Skip to content

Per-guild channel restrictions via MATRIMONY_ALLOWED_CHANNELS - #3

Open
devin-ai-integration[bot] wants to merge 1 commit into
mainfrom
devin/1791490871-channel-restrictions
Open

devin-ai-integration[bot] wants to merge 1 commit into
mainfrom
devin/1791490871-channel-restrictions

Conversation

@devin-ai-integration

Copy link
Copy Markdown
Contributor

Summary

Adds an optional per-guild allow-list for command channels, configured entirely through env vars (consistent with the rest of Config):

  • MATRIMONY_ALLOWED_CHANNELS — inline JSON object mapping guild ids to channel id lists, e.g. {"123456789012345678": ["111222333444555666"]}
  • MATRIMONY_ALLOWED_CHANNELS_FILE — path to a JSON file with the same mapping; used only when the inline var is unset

Dispatch: the check lives in MatrimonyBot.should_process() (matrimony/bot.py), so it runs before command parsing/dispatch. Commands sent in a non-allowed channel are silently ignored — the same pattern as the existing self-loop guard, and it means non-command chatter in a restricted guild never triggers anything.

Semantics:

  • Guild absent from the mapping → unrestricted (existing deployments unaffected)
  • Guild mapped to [] → commands accepted in no channel
  • DMs (message.guild is None) → never restricted
  • Threads count as their own channels (documented in README)

Fail-open parsing: malformed JSON, non-object top level, non-list values, non-numeric ids, or an unreadable file all log a matrimony warning and yield {} (no restrictions) — a typo can't lock every server out (matrimony/config.py).

Changes

  • matrimony/config.py — Config.allowed_channels: dict[int, frozenset[int]], _parse_allowed_channels(), _allowed_channels_from_env()
  • matrimony/bot.py — should_process() enforces the allow-list
  • tests/test_allowed_channels.py — 16 tests: parsing (inline/file/precedence/each failure mode with warning assertion) + dispatch gate (allowed/disallowed channel, unlisted guild, empty list, DMs, env end-to-end)
  • README.md, .env.example — config table rows, feature bullet, and a "Channel restrictions" section with example

ruff check clean; 86 tests pass (70 existing + 16 new).

Link to Devin session: https://app.devin.ai/sessions/aa55cdd684ae490b8ecac90ebfb5fc85
Open in Devin Desktop: https://app.devin.ai/desktop/session/aa55cdd684ae490b8ecac90ebfb5fc85?variant=devin
Requested by: @CommunityPoke

Guild ids map to lists of allowed channel ids via the
MATRIMONY_ALLOWED_CHANNELS env var (inline JSON) or
MATRIMONY_ALLOWED_CHANNELS_FILE (path to a JSON file; the inline var
wins when both are set).

- Check runs in should_process(), before command dispatch: commands in
  non-allowed channels are silently ignored, matching how the bot
  already ignores its own messages.
- Guilds absent from the mapping are unrestricted, DMs are never
  restricted, and a guild mapped to [] accepts commands nowhere.
- Malformed JSON / wrong shapes log a warning and are treated as no
  restriction (fail-open, so a typo can't lock every server out).

Docs: README config table + new 'Channel restrictions' section and
.env.example entries. Tests: tests/test_allowed_channels.py covers
parsing (inline/file/precedence/bad input) and the dispatch gate.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@devin-ai-integration

Copy link
Copy Markdown
Contributor Author

I'll fix CI failures and address comments from users with write access. I'll skip comments containing "(aside)".

  • Disable automatic comment, CI, and merge conflict monitoring

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant