resubscribe-info-wrap-teardown-on-replaced-sublist

telegramdesktop/tdesktop/public-canaryc0483ec1 files, +3/-2
Keep saved sublists alive through item teardown

Task: 2026/08/21/finish-info-wrap-sublist-teardown-past-item-destroy

telegramdesktop/tdesktop/public-canaryead9ecb4 files, +39/-20
Align sublist media counts, windows and titles

Task: 2026/08/21/align-sublist-media-count-window-and-title

telegramdesktop/tdesktop/public-canary2ba13691 files, +7/-5
Show the new window tooltip only on entries that have one

Task: 2026/08/23/verify-saved-sublist-media-surfaces-and-gate-tooltip

telegramdesktop/tdesktop/public-canary09246a64 files, +90/-67
Unify sublist media window ids and persisted titles

Task: 2026/08/23/unify-sublist-separate-id-and-window-naming-rulings

telegramdesktop/tdesktop/public-canary9132e633 files, +26/-7
[ai] Refuse implausible test watchdog values

Task: 2026/08/23/refuse-implausible-test-watchdog-values

telegramdesktop/tdesktop/public-canarydaa4d1d1 files, +2/-2
Limit media topic context to forum chats

telegramdesktop/tdesktop/public-canary40510444 files, +7/-0
Add public keys for canary channel.

telegramdesktop/tdesktop/public-canary2ffa98f9 files, +1279/-0
Add v2 update verification core and build channels

telegramdesktop/tdesktop/public-canarydf971033 files, +672/-0
Support v2 channel packing in the Packer

telegramdesktop/tdesktop/public-canaryb5addae7 files, +662/-141
Verify, fetch and install v2 updates in the client

telegramdesktop/tdesktop/public-canary5f519592 files, +9/-1
Show canary version and skip changelogs on canary

#tdesktop
🫡3
telegramdesktop/tdesktop/public-canaryfa452272 files, +821/-0
Add focused tests for v2 update verification

telegramdesktop/tdesktop/public-canaryb1bcf901 files, +862/-0
Add canary build and publish workflow

telegramdesktop/tdesktop/public-canary0c2c3511 files, +186/-163
Build one canary lane per repository in CI

telegramdesktop/tdesktop/public-canary726fcf83 files, +31/-13
Use readable v2 update file names

telegramdesktop/tdesktop/public-canaryad601924 files, +117/-8
Use new update names and pinned Bot API image in CI

telegramdesktop/tdesktop/public-canary23287bd3 files, +108/-62
Ship per-arch mac updates with a universal installer

telegramdesktop/tdesktop/public-canary6181c831 files, +70/-28
Publish portable archives as canary first installs

telegramdesktop/tdesktop/public-canary26e85091 files, +5/-4
Drop the bundled d3d compiler from canary builds

telegramdesktop/tdesktop/public-canary6bd95083 files, +41/-4
Embed external and local signatures in one packer pass

telegramdesktop/tdesktop/public-canary10b552c2 files, +82/-3
Add a v2 update switch to the release build scripts

telegramdesktop/tdesktop/public-canaryec350451 files, +29/-1
Read the pinned metadata through the local Bot API

telegramdesktop/tdesktop/public-canarya7be4f63 files, +25/-1
Support v2 updates in the updater and deploy scripts

telegramdesktop/tdesktop/public-canaryc7bebf323 files, +872/-216
Harden canary builds running.

#tdesktop
🫡3
telegramdesktop/tdesktop/public-canaryfd5fe9a4 files, +20/-10
Fix build for Release.

telegramdesktop/tdesktop/public-canary15f2bd62 files, +68/-21
Try to fix signing.

telegramdesktop/tdesktop/public-canary8c74afe1 files, +77/-5
Improve caching.

telegramdesktop/tdesktop/public-canary69b6ab51 files, +17/-5
Try to fix signing again.

telegramdesktop/tdesktop/public-canary2078eec10 files, +598/-311
New names, separate publishing.

telegramdesktop/tdesktop/public-canarya460e667 files, +255/-6
Fix translocated launch on macOS.

telegramdesktop/tdesktop/public-canary1fc64304 files, +32/-14
Improve version display for canary.

telegramdesktop/tdesktop/public-canary417b0fa1 files, +141/-40
Split macOS canary build into per-arch jobs.

telegramdesktop/tdesktop/public-canary08bf1b27 files, +198/-3
Add an in-title CANARY/PRIVATE marking.

telegramdesktop/tdesktop/public-canary0eee2696 files, +42/-24
Rename canary branches.

telegramdesktop/tdesktop/public-canary2c1217f1 files, +3/-0
Fixed per-arch build picking universal crashpad handler.

telegramdesktop/tdesktop/public-canary61f84641 files, +11/-4
Keep TelegramForcePortable in portable archives.

telegramdesktop/tdesktop/public-canary6f655bb1 files, +11/-11
Allow CANARY_ALLOW_UNSIGNED in public lane too.

#tdesktop
🫡3
telegramdesktop/tdesktop/public-canary835582c1 files, +38/-3
Try workaround clone problems.

telegramdesktop/tdesktop/public-canaryee677301 files, +25/-19
Fix build with GCC.

telegramdesktop/tdesktop/public-canary88c10ec2 files, +36/-19
Fix public publishing.

telegramdesktop/tdesktop/public-canary2df28571 files, +1/-1
Removed stale comment about swscale destination format caching.

telegramdesktop/tdesktop/public-canaryc62c9741 files, +5/-0
Restricted transcode temp directory permissions to user.

Related commit: 0807483acc.

telegramdesktop/tdesktop/public-canary058e3082 files, +26/-6
Extracted video editor layer showing to shared helper.

telegramdesktop/tdesktop/public-canaryef9a5621 files, +26/-10
Extracted shared video encoder setup from H264 encoder.

telegramdesktop/tdesktop/public-canary71810502 files, +7/-3
Added VP9 encoder and webm muxer to ffmpeg build configs.

telegramdesktop/tdesktop/public-canarybb74f572 files, +150/-20
Added webm sticker output mode to video encoder.

telegramdesktop/tdesktop/public-canary03968847 files, +332/-69
Added adapting video stickers into custom emoji.

Related commit: 9895e5bb89.

telegramdesktop/tdesktop/public-canary51bbbf91 files, +6/-6
Keep canary artifacts for seven days

#tdesktop
🫡3
telegramdesktop/tdesktop/public-canaryad80ea04 files, +247/-106
Moved out corner status from view gif to separated module.

telegramdesktop/tdesktop/public-canarya6711d55 files, +169/-71
Moved out video message seek ring from view gif to separated module.

telegramdesktop/tdesktop/public-canary654e1685 files, +205/-46
Added seek ring with handle to paused video messages.

telegramdesktop/tdesktop/public-canarye8c7b4d4 files, +101/-15
Added frame preview while seeking in video messages.

telegramdesktop/tdesktop/public-canarya1ef6db8 files, +1143/-14
[iv-editor] Added slash menu with list of insertable blocks.

telegramdesktop/tdesktop/public-canary90ca5b32 files, +24/-1
[iv-editor] Added caret restore after inline button and formula edit.

Related commits: 3cb72867d6, 6b970dfee9.

telegramdesktop/tdesktop/public-canaryd2427e82 files, +68/-5
[iv-editor] Added restore of trimmed spaces on inline field commit.

Related commit: 4ddd36665b.

telegramdesktop/tdesktop/public-canary533144c1 files, +1/-1
Fixed macOS libraries prune dropping pkg-config files for FFmpeg build.

#tdesktop
🫡3
UnigramDev/Unigram/scroll-anchoringbc2b6b88 files, +465/-168
Anchor the message list per mutation instead of a global scroll mode

#unigram
UnigramDev/Unigram/develop25eb8e11 files, +5/-5
Gate paste as formatted text behind Ctrl+Shift+V

UnigramDev/Unigram/developfd67a471 files, +1/-1
Fix theme glitch when opening search

UnigramDev/Unigram/developaeb5c551 files, +2/-5
Fix mouse over in send files popup

UnigramDev/Unigram/developc3bd9931 files, +2/-2
Hide "delete for both" if chat is empty

UnigramDev/Unigram/develop3be2d331 files, +3/-3
Pass zero instead of original size

UnigramDev/Unigram/developd5930171 files, +2/-1
Give a solid background to WindowPresenter

UnigramDev/Unigram/developfd98e5f24 files, +42/-72
Code cleanup and fix build on .NET Native

