fix(identity): prevent allowlist ID entries from matching usernames (#1406)

This commit is contained in:
美電球 2026-03-13 15:41:18 +08:00 committed by GitHub
parent a43c9c87c3
commit 387fc74c2f
2 changed files with 26 additions and 5 deletions

View file

@ -59,6 +59,9 @@ func MatchAllowed(sender bus.SenderInfo, allowed string) bool {
} }
} }
// Keep track of explicit username format
isAtUsername := strings.HasPrefix(allowed, "@")
// Strip leading "@" for username matching // Strip leading "@" for username matching
trimmed := strings.TrimPrefix(allowed, "@") trimmed := strings.TrimPrefix(allowed, "@")
@ -75,11 +78,9 @@ func MatchAllowed(sender bus.SenderInfo, allowed string) bool {
return true return true
} }
// Match against Username // Match against Username only when explicitly requested via "@username"
if sender.Username != "" { if isAtUsername && sender.Username != "" && sender.Username == trimmed {
if sender.Username == trimmed || sender.Username == allowedUser { return true
return true
}
} }
// Match compound sender format against allowed parts // Match compound sender format against allowed parts

View file

@ -104,6 +104,16 @@ func TestMatchAllowed(t *testing.T) {
allowed: "@alice", allowed: "@alice",
want: true, want: true,
}, },
{
name: "plain entry does not match username",
sender: bus.SenderInfo{
Platform: "discord",
PlatformID: "999999",
Username: "123456",
},
allowed: "123456",
want: false,
},
{ {
name: "@username does not match", name: "@username does not match",
sender: telegramSender, sender: telegramSender,
@ -123,6 +133,16 @@ func TestMatchAllowed(t *testing.T) {
allowed: "999|alice", allowed: "999|alice",
want: true, want: true,
}, },
{
name: "compound matches by ID when username differs",
sender: bus.SenderInfo{
Platform: "discord",
PlatformID: "123456",
Username: "not123456",
},
allowed: "123456|alice",
want: true,
},
{ {
name: "compound does not match", name: "compound does not match",
sender: telegramSender, sender: telegramSender,