Default Discord client allowedMentions to users-only (block mass pings)
The raw sendMessage/editMessage paths did not route through sanitizeForOutbound, so an agent-authored @everyone/@here in a progress or edited message could still ping the whole channel. Set a client-level allowedMentions default (parse: ['users']) so no normal send/edit can mass-ping; explicit <@id> user mentions still work, and the disk-usage alert broadcasts via a separate REST path with its own allowedMentions. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
This commit is contained in:
@@ -210,6 +210,11 @@ export class DiscordChannel implements Channel {
|
||||
GatewayIntentBits.MessageContent,
|
||||
GatewayIntentBits.DirectMessages,
|
||||
],
|
||||
// Guardrail: agent-authored messages must never mass-ping. Allow only
|
||||
// explicit user mentions (e.g. <@id>) by default; never parse @everyone,
|
||||
// @here, or role mentions on any send/edit. Intentional broadcasts (e.g.
|
||||
// the disk-usage alert) use a dedicated path with their own allowedMentions.
|
||||
allowedMentions: { parse: ['users'] },
|
||||
});
|
||||
|
||||
this.client.on(Events.MessageCreate, async (message: Message) => {
|
||||
|
||||
Reference in New Issue
Block a user