UnigramDev/Unigram/developf04652a4 files, +34/-5
Add some asserts to beta

UnigramDev/Unigram/develop15a16681 files, +1/-1
Bump version to 12.10

UnigramDev/Unigram/developea15e7632 files, +51/-38
TEMP: trace LoadMoreItemsAsync

UnigramDev/Unigram/developc3106b51 files, +21/-2
Make .NET 10 debug builds faster

UnigramDev/Unigram/develop1ea02a21 files, +27/-0
Forcefully include missing PDBs

UnigramDev/Unigram/develop8ce2e091 files, +102/-17
Add store builds support to .ps1

UnigramDev/Unigram/develope05117f1 files, +7/-0
Add flag to enable instrumentation

#unigram
DrKLO/Telegram/master3c0c32c300 files, +0/-241508
remove third_party libs

DrKLO/Telegram/master4f258525 files, +10/-2
add third_party libs as submodules

#android
🫡3
telegramdesktop/tdesktop/public-canaryc77db402 files, +54/-0
Added cache of participant ban state to chat participants API.

telegramdesktop/tdesktop/public-canaryaba92422 files, +53/-0
Added ban and unban of monoforum peer to sublist menus.

telegramdesktop/tdesktop/public-canary5005a0c3 files, +25/-0
[thanos] Fixed lost collapse animation on delete in new chat view.

telegramdesktop/tdesktop/public-canary100460b1 files, +21/-0
[thanos] Moved collapse gaps with content in history view list widget.

telegramdesktop/tdesktop/public-canarycb8e3201 files, +3/-0
[thanos] Added scroll pin after list resize during collapse.

telegramdesktop/tdesktop/public-canarye93fe9e1 files, +1/-1
[thanos] Replaced direct scroll with syntetic one during collapse.

telegramdesktop/tdesktop/public-canaryf29c9b63 files, +8/-1
[thanos] Fixed lost collapse for all but first of deleted messages.

telegramdesktop/tdesktop/public-canary6c5e79a4 files, +75/-43
[thanos] Replaced assumed collapse gap height with measured one.

telegramdesktop/tdesktop/public-canarycc374681 files, +20/-1
Fixed rich paste toast offering editor for plain text lists.

Related commit: 98591aa959.

telegramdesktop/tdesktop/public-canaryf6bc1ef1 files, +29/-0
Fixed missing ATL breaking breakpad build in canary Windows job.

#tdesktop
🫡3
DrKLO/Telegram/master62b56a046 files, +1122/-612
update to 12.10.1 (7038)

#android
🫡3
morethanwords/tweb/masterb6d3b0510 files, +281/-15
Support chat-specific hashtag and cashtag search

morethanwords/tweb/master293cb458 files, +233/-9
Stop a stalled spoiler renderer from bricking a chat

A chat with a media spoiler in it could become permanently impossible to open:
the container went active but the topbar and input kept their `hide` class, the
bubbles stayed in a detached `chatInner`, and nothing was logged anywhere.

The chain started at the shader fetch. `DotRendererCore.shaderTexts[url] ??= fetch(url)`
memoized the request forever, so once it stalled every later attempt inherited the
same dead promise; `init()` memoized its failure the same way. The worker only posts
`media-inited` after `init()` resolves, so `DotRenderer.mediaWorkerReady` — a static
deferred, with `mediaInited` latched true and no retry — stayed pending for the rest
of the session. `wrapMediaSpoiler` awaits it, so that bubble's render promise never
settled, and `processBatch`'s `Promise.all(...).catch(noop)` waited on it forever:
`.catch` covers a rejection, never an answer that simply does not arrive. Behind it
queued `performHistoryResult` and then `Chat.setPeerPromise`, and `setPeer`'s early
return on a pending `setPeerPromise` turned every retry into a silent no-op.

Bound each step so no single stuck promise can latch permanently:

* never memoize a failed shader fetch or a failed `init()`, and give the fetch a
timeout, so the next spoiler retries instead of inheriting a dead promise
* give up on the worker's `*-inited` answer after a deadline: resolve the deferred
(the spoiler degrades to its blurred thumbnail, which still covers the media) and
unlatch `*Inited` so the next spoiler re-sends the init
* bound `wrapMediaSpoiler`'s wait on the dot canvas — it is decoration on top of an
already-covering thumbnail and must never hold up the message batch
* bound the batch's media `Promise.all`; the bubbles are already built, so at worst
some media finishes loading after mount instead of before it
* expire the in-flight peer-change dedupe, so an abandoned change stops swallowing
every attempt to reopen the chat

Also fixes a null deref in `replaceSharedMediaTab`, which threw on `tab.container`
when both the previous tab and the new one were undefined, aborting the peer change
that called it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

morethanwords/tweb/master12fbb852 files, +119/-2
Isolate fastRaf callbacks so one throw cannot poison the batch

Callbacks batched into a single frame are unrelated to each other, but `fastRaf`
ran them with a bare `forEach`, so the first one to throw cancelled every callback
queued behind it. `fastRafPromise` resolves from a callback queued in exactly that
way and caches its promise in a module-level variable that is only cleared once the
promise resolves — losing that resolve leaves it pending forever, and every later
`fastRafPromise()` hands out the same dead promise. Awaiting one is enough to park
a render path for the lifetime of the tab, silently.

`fastRafConventional` had the same hazard with an extra edge: a throw escaping its
loop also left the queue non-empty and `processing` stuck true, degrading every
later call to synchronous execution.

Run each callback in isolation and log what it threw, so a broken callback fails
alone instead of taking the frame's other work with it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

#webk
🫡3
morethanwords/tweb/master12718821 files, +8/-8
Stop a read receipt from leaving two check marks on one message

An outgoing message in a group could end up rendering its sent and its read
status side by side — "18:11 ✓✓ ✓" — with the thread reply counter that used to
sit next to them gone.

setBubbleSendingStatus asked whether a status was already there with a
descendant query (`element.querySelector('.time-sending-status')`) but then
wrote over `element.firstElementChild`, which is only the same node while
nothing has been prepended in front of it. setBubbleRepliesCount prepends
exactly there: a message that gains its first thread reply after its bubble was
rendered gets `.time-replies` pushed ahead of the status. The next status change
— the read receipt — then replaced the counter instead of the old icon, and the
old icon stayed. Both carry `order: 5` against the time's `0`, so they line up
after the time in DOM order, newest first. The `!status` branch had the mirror
of the same bug: it removed the first child and left the status alone.

The two lookups now name the node they intend to touch, so a status replaces a
status and a missing one is prepended. setBubbleRepliesCount gets the same
direct-child scope: once the status bug had eaten the outer `.time`'s counter,
its descendant query found the copy inside `.time-inner`, concluded the counter
was already mounted and never restored it — leaving the hidden spacer that
reserves the footer's width one element short of what is drawn.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

morethanwords/tweb/mastera5a90e74 files, +64/-2
Keep tag search input focused

#webk
🫡3
morethanwords/tweb/master3501e7611 files, +107/-23
Take a frame's url and height as input rather than at face value

Three values a hosted frame — a mini app, a payment provider, an Instant View
embed — hands the client were used as given.

`path_full` from a `web_app_open_tg_link` event was pasted onto the bare host,
so a value that does not open with a slash landed in the host instead of the
path: '.evil.com/x' built https://t.me.evil.com/x. It walks out of the
registrable domain but not out of the client, because wrapUrl's t.me regexp is
not anchored at its end and matches the result anyway, handing it to the `im`
handler, which reads the parsed path and never the href — so the link opens a
username. Both call sites build it through `getWebViewTgLink` now, which anchors
the path.

`resize_frame` from an Instant View embed set the block height with no ceiling.
The event is the embed's own way of asking for the room its content needs, and
the document that sends it is third party by definition — after a navigation
away, not even the one the block asked for — so the height is capped at four
viewports.

`keyboardButtonUrlAuth.url` reached `window.open()` raw, the one url in the
client that skipped `safeWindowOpen`; the server rejects a non-https button url
today, which is what kept it out of reach. Its local `openWindow` wrapper is
gone. The helper it now shares, meanwhile, repeated wrapUrl's protocol filter
for none of its callers, and most of them pass a url straight off the wire — a
web app event, a gift's listing url, a bot's privacy policy. The filter lives in
`normalizeUrlProtocol` and runs there too, replacing the three hand-rolled
copies of it.

Untouched: the bridge still authorizes an inbound message by WindowProxy
identity alone unless the server asked for `same_origin`, and still answers a
frame it is not bound to at '*'. Binding it by default would break the
cross-origin hops the opt-in exists to permit — a 3DS redirect, an OAuth leg.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

#webk
🫡3