Repository navigation
Staff role access (admin except bot invite) #16
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
36391b2
222a3e2
c2e2218
d9770f6
9602ac0
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -167,6 +167,7 @@ public List<GuildInfo> getManageableGuilds(Authentication authentication) { | |
|
|
||
| /** | ||
| * Check if user has admin permissions in a specific guild (regardless of bot presence) | ||
| * Returns true if user has EITHER actual admin permissions OR Staff role | ||
| */ | ||
| public boolean isUserAdminInGuild(Authentication authentication, String guildId) { | ||
| if (authentication == null || !(authentication.getPrincipal() instanceof OAuth2User)) { | ||
|
|
@@ -181,18 +182,72 @@ public boolean isUserAdminInGuild(Authentication authentication, String guildId) | |
| return false; | ||
| } | ||
|
|
||
| // User is admin if they have actual permissions OR Staff role | ||
| return checkAdminPermissions(guildId, accessToken) || hasStaffRole(userId, guildId); | ||
| } | ||
|
|
||
| /** | ||
| * Check if user has Staff role in a guild | ||
| */ | ||
| private boolean hasStaffRole(String userId, String guildId) { | ||
| Guild guild = jda.getGuildById(guildId); | ||
| if (guild == null) { | ||
| return false; | ||
| } | ||
|
|
||
| net.dv8tion.jda.api.entities.Member member = guild.getMemberById(userId); | ||
| if (member == null) { | ||
| return false; | ||
| } | ||
|
|
||
| return member.getRoles().stream() | ||
| .anyMatch(role -> role.getName().equalsIgnoreCase("Staff")); | ||
| } | ||
|
|
||
| /** | ||
| * Check if user has actual ADMINISTRATOR or MANAGE_SERVER permissions (no Staff role) | ||
| * Use this for restricted actions like bot invites | ||
| */ | ||
| public boolean isUserActualAdminInGuild(Authentication authentication, String guildId) { | ||
|
||
| if (authentication == null || !(authentication.getPrincipal() instanceof OAuth2User)) { | ||
| return false; | ||
| } | ||
|
|
||
| String accessToken = getAccessToken(authentication); | ||
|
|
||
| if (accessToken == null) { | ||
| return false; | ||
| } | ||
|
|
||
| return checkAdminPermissions(guildId, accessToken); | ||
| } | ||
|
|
||
| /** | ||
| * Check if user has actual ADMINISTRATOR or MANAGE_SERVER permissions in a guild | ||
| * Extracted as a helper to avoid duplication between permission checking methods | ||
| */ | ||
| private boolean checkAdminPermissions(String guildId, String accessToken) { | ||
| List<Map<String, Object>> userGuilds = getUserGuildsFromDiscord(accessToken); | ||
|
|
||
| for (Map<String, Object> userGuild : userGuilds) { | ||
| if (guildId.equals(userGuild.get("id"))) { | ||
| Long permissions = Long.parseLong(userGuild.get("permissions").toString()); | ||
| boolean isAdmin = (permissions & Permission.ADMINISTRATOR.getRawValue()) != 0 || | ||
| (permissions & Permission.MANAGE_SERVER.getRawValue()) != 0; | ||
| return isAdmin; | ||
| Object permissionsObj = userGuild.get("permissions"); | ||
| if (permissionsObj == null) { | ||
| return false; | ||
| } | ||
|
|
||
| long permissions; | ||
| try { | ||
| permissions = Long.parseLong(permissionsObj.toString()); | ||
| } catch (NumberFormatException e) { | ||
| // Treat unparseable permissions as missing admin privileges | ||
| return false; | ||
| } | ||
| return (permissions & Permission.ADMINISTRATOR.getRawValue()) != 0 || | ||
| (permissions & Permission.MANAGE_SERVER.getRawValue()) != 0; | ||
| } | ||
| } | ||
|
|
||
| logger.warn("User {} attempted to access guild {} without permissions", userId, guildId); | ||
| return false; | ||
| } | ||
|
|
||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The documentation mentions the "Staff" role specifically (with capital S), but the implementation uses case-insensitive matching via
equalsIgnoreCase("Staff"). Consider documenting this case-insensitive behavior in the README.md and SECURITY.md, or alternatively, use exact case matching if the role name should be case-sensitive.