fix(channels): improve security warning for empty allow_from (fixes #2381)
This commit is contained in:
parent
6124b01678
commit
31e05ea19c
1 changed files with 6 additions and 4 deletions
|
|
@ -119,14 +119,16 @@ func NewBaseChannel(
|
||||||
// currently defaults to accepting messages from ANYONE. To explicitly
|
// currently defaults to accepting messages from ANYONE. To explicitly
|
||||||
// acknowledge and permit this (e.g. for a public bot), use ["*"].
|
// acknowledge and permit this (e.g. for a public bot), use ["*"].
|
||||||
if len(bc.allowList) == 0 {
|
if len(bc.allowList) == 0 {
|
||||||
logger.WarnCF("channels", fmt.Sprintf("SECURITY: Channel '%s' allows EVERYONE (allow_from is empty)", bc.name), map[string]any{
|
logger.WarnCF("channels", fmt.Sprintf("SECURITY: Channel '%s' allows EVERYONE (allow_from is empty). This is a potential security risk.", bc.name), map[string]any{
|
||||||
"channel": bc.name,
|
"channel": bc.name,
|
||||||
"hint": "Set allow_from to your ID, or use '*' to explicitly acknowledge open access.",
|
"channelID": bc.name,
|
||||||
|
"hint": "Set allow_from to your ID, or use ['*'] to explicitly acknowledge open access. See: https://github.com/sipeed/picoclaw/blob/main/docs/configuration.md",
|
||||||
})
|
})
|
||||||
} else {
|
} else {
|
||||||
logger.InfoCF("channels", fmt.Sprintf("Channel '%s' allow_from configured", bc.name), map[string]any{
|
logger.InfoCF("channels", fmt.Sprintf("Channel '%s' allow_from configured (%d entries)", bc.name, len(bc.allowList)), map[string]any{
|
||||||
"channel": bc.name,
|
"channel": bc.name,
|
||||||
"allow_list": bc.allowList,
|
"allow_list": bc.allowList,
|
||||||
|
"count": len(bc.allowList),
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue