You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Currently, this is "functioning as designed" - there are use cases where users configure the bot to submit to anonymous feedback channels which only it and mods have access to. The recommendation is to block the bot from mentioning roles and using channels that admins don't wish bot users to be able to leverage. (As a reminder, the bot can be locked to certain roles).
That said, I can see how this is limiting for complex setups where users want to have discussions using the bot, but admins want to limit channels and mentions to users which would normally be able to utilize them. I could see a case to be made for additional admin settings controlling channel access and mentions. I'd propose "respect disallowed channels" and "respect disallowed mentions." If anyone is looking to add, I'd just ask that the settings default to false for existing servers to not alter existing behavior.
nminchow
changed the title
User mention exploit
no option to limit user messages to channels which they are members of
Aug 30, 2021
Bot allows users to send messages to channels they don't have access to, as well as mention roles.
The text was updated successfully, but these errors were encountered: