FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

feat: add permission check for /new command by Rain-0x01-39 · Pull Request #9739 · AstrBotDevs/AstrBot · GitHub

feat: add permission check for /new command - #9739

Open
Rain-0x01-39 wants to merge 1 commit into
AstrBotDevs:masterfrom
Rain-0x01-39:feat/new-cmd-permission-check
Open

feat: add permission check for /new command#9739
Rain-0x01-39 wants to merge 1 commit into
AstrBotDevs:masterfrom
Rain-0x01-39:feat/new-cmd-permission-check

Conversation

Rain-0x01-39 commented Aug 19, 2026
edited
Loading

Copy link
Copy Markdown
Contributor

/new 命令缺少权限控制,在群聊且会话隔离关闭的场景下(共享会话),任意成员都可以创建新会话并切换,影响其他用户的对话上下文。而 /reset 已有对应的权限检查,/new 与之不一致。

Modifications / 改动点

  • astrbot/builtin_stars/builtin_commands/commands/conversation.py:为 new_conv 方法新增场景化权限检查,逻辑与 reset 一致——群聊+会话隔离关闭时默认要求 admin,其余场景 member 即可。权限可通过 Dashboard 的指令管理覆盖。

  • This is NOT a breaking change. / 这不是一个破坏性变更。

Screenshots or Test Results / 运行截图或测试结果


Checklist / 检查清单

  • 😊 If there are new features added in the PR, I have discussed it with the authors through issues/emails, etc.
    / 如果 PR 中有新加入的功能,已经通过 Issue / 邮件等方式和作者讨论过。

  • 👀 My changes have been well-tested, and "Verification Steps" and "Screenshots" have been provided above.
    / 我的更改经过了良好的测试,并已在上方提供了“验证步骤”和“运行截图”

  • 🤓 I have ensured that no new dependencies are introduced, OR if new dependencies are introduced, they have been added to the appropriate locations in requirements.txt and pyproject.toml.
    / 我确保没有引入新依赖库,或者引入了新依赖库的同时将其添加到 requirements.txt 和 pyproject.toml 文件相应位置。

  • 😮 My changes do not introduce malicious code.
    / 我的更改没有引入恶意代码。

    (超小声)feat(provider): add enabled/disabled thinking type for Anthropic provider #8560 fix: validate bool config values and add reasoning field schema #9689 没动静了。

Summary by Sourcery

Enforce context-aware permissions for creating new conversations.

Bug Fixes:

  • Restrict the /new command in shared group conversations to administrators, preventing members from changing the shared conversation context.

Enhancements:

  • Align /new permission behavior with /reset while preserving configurable per-scenario permission overrides.

dosubot Bot added size:M This PR changes 30-99 lines, ignoring generated files. area:core The bug / feature is about astrbot's core, backend labels Aug 19, 2026

sourcery-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Choose a reason Spam Abuse Off Topic Outdated Duplicate Resolved Low Quality

Hey - I've left some high level feedback:

  • The new permission check for /new duplicates logic that likely already exists for /reset; consider extracting a shared helper or reusing the existing mechanism so the two commands stay consistent and easier to maintain.
  • Role and permission values ("admin"/"member") are currently hard-coded string literals; it would be more robust to use centralized constants or an enum and validate against known roles to avoid subtle bugs from typos or future changes.
Prompt for AI Agents
Please address the comments from this code review:

## Overall Comments
- The new permission check for `/new` duplicates logic that likely already exists for `/reset`; consider extracting a shared helper or reusing the existing mechanism so the two commands stay consistent and easier to maintain.
- Role and permission values ("admin"/"member") are currently hard-coded string literals; it would be more robust to use centralized constants or an enum and validate against known roles to avoid subtle bugs from typos or future changes.

Sourcery is free for open source - if you like our reviews please consider sharing them ✨ Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.

This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:core The bug / feature is about astrbot's core, backend size:M This PR changes 30-99 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant


Back | FazBrowse Home | New Git URL