feat: Implement spam protection with configurable limits and auto-mute escalation

This commit is contained in:
HueByte
2026-07-17 19:47:57 +02:00
parent 3281064720
commit 53d0d326cb
9 changed files with 556 additions and 0 deletions
+11
View File
@@ -42,6 +42,13 @@ you send from the TUI now reach your own connected IRC client instantly.
- **`[open]` images without saving them** — every image attachment now shows `[open] [↓ save original]` beneath its preview. Open views the image in your default browser straight from the server; in end-to-end encrypted rooms (where a browser would only see ciphertext) the client downloads, decrypts with the room key, and opens the image in your OS viewer from a temp file instead. Both actions are individually clickable, Enter on the line opens, and the right-click menu carries both.
- **Attachment links work in a browser** — `GET /api/files/{id}` is now a capability URL: the unguessable GUID in the link is the access token (Discord-CDN style), so attachment links can be opened directly in a browser or shared to IRC without a login token. Images and audio are served inline so the browser displays them instead of forcing a download. Blobs from encrypted rooms remain ciphertext, so their links reveal nothing.
- **IRC gets image links instead of terminal art** — the gateway no longer floods IRC clients with truecolor-ANSI ASCII art for images. Each attachment is now a single line — `[Image: photo.png] https://your-server/api/files/…` — the convention every IRC client understands, and ones like TheLounge or IRCCloud auto-preview. Set the new `Irc:PublicBaseUrl` option (e.g. `"https://chat.example.com"`) so those links come out absolute; unset, they fall back to relative paths as before.
- **Spam protection** — per-user message flood and duplicate-message limits, join and
channel-creation throttles, and automatic escalation: enough rejected sends in a few minutes
earns a timed auto-mute through the normal mute system (moderators see it, and it expires on
its own). One guard covers every ingress — TUI and IRC clients hit the same limits. Mods and
above are exempt, everything is configurable under the new `Spam` section
(`Spam:Enabled` master switch, lenient defaults a fast typist won't trip), and the guard only
ever sees stored content — encrypted-room messages stay ciphertext.
## Improvements
@@ -62,6 +69,10 @@ you send from the TUI now reach your own connected IRC client instantly.
## Notes for server operators
- New config key: `Server:Registration``"open"` (default), `"invite"`, or `"closed"`.
- New config section: `Spam` — flood/duplicate/join/create thresholds and auto-mute duration;
see `appsettings.example.json`. On by default with lenient limits; `Spam:Enabled: false`
turns it all off. Note `Spam:MaxJoinsPerWindow` counts only *first-time* channel joins —
keep it above your public channel count so a new member's first connect isn't throttled.
- New REST endpoints: `POST/GET/DELETE /api/invites` (Admin+), `GET /api/users/me/export`,
`DELETE /api/users/me`.
- One new database migration (`AddInvitesAndReplies`) applies automatically on startup.