mirror of
https://github.com/bohd4nx/FragmentAPI.git
synced 2026-07-25 06:14:29 +00:00
chore: add CONTRIBUTING and SECURITY guidelines to improve project documentation
This commit is contained in:
@@ -0,0 +1,58 @@
|
||||
# Contributing to pyfragment
|
||||
|
||||
## Development setup
|
||||
|
||||
```bash
|
||||
git clone https://github.com/bohd4nx/pyfragment.git
|
||||
cd pyfragment
|
||||
pip install -e ".[dev]"
|
||||
```
|
||||
|
||||
## Running checks
|
||||
|
||||
```bash
|
||||
# Lint and format
|
||||
ruff check . --fix && ruff format .
|
||||
|
||||
# Type check
|
||||
mypy . --explicit-package-bases
|
||||
|
||||
# Tests
|
||||
pytest
|
||||
```
|
||||
|
||||
All three must pass before opening a PR.
|
||||
|
||||
## Project structure
|
||||
|
||||
```
|
||||
pyfragment/
|
||||
client.py — FragmentClient (public entry point)
|
||||
enums.py — ApiProvider, PaymentMethod, WalletVersion
|
||||
exceptions.py — exception hierarchy
|
||||
core/ — constants, validation helpers
|
||||
domains/ — one package per feature domain
|
||||
ads/ — recharge_ads, topup_gram
|
||||
anonymous_numbers/— get_login_code, toggle_login_codes, terminate_sessions
|
||||
giveaways/ — giveaway_stars, giveaway_premium
|
||||
marketplace/ — search_usernames, search_numbers, search_gifts
|
||||
purchases/ — purchase_stars, purchase_premium
|
||||
services/ — shared infrastructure services
|
||||
cookies/ — browser cookie extraction (models + service)
|
||||
tonapi/ — wallet info, transaction signing (tonapi/toncenter)
|
||||
tests/ — unit tests (pytest)
|
||||
examples/ — runnable usage examples (excluded from CI)
|
||||
```
|
||||
|
||||
## Conventions
|
||||
|
||||
- All public async methods live on `FragmentClient` and delegate to a domain service.
|
||||
- Domain functions receive a `FragmentClient` instance, never raw HTTP clients.
|
||||
- Patch targets in tests use the module where the name is **defined**, e.g. `pyfragment.services.tonapi.transaction._make_ton_client`.
|
||||
- Versioning follows [CalVer](https://calver.org/): `YYYY.MINOR.MICRO`. Bump in `pyproject.toml`; tag as `vYYYY.MINOR.MICRO`.
|
||||
|
||||
## Pull requests
|
||||
|
||||
- Keep PRs focused — one feature or fix per PR.
|
||||
- Update `CHANGELOG.md` under `[Unreleased]`.
|
||||
- Add or update tests for any changed behaviour.
|
||||
+19
@@ -0,0 +1,19 @@
|
||||
# Security Policy
|
||||
|
||||
## Reporting a vulnerability
|
||||
|
||||
Please **do not** open a public GitHub issue for security vulnerabilities.
|
||||
|
||||
Report them privately via GitHub's [Security Advisory](https://github.com/bohd4nx/pyfragment/security/advisories/new) feature, or contact the maintainer directly at [@bohd4nx](https://t.me/bohd4nx) on Telegram.
|
||||
|
||||
Include:
|
||||
|
||||
- A description of the vulnerability and its potential impact.
|
||||
- Steps to reproduce or a proof-of-concept.
|
||||
- Affected versions.
|
||||
|
||||
You will receive a response within 72 hours. Once the fix is released, the advisory will be published.
|
||||
|
||||
## Scope
|
||||
|
||||
This library handles sensitive credentials (GRAM (ex TON) seed phrases, Fragment session cookies, Tonapi keys). Please treat any finding that could expose or misuse these credentials as high severity.
|
||||
Reference in New Issue
Block a user