Files
polymarket-insider-tracker/tests
Patrick Selamy 5afbb35ee9 fix(alerter): escape all dynamic numeric fields in Telegram MarkdownV2 (#106)
Telegram's MarkdownV2 parser treats `.` as a special character and rejects
the message with `Bad Request: can't parse entities` if any unescaped `.`
appears outside a code or pre block. The current formatter only escapes
the static `Market:` title and the `$` in the USDC amount, while leaving
three numeric runs unescaped:

  *Risk Score:* 0.82 (HIGH)            ← `.` in the score literal
  *Trade:* BUY Yes @ $0.075 | $15,000.00
                       ↑                  ↑
                       price              USDC amount

In production this means well-formed alerts silently fail to reach
Telegram users — the dispatcher reports a 400 from the Bot API and the
event is dropped.

This change routes every dynamic value through `_escape_telegram_markdown`
before interpolation:

  - `assessment.weighted_score` (risk score)
  - `trade.price` (price string)
  - `format_usdc(trade.notional_value)` (USDC amount, including its `.`)
  - `trade.side` and `trade.outcome` (defensive — upstream values may
    contain `-` or `.` in future schema changes)

The test that previously asserted `"0.82" in result.telegram_markdown` is
updated to require the escaped form `"0\.82"`, and a new test pins down
that none of `0.82` / `0.075` / `15,000.00` appear in unescaped form.

Co-authored-by: schrodinger01 <schrodinger01@users.noreply.github.com>
2026-06-14 15:17:39 -04:00
..