Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

no option to limit user messages to channels which they are members of #54

Open
lacuna-exe opened this issue Aug 29, 2021 · 1 comment
Labels
enhancement New feature or request

Comments

@lacuna-exe
Copy link

Bot allows users to send messages to channels they don't have access to, as well as mention roles.

@nminchow nminchow added the enhancement New feature or request label Aug 30, 2021
@nminchow
Copy link
Owner

Currently, this is "functioning as designed" - there are use cases where users configure the bot to submit to anonymous feedback channels which only it and mods have access to. The recommendation is to block the bot from mentioning roles and using channels that admins don't wish bot users to be able to leverage. (As a reminder, the bot can be locked to certain roles).

That said, I can see how this is limiting for complex setups where users want to have discussions using the bot, but admins want to limit channels and mentions to users which would normally be able to utilize them. I could see a case to be made for additional admin settings controlling channel access and mentions. I'd propose "respect disallowed channels" and "respect disallowed mentions." If anyone is looking to add, I'd just ask that the settings default to false for existing servers to not alter existing behavior.

@nminchow nminchow changed the title User mention exploit no option to limit user messages to channels which they are members of Aug 30, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants