a bot , even if the bot never sent an inline message ?
Yes, in theory that can happen. E.g. for custom clients
With moded clients anyone can send you any kind of data. You have to filter and process callback data with caution.
Alright Thanks very much
I think this is a real security issues if i'm working with user_id also .. since a callbackquery can be constructed with custom data right ? ( ie : using different user_id than the actual one .
only the data on the callbackquery is susceptible from user modification. User id, chat id and the other properties can't be changed.
Обсуждают сегодня