using Remora.Discord.API.Abstractions.Objects; using Remora.Discord.API.Abstractions.Rest; using Remora.Rest.Core; using Remora.Results; using TeamOctolings.Octobot.Data; using TeamOctolings.Octobot.Extensions; namespace TeamOctolings.Octobot.Services; public sealed class AccessControlService { private readonly GuildDataService _data; private readonly IDiscordRestGuildAPI _guildApi; private readonly IDiscordRestUserAPI _userApi; public AccessControlService(GuildDataService data, IDiscordRestGuildAPI guildApi, IDiscordRestUserAPI userApi) { _data = data; _guildApi = guildApi; _userApi = userApi; } private static bool CheckPermission(IEnumerable roles, GuildData data, MemberData memberData, DiscordPermission permission) { var moderatorRole = GuildSettings.ModeratorRole.Get(data.Settings); if (!moderatorRole.Empty() && memberData.Roles.Contains(moderatorRole.Value)) { return true; } return roles .Where(r => memberData.Roles.Contains(r.ID.Value)) .Any(r => r.Permissions.HasPermission(permission) ); } /// /// Checks whether or not a member can interact with another member /// /// The ID of the guild in which an operation is being performed. /// The executor of the operation. /// The target of the operation. /// The operation. /// The cancellation token for this operation. /// /// /// A result which has succeeded with a null string if the member can interact with the target. /// /// A result which has succeeded with a non-null string containing the error message if the member cannot /// interact with the target. /// /// A result which has failed if an error occurred during the execution of this method. /// /// public async Task> CheckInteractionsAsync( Snowflake guildId, Snowflake? interacterId, Snowflake targetId, string action, CancellationToken ct = default) { if (interacterId == targetId) { return Result.FromSuccess($"UserCannot{action}Themselves".Localized()); } var guildResult = await _guildApi.GetGuildAsync(guildId, ct: ct); if (!guildResult.IsDefined(out var guild)) { return Result.FromError(guildResult); } if (interacterId == guild.OwnerID) { return Result.FromSuccess(null); } var botResult = await _userApi.GetCurrentUserAsync(ct); if (!botResult.IsDefined(out var bot)) { return Result.FromError(botResult); } var rolesResult = await _guildApi.GetGuildRolesAsync(guildId, ct); if (!rolesResult.IsDefined(out var roles)) { return Result.FromError(rolesResult); } var data = await _data.GetData(guildId, ct); var targetData = data.GetOrCreateMemberData(targetId); var botData = data.GetOrCreateMemberData(bot.ID); if (interacterId is null) { return CheckInteractions(action, guild, roles, targetData, botData, botData); } var interacterData = data.GetOrCreateMemberData(interacterId.Value); var hasPermission = CheckPermission(roles, data, interacterData, action switch { "Ban" => DiscordPermission.BanMembers, "Kick" => DiscordPermission.KickMembers, "Mute" or "Unmute" or "Warn" or "Unwarn" or "GetWarns" => DiscordPermission.ModerateMembers, _ => throw new Exception() }); return hasPermission ? CheckInteractions(action, guild, roles, targetData, botData, interacterData) : Result.FromSuccess($"UserCannot{action}Members".Localized()); } private static Result CheckInteractions( string action, IGuild guild, IReadOnlyList roles, MemberData targetData, MemberData botData, MemberData interacterData) { if (botData.Id == targetData.Id) { return Result.FromSuccess($"UserCannot{action}Bot".Localized()); } if (targetData.Id == guild.OwnerID) { return Result.FromSuccess($"UserCannot{action}Owner".Localized()); } var targetRoles = roles.Where(r => targetData.Roles.Contains(r.ID.Value)).ToList(); var botRoles = roles.Where(r => botData.Roles.Contains(r.ID.Value)); var targetBotRoleDiff = targetRoles.MaxOrDefault(r => r.Position) - botRoles.MaxOrDefault(r => r.Position); if (targetBotRoleDiff >= 0) { return Result.FromSuccess($"BotCannot{action}Target".Localized()); } var interacterRoles = roles.Where(r => interacterData.Roles.Contains(r.ID.Value)); var targetInteracterRoleDiff = targetRoles.MaxOrDefault(r => r.Position) - interacterRoles.MaxOrDefault(r => r.Position); return targetInteracterRoleDiff < 0 ? Result.FromSuccess(null) : Result.FromSuccess($"UserCannot{action}Target".Localized()); } }