using Remora.Discord.API.Abstractions.Objects; using Remora.Discord.API.Abstractions.Rest; using Remora.Rest.Core; using Remora.Results; using TeamOctolings.Octobot.Data; using TeamOctolings.Octobot.Extensions; namespace TeamOctolings.Octobot.Services; public sealed class AccessControlService { private readonly GuildDataService _data; private readonly IDiscordRestGuildAPI _guildApi; private readonly IDiscordRestUserAPI _userApi; public AccessControlService(GuildDataService data, IDiscordRestGuildAPI guildApi, IDiscordