This commit is contained in:
Darren.Zeng 2026-04-17 22:56:03 +02:00 committed by GitHub
commit 0ee57d665d
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -5,6 +5,7 @@ import (
"crypto/rand" "crypto/rand"
"encoding/binary" "encoding/binary"
"encoding/hex" "encoding/hex"
"fmt"
"regexp" "regexp"
"strconv" "strconv"
"strings" "strings"
@ -128,10 +129,15 @@ func NewBaseChannel(
// currently defaults to accepting messages from ANYONE. To explicitly // currently defaults to accepting messages from ANYONE. To explicitly
// acknowledge and permit this (e.g. for a public bot), use ["*"]. // acknowledge and permit this (e.g. for a public bot), use ["*"].
if len(bc.allowList) == 0 { if len(bc.allowList) == 0 {
logger.WarnCF("channels", "SECURITY: Channel allows EVERYONE (allow_from is empty)", map[string]any{ logger.WarnCF("channels", fmt.Sprintf("SECURITY: Channel '%s' allows EVERYONE (allow_from is empty)", bc.name), map[string]any{
"channel": bc.name, "channel": bc.name,
"hint": "Set allow_from to your ID, or use '*' to explicitly acknowledge open access.", "hint": "Set allow_from to your ID, or use '*' to explicitly acknowledge open access.",
}) })
} else {
logger.InfoCF("channels", fmt.Sprintf("Channel '%s' allow_from configured", bc.name), map[string]any{
"channel": bc.name,
"allow_list": bc.allowList,
})
} }
return bc return bc