Skip to main content
All projects

Nub Music Bot

Streams HD audio and video into Telegram group voice chats from a pool of assistant clients, with address-level SSRF checks on every remote URL and a sweeper for idle calls.

Open source
Project
Telegram streaming engine
Language
Python
Started
2025-04

The story

A Telegram bot that joins a group voice chat and streams audio or video into it. Simple to describe, unpleasant to make reliable: Telegram's calling layer is stateful, the media sources are hostile, and users will paste anything into a /play command.

The defensive work is the part I would point at. url_guard.py resolves hostnames and checks the resulting addresses against private and metadata ranges before a fetch happens, because blocklisting URL strings is not the same as refusing to talk to 169.254.169.254. The idle sweeper exists because Telegram caps how many groups an account can sit in, and an assistant that never leaves eventually cannot join.

Unit and integration tests run on GitHub Actions, including cases that assert the guard rejects what it should.

Under the hood

The decisions that make it work.

Assistant pool
Up to five string-session PyTgCalls workers are managed dynamically, so concurrent calls do not queue behind a single client.
SSRF guard
url_guard.py resolves each host and rejects link-local, loopback and cloud metadata addresses before anything is fetched — validation at the address, not the string.
Idle sweeper
A background worker evicts inactive voice chats, which is what keeps the assistants under Telegram's 500-group ceiling.
Provider seam
Spotify tracks and playlists fall back to YouTube search behind one interface, flattening up to 50 items per request.

Built with

  • Python 3.13
  • Pyrogram
  • PyTgCalls
  • MongoDB
  • asyncio
  • yt-dlp