feat: add permission check for /new command - #9739
Open
Rain-0x01-39 wants to merge 1 commit into
Open
Conversation
Contributor
There was a problem hiding this comment.
Hey - I've left some high level feedback:
- The new permission check for
/newduplicates logic that likely already exists for/reset; consider extracting a shared helper or reusing the existing mechanism so the two commands stay consistent and easier to maintain. - Role and permission values ("admin"/"member") are currently hard-coded string literals; it would be more robust to use centralized constants or an enum and validate against known roles to avoid subtle bugs from typos or future changes.
Prompt for AI Agents
Please address the comments from this code review:
## Overall Comments
- The new permission check for `/new` duplicates logic that likely already exists for `/reset`; consider extracting a shared helper or reusing the existing mechanism so the two commands stay consistent and easier to maintain.
- Role and permission values ("admin"/"member") are currently hard-coded string literals; it would be more robust to use centralized constants or an enum and validate against known roles to avoid subtle bugs from typos or future changes.Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
/new命令缺少权限控制,在群聊且会话隔离关闭的场景下(共享会话),任意成员都可以创建新会话并切换,影响其他用户的对话上下文。而/reset已有对应的权限检查,/new与之不一致。Modifications / 改动点
astrbot/builtin_stars/builtin_commands/commands/conversation.py:为new_conv方法新增场景化权限检查,逻辑与reset一致——群聊+会话隔离关闭时默认要求admin,其余场景member即可。权限可通过 Dashboard 的指令管理覆盖。This is NOT a breaking change. / 这不是一个破坏性变更。
Screenshots or Test Results / 运行截图或测试结果
Checklist / 检查清单
😊 If there are new features added in the PR, I have discussed it with the authors through issues/emails, etc.
/ 如果 PR 中有新加入的功能,已经通过 Issue / 邮件等方式和作者讨论过。
👀 My changes have been well-tested, and "Verification Steps" and "Screenshots" have been provided above.
/ 我的更改经过了良好的测试,并已在上方提供了“验证步骤”和“运行截图”。
🤓 I have ensured that no new dependencies are introduced, OR if new dependencies are introduced, they have been added to the appropriate locations in
requirements.txtandpyproject.toml./ 我确保没有引入新依赖库,或者引入了新依赖库的同时将其添加到
requirements.txt和pyproject.toml文件相应位置。😮 My changes do not introduce malicious code.
/ 我的更改没有引入恶意代码。
Summary by Sourcery
Enforce context-aware permissions for creating new conversations.
Bug Fixes:
/newcommand in shared group conversations to administrators, preventing members from changing the shared conversation context.Enhancements:
/newpermission behavior with/resetwhile preserving configurable per-scenario permission overrides.