mirror of
https://github.com/RedWizardsLab/EchoHub.git
synced 2026-09-04 08:36:11 +02:00
feat: Implement spam protection with configurable limits and auto-mute escalation
This commit is contained in:
@@ -42,6 +42,13 @@ you send from the TUI now reach your own connected IRC client instantly.
|
||||
- **`[open]` images without saving them** — every image attachment now shows `[open] [↓ save original]` beneath its preview. Open views the image in your default browser straight from the server; in end-to-end encrypted rooms (where a browser would only see ciphertext) the client downloads, decrypts with the room key, and opens the image in your OS viewer from a temp file instead. Both actions are individually clickable, Enter on the line opens, and the right-click menu carries both.
|
||||
- **Attachment links work in a browser** — `GET /api/files/{id}` is now a capability URL: the unguessable GUID in the link is the access token (Discord-CDN style), so attachment links can be opened directly in a browser or shared to IRC without a login token. Images and audio are served inline so the browser displays them instead of forcing a download. Blobs from encrypted rooms remain ciphertext, so their links reveal nothing.
|
||||
- **IRC gets image links instead of terminal art** — the gateway no longer floods IRC clients with truecolor-ANSI ASCII art for images. Each attachment is now a single line — `[Image: photo.png] https://your-server/api/files/…` — the convention every IRC client understands, and ones like TheLounge or IRCCloud auto-preview. Set the new `Irc:PublicBaseUrl` option (e.g. `"https://chat.example.com"`) so those links come out absolute; unset, they fall back to relative paths as before.
|
||||
- **Spam protection** — per-user message flood and duplicate-message limits, join and
|
||||
channel-creation throttles, and automatic escalation: enough rejected sends in a few minutes
|
||||
earns a timed auto-mute through the normal mute system (moderators see it, and it expires on
|
||||
its own). One guard covers every ingress — TUI and IRC clients hit the same limits. Mods and
|
||||
above are exempt, everything is configurable under the new `Spam` section
|
||||
(`Spam:Enabled` master switch, lenient defaults a fast typist won't trip), and the guard only
|
||||
ever sees stored content — encrypted-room messages stay ciphertext.
|
||||
|
||||
## Improvements
|
||||
|
||||
@@ -62,6 +69,10 @@ you send from the TUI now reach your own connected IRC client instantly.
|
||||
## Notes for server operators
|
||||
|
||||
- New config key: `Server:Registration` — `"open"` (default), `"invite"`, or `"closed"`.
|
||||
- New config section: `Spam` — flood/duplicate/join/create thresholds and auto-mute duration;
|
||||
see `appsettings.example.json`. On by default with lenient limits; `Spam:Enabled: false`
|
||||
turns it all off. Note `Spam:MaxJoinsPerWindow` counts only *first-time* channel joins —
|
||||
keep it above your public channel count so a new member's first connect isn't throttled.
|
||||
- New REST endpoints: `POST/GET/DELETE /api/invites` (Admin+), `GET /api/users/me/export`,
|
||||
`DELETE /api/users/me`.
|
||||
- One new database migration (`AddInvitesAndReplies`) applies automatically on startup.
|
||||
|
||||
Reference in New Issue
Block a user