Some checks failed
ClawSweeper Dispatch / dispatch (push) Has been cancelled
CodeQL / Security High (actions) (push) Has been cancelled
CodeQL / Security High (channel-runtime-boundary) (push) Has been cancelled
CodeQL / Security High (core-auth-secrets) (push) Has been cancelled
CodeQL / Security High (mcp-process-tool-boundary) (push) Has been cancelled
CodeQL / Security High (network-ssrf-boundary) (push) Has been cancelled
CodeQL / Security High (plugin-trust-boundary) (push) Has been cancelled
CodeQL / Security High (process-exec-boundary) (push) Has been cancelled
Docs Sync Publish Repo / sync-publish-repo (push) Has been cancelled
Docs / docs (push) Has been cancelled
OpenClaw Stable Main Closeout / Resolve stable release closeout inputs (push) Has been cancelled
OpenClaw Stable Main Closeout / Verify stable main closeout (push) Has been cancelled
Workflow Sanity / no-tabs (push) Has been cancelled
Workflow Sanity / actionlint (push) Has been cancelled
Workflow Sanity / generated-doc-baselines (push) Has been cancelled
CI / runner-admission (push) Has been cancelled
CI / preflight (push) Has been cancelled
CI / security-fast (push) Has been cancelled
CI / pnpm-store-warmup (push) Has been cancelled
CI / build-artifacts (push) Has been cancelled
CI / native-i18n (push) Has been cancelled
CI / ${{ matrix.check_name }} (push) Has been cancelled
CI / ${{ matrix.checkName }} (push) Has been cancelled
CI / checks-node-compat-node22 (push) Has been cancelled
CI / check-bundled-channel-config-metadata (push) Has been cancelled
CI / check-dependencies (push) Has been cancelled
CI / check-guards (push) Has been cancelled
CI / check-lint (push) Has been cancelled
CI / check-prod-types (push) Has been cancelled
CI / check-shrinkwrap (push) Has been cancelled
CI / check-test-types (push) Has been cancelled
CI / check-additional-boundaries-a (push) Has been cancelled
CI / check-additional-boundaries-bcd (push) Has been cancelled
CI / check-additional-extension-bundled (push) Has been cancelled
CI / check-additional-extension-channels (push) Has been cancelled
CI / check-additional-extension-package-boundary (push) Has been cancelled
CI / check-additional-runtime-topology-architecture (push) Has been cancelled
CI / check-session-accessor-boundary (push) Has been cancelled
CI / check-session-transcript-reader-boundary (push) Has been cancelled
CI / check-docs (push) Has been cancelled
CI / skills-python (push) Has been cancelled
CI / macos-swift (push) Has been cancelled
CI / ios-build (push) Has been cancelled
CI / ci-timings-summary (push) Has been cancelled
Native App Locale Refresh / Refresh native fa (push) Has been cancelled
Native App Locale Refresh / Refresh native fr (push) Has been cancelled
Native App Locale Refresh / Refresh native hi (push) Has been cancelled
Native App Locale Refresh / Refresh native id (push) Has been cancelled
Native App Locale Refresh / Refresh native it (push) Has been cancelled
Native App Locale Refresh / Refresh native ja-JP (push) Has been cancelled
Control UI Locale Refresh / plan (push) Has been cancelled
Control UI Locale Refresh / Refresh ${{ matrix.locale }} (push) Has been cancelled
Control UI Locale Refresh / Commit control UI locale refresh (push) Has been cancelled
Live Media Runner Image / Build live media runner image (push) Has been cancelled
Native App Locale Refresh / Refresh native ar (push) Has been cancelled
Native App Locale Refresh / Refresh native de (push) Has been cancelled
Native App Locale Refresh / Refresh native es (push) Has been cancelled
Native App Locale Refresh / Refresh native ko (push) Has been cancelled
Native App Locale Refresh / Refresh native nl (push) Has been cancelled
Native App Locale Refresh / Refresh native pl (push) Has been cancelled
Native App Locale Refresh / Refresh native pt-BR (push) Has been cancelled
Native App Locale Refresh / Refresh native ru (push) Has been cancelled
Native App Locale Refresh / Refresh native sv (push) Has been cancelled
Native App Locale Refresh / Refresh native th (push) Has been cancelled
Native App Locale Refresh / Refresh native tr (push) Has been cancelled
Native App Locale Refresh / Refresh native uk (push) Has been cancelled
Native App Locale Refresh / Refresh native vi (push) Has been cancelled
Native App Locale Refresh / Refresh native zh-CN (push) Has been cancelled
Native App Locale Refresh / Refresh native zh-TW (push) Has been cancelled
Native App Locale Refresh / Commit native locale refresh (push) Has been cancelled
Plugin Init Scaffold Validation / Validate provider scaffold (push) Has been cancelled
Plugin NPM Release / preview_plugins_npm (push) Has been cancelled
Plugin NPM Release / Validate release publish approval (push) Has been cancelled
Plugin NPM Release / preview_plugin_pack (push) Has been cancelled
Plugin NPM Release / publish_plugins_npm (push) Has been cancelled
Sandbox Common Smoke / sandbox-common-smoke (push) Has been cancelled
Website Installer Sync / static (push) Has been cancelled
Website Installer Sync / linux-docker (push) Has been cancelled
Website Installer Sync / macos-installer (push) Has been cancelled
Website Installer Sync / windows-installer (push) Has been cancelled
Website Installer Sync / sync-website (push) Has been cancelled
Adolf is a fork/vendored clone of github.com/openclaw/openclaw (v2026.6.11), free to diverge. Tree copied sans upstream .git; upstream remote added for future syncs. Node pinned to 24 (.nvmrc); engines already require >=22.19. Preserves docs/ARCHITECTURE.md. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LeqyaxJF2nbRXJtae2kNB2
118 lines
3.5 KiB
TypeScript
118 lines
3.5 KiB
TypeScript
// Discord plugin module implements runtime.moderation behavior.
|
|
import type { AgentToolResult } from "openclaw/plugin-sdk/agent-core";
|
|
import {
|
|
type ActionGate,
|
|
jsonResult,
|
|
readStringParam,
|
|
type DiscordActionConfig,
|
|
type OpenClawConfig,
|
|
} from "../runtime-api.js";
|
|
import {
|
|
banMemberDiscord,
|
|
hasAnyGuildPermissionDiscord,
|
|
kickMemberDiscord,
|
|
timeoutMemberDiscord,
|
|
} from "../send.js";
|
|
import {
|
|
isDiscordModerationAction,
|
|
readDiscordModerationCommand,
|
|
requiredGuildPermissionForModerationAction,
|
|
} from "./runtime.moderation-shared.js";
|
|
import { createDiscordActionOptions } from "./runtime.shared.js";
|
|
|
|
export const discordModerationActionRuntime = {
|
|
banMemberDiscord,
|
|
hasAnyGuildPermissionDiscord,
|
|
kickMemberDiscord,
|
|
timeoutMemberDiscord,
|
|
};
|
|
|
|
async function verifySenderModerationPermission(params: {
|
|
guildId: string;
|
|
senderUserId?: string;
|
|
requiredPermission: bigint;
|
|
accountId?: string;
|
|
cfg: OpenClawConfig;
|
|
}) {
|
|
// CLI/manual flows may not have sender context; enforce only when present.
|
|
if (!params.senderUserId) {
|
|
return;
|
|
}
|
|
const hasPermission = await discordModerationActionRuntime.hasAnyGuildPermissionDiscord(
|
|
params.guildId,
|
|
params.senderUserId,
|
|
[params.requiredPermission],
|
|
createDiscordActionOptions({ cfg: params.cfg, accountId: params.accountId }),
|
|
);
|
|
if (!hasPermission) {
|
|
throw new Error("Sender does not have required permissions for this moderation action.");
|
|
}
|
|
}
|
|
|
|
export async function handleDiscordModerationAction(
|
|
action: string,
|
|
params: Record<string, unknown>,
|
|
isActionEnabled: ActionGate<DiscordActionConfig>,
|
|
cfg: OpenClawConfig,
|
|
): Promise<AgentToolResult<unknown>> {
|
|
if (!isDiscordModerationAction(action)) {
|
|
throw new Error(`Unknown action: ${action}`);
|
|
}
|
|
if (!isActionEnabled("moderation", false)) {
|
|
throw new Error("Discord moderation is disabled.");
|
|
}
|
|
if (!cfg) {
|
|
throw new Error("Discord moderation actions require a resolved runtime config.");
|
|
}
|
|
const accountId = readStringParam(params, "accountId");
|
|
const command = readDiscordModerationCommand(action, params);
|
|
const senderUserId = readStringParam(params, "senderUserId");
|
|
const withOpts = () => createDiscordActionOptions({ cfg, accountId });
|
|
await verifySenderModerationPermission({
|
|
guildId: command.guildId,
|
|
senderUserId,
|
|
requiredPermission: requiredGuildPermissionForModerationAction(command.action),
|
|
accountId,
|
|
cfg,
|
|
});
|
|
switch (command.action) {
|
|
case "timeout": {
|
|
const member = await discordModerationActionRuntime.timeoutMemberDiscord(
|
|
{
|
|
guildId: command.guildId,
|
|
userId: command.userId,
|
|
durationMinutes: command.durationMinutes,
|
|
until: command.until,
|
|
reason: command.reason,
|
|
},
|
|
withOpts(),
|
|
);
|
|
return jsonResult({ ok: true, member });
|
|
}
|
|
case "kick": {
|
|
await discordModerationActionRuntime.kickMemberDiscord(
|
|
{
|
|
guildId: command.guildId,
|
|
userId: command.userId,
|
|
reason: command.reason,
|
|
},
|
|
withOpts(),
|
|
);
|
|
return jsonResult({ ok: true });
|
|
}
|
|
case "ban": {
|
|
await discordModerationActionRuntime.banMemberDiscord(
|
|
{
|
|
guildId: command.guildId,
|
|
userId: command.userId,
|
|
reason: command.reason,
|
|
deleteMessageDays: command.deleteMessageDays,
|
|
},
|
|
withOpts(),
|
|
);
|
|
return jsonResult({ ok: true });
|
|
}
|
|
}
|
|
throw new Error("Unsupported Discord moderation action");
|
|
}
|