{"_id":"@acegalaxy/ott-gateway","_rev":"3-dc614d0b43f0a9a47acb83f041255476","name":"@acegalaxy/ott-gateway","dist-tags":{"latest":"0.1.2"},"versions":{"0.1.0":{"name":"@acegalaxy/ott-gateway","version":"0.1.0","keywords":["ott","telegram","whatsapp","bot","security","gateway","authz"],"author":{"name":"ACE Galaxy","email":"hello@acegalaxy.co"},"license":"MIT","_id":"@acegalaxy/ott-gateway@0.1.0","maintainers":[{"name":"kanelr","email":"lanhnk@acegalaxy.co"}],"homepage":"https://github.com/acegalaxy-co/ace_commons-ott-gateway-nodejs#readme","bugs":{"url":"https://github.com/acegalaxy-co/ace_commons-ott-gateway-nodejs/issues"},"dist":{"shasum":"f7fbf6ae23b87639554d8f1294456623b26c02d6","tarball":"https://registry.npmjs.org/@acegalaxy/ott-gateway/-/ott-gateway-0.1.0.tgz","fileCount":42,"integrity":"sha512-nWBSwQW3c/p6PCOyWpIUC/elM07CDMG+s+ADvYWlEuJFd5l91310+C2wRaVHAFBESalb/FtnxaLzP8oNFjpyAw==","signatures":[{"sig":"MEQCICUXcABNUfUFE+LvZY+m9Wc491MrpYA+WMQ0xEtDo3yyAiAePJhPEyg7GEr6UQxJfwpvK1vs5fOj6qYxSyQewGRFnQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":57547},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./*":{"types":"./dist/*.d.ts","default":"./dist/*.js"}},"gitHead":"f2cc8c72f8823822b134a426f2fe71a32e9f38cd","private":false,"scripts":{"test":"node --test test/*.test.js","build":"tsc","clean":"rm -rf dist","pretest":"npm run build","prepublishOnly":"npm run build"},"_npmUser":{"name":"kanelr","email":"lanhnk@acegalaxy.co"},"repository":{"url":"git+https://github.com/acegalaxy-co/ace_commons-ott-gateway-nodejs.git","type":"git"},"_npmVersion":"11.12.1","description":"Inbound message security gateway for bots — 5-layer default-deny (caller-validator, identity-resolver, rate-limit, audit, forward) for Telegram/WhatsApp/WeChat and other OTT platforms.","directories":{},"_nodeVersion":"25.9.0","dependencies":{"@acegalaxy/security-utils":"^0.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.7.0","@types/node":"^20.0.0"},"_npmOperationalInternal":{"tmp":"tmp/ott-gateway_0.1.0_1778086030712_0.9529617849085177","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@acegalaxy/ott-gateway","version":"0.1.1","keywords":["ott","telegram","whatsapp","bot","security","gateway","authz"],"author":{"name":"ACE Galaxy","email":"hello@acegalaxy.co"},"license":"MIT","_id":"@acegalaxy/ott-gateway@0.1.1","maintainers":[{"name":"kanelr","email":"lanhnk@acegalaxy.co"}],"homepage":"https://github.com/acegalaxy-co/ace_commons-ott-gateway-nodejs#readme","bugs":{"url":"https://github.com/acegalaxy-co/ace_commons-ott-gateway-nodejs/issues"},"dist":{"shasum":"24ce23ad89c8ef9dafcdf5da0cdad7060211d8cf","tarball":"https://registry.npmjs.org/@acegalaxy/ott-gateway/-/ott-gateway-0.1.1.tgz","fileCount":42,"integrity":"sha512-727pMmRTDJFbRtmJpvdV63YWFVlDBPu5uAI8j08dqWIjk/fKZA1v9rfKCuQd+KSkKpCsv8wjClbSpWcMa0ptvA==","signatures":[{"sig":"MEYCIQDNQsHDYl2bJmf6zzPw3SguWkDIUQALS5YLmYosp4uoqwIhALPA0wb586R+pBv/F/77Bg8PMHSkm44s8cQ0XbZDVfD3","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":57547},"main":"dist/index.js","types":"dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./*":{"types":"./dist/*.d.ts","default":"./dist/*.js"}},"gitHead":"e714fe556da57f669a4e439de555f870f4e38677","private":false,"scripts":{"test":"node --test test/*.test.js","build":"tsc","clean":"rm -rf dist","pretest":"npm run build","prepublishOnly":"npm run build"},"_npmUser":{"name":"kanelr","email":"lanhnk@acegalaxy.co"},"repository":{"url":"git+https://github.com/acegalaxy-co/ace_commons-ott-gateway-nodejs.git","type":"git"},"_npmVersion":"11.12.1","description":"Inbound message security gateway for bots — 5-layer default-deny (caller-validator, identity-resolver, rate-limit, audit, forward) for Telegram/WhatsApp/WeChat and other OTT platforms.","directories":{},"_nodeVersion":"25.9.0","dependencies":{"@acegalaxy/security-utils":"^0.1.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.7.0","@types/node":"^20.0.0"},"_npmOperationalInternal":{"tmp":"tmp/ott-gateway_0.1.1_1778088200255_0.548826244946897","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@acegalaxy/ott-gateway","version":"0.1.2","description":"Inbound message security gateway for bots — 5-layer default-deny (caller-validator, identity-resolver, rate-limit, audit, forward) for Telegram/WhatsApp/WeChat and other OTT platforms.","main":"dist/index.js","scripts":{"test":"node --test test/*.test.js","build":"tsc","prepublishOnly":"npm run build","clean":"rm -rf dist","pretest":"npm run build"},"keywords":["ott","telegram","whatsapp","bot","security","gateway","authz"],"author":{"name":"ACE Galaxy","email":"hello@acegalaxy.co"},"license":"MIT","private":false,"engines":{"node":">=20"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+https://github.com/acegalaxy-co/ace_commons-ott-gateway-nodejs.git"},"bugs":{"url":"https://github.com/acegalaxy-co/ace_commons-ott-gateway-nodejs/issues"},"homepage":"https://github.com/acegalaxy-co/ace_commons-ott-gateway-nodejs#readme","dependencies":{"@acegalaxy/security-utils":"^0.1.2"},"types":"dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./*":{"types":"./dist/*.d.ts","default":"./dist/*.js"},"./package.json":"./package.json"},"devDependencies":{"typescript":"^5.7.0","@types/node":"^20.0.0"},"gitHead":"e714fe556da57f669a4e439de555f870f4e38677","_id":"@acegalaxy/ott-gateway@0.1.2","_nodeVersion":"25.9.0","_npmVersion":"11.12.1","dist":{"integrity":"sha512-aV0hMa5ooyWtenmYa9g6bF6dJuTZNwQ5quSqHtdYfebTuKOm0kyNMHzMOh0U8Klegq5CT3svhfuuvwC9abs9Ug==","shasum":"4594f7c90529a70854ad062347973118a57b3c63","tarball":"https://registry.npmjs.org/@acegalaxy/ott-gateway/-/ott-gateway-0.1.2.tgz","fileCount":42,"unpackedSize":57587,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDX01QgEHl3WBJjkTtFBY3SbWiCpzIwaJf7nrJ49W+VgAIhAKLLFm9diG3tIkUJOtCYjIAag8wioMabGprmteYsGLgm"}]},"_npmUser":{"name":"kanelr","email":"lanhnk@acegalaxy.co"},"directories":{},"maintainers":[{"name":"kanelr","email":"lanhnk@acegalaxy.co"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/ott-gateway_0.1.2_1778088285047_0.7065840511934545"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-06T16:47:10.656Z","modified":"2026-05-06T17:24:45.315Z","0.1.0":"2026-05-06T16:47:10.863Z","0.1.1":"2026-05-06T17:23:20.401Z","0.1.2":"2026-05-06T17:24:45.195Z"},"bugs":{"url":"https://github.com/acegalaxy-co/ace_commons-ott-gateway-nodejs/issues"},"author":{"name":"ACE Galaxy","email":"hello@acegalaxy.co"},"license":"MIT","homepage":"https://github.com/acegalaxy-co/ace_commons-ott-gateway-nodejs#readme","keywords":["ott","telegram","whatsapp","bot","security","gateway","authz"],"repository":{"type":"git","url":"git+https://github.com/acegalaxy-co/ace_commons-ott-gateway-nodejs.git"},"description":"Inbound message security gateway for bots — 5-layer default-deny (caller-validator, identity-resolver, rate-limit, audit, forward) for Telegram/WhatsApp/WeChat and other OTT platforms.","maintainers":[{"name":"kanelr","email":"lanhnk@acegalaxy.co"}],"readme":"# @acegalaxy/ott-gateway\n\n[![npm version](https://img.shields.io/npm/v/@acegalaxy%2Fott-gateway.svg)](https://www.npmjs.com/package/@acegalaxy/ott-gateway)\n[![npm downloads](https://img.shields.io/npm/dm/@acegalaxy%2Fott-gateway.svg)](https://www.npmjs.com/package/@acegalaxy/ott-gateway)\n[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](https://opensource.org/licenses/MIT)\n[![Node](https://img.shields.io/node/v/@acegalaxy%2Fott-gateway.svg)](https://nodejs.org)\n\n\n**Inbound message security gateway for bots — 5 layers, default-deny.**\n\nStop bot framework abuse. Most Telegram/WhatsApp/WeChat bot frameworks treat\n*\"can the bot read this message?\"* as the only access check. That's not authz —\nthat's just delivery. `ott-gateway` sits between your bot transport and your\nhandler and enforces real authorization on every inbound message.\n\n## Why\n\nA raw bot token says nothing about *who* is on the other end. Anyone who can\nDM your bot, or get added to a group with it, can hit your handlers. Real\nproducts need:\n\n- per-platform policy (block bots, block forwarded floods, block unknown chats)\n- mapped identity (Telegram user_id → your internal user/role)\n- rate limits per identity, not per IP\n- audit log of every accept/deny decision\n- a single forward point so handlers never see un-vetted input\n\n`ott-gateway` gives you all five as composable layers.\n\n## The 5 layers\n\nEvery inbound message walks the chain top-to-bottom. Any layer can `deny`.\n\n1. **caller-validator** — platform policy. Reject bots-talking-to-bots,\n   disallowed chat types, missing fields, suspicious forwards.\n2. **identity-resolver** — map platform principal (e.g. `telegram:user_id`)\n   to your internal identity + role. Unknown principal → deny.\n3. **rate-limit** — token bucket per resolved identity (not per chat),\n   so one user can't burn quota by switching groups.\n4. **audit** — structured log of `{ts, platform, principal, identity, decision, reason}`\n   for every message, accept or deny. Pluggable sink.\n5. **forward** — only here does your handler see the message, with\n   resolved identity attached.\n\nDefault at every layer is **deny**. You allowlist explicitly.\n\n## Install\n\n```bash\nnpm install @acegalaxy/ott-gateway\n```\n\n## Quick start (Telegram)\n\n```js\nimport { createGateway } from '@acegalaxy/ott-gateway';\n\nconst gateway = createGateway({\n  platform: 'telegram',\n  identityMap: async (principal) => {\n    // your DB lookup; return null to deny\n    return await db.users.findByTelegramId(principal.userId);\n  },\n  rateLimit: { perMinute: 30 },\n  auditSink: async (record) => log.info(record),\n  handler: async (msg, identity) => {\n    // only reaches here if all 5 layers passed\n    await myBot.dispatch(msg, identity);\n  },\n});\n\ntelegramBot.on('message', (msg) => gateway.ingest(msg));\n```\n\n## vs raw bot framework\n\n| | raw `node-telegram-bot-api` | `ott-gateway` |\n|---|---|---|\n| who can talk to bot | anyone in any chat | allowlisted identities only |\n| rate limit | none (or per-chat) | per-identity, cross-chat |\n| audit trail | you write it | built-in, structured |\n| identity in handler | raw `user_id` | resolved internal user + role |\n| add WhatsApp later | rewrite handlers | swap adapter, keep chain |\n\n## Status\n\n`0.1.x` — API may shift. Used in production internally at ACE Galaxy across\nmultiple bots. Telegram adapter ships; WhatsApp/WeChat adapters in progress.\n\n## License\n\nMIT (c) 2026 ACE Galaxy. See [LICENSE](LICENSE).\n\nSecurity issues -> [SECURITY.md](SECURITY.md).\nContributions -> [CONTRIBUTING.md](CONTRIBUTING.md).\n","readmeFilename":"README.md"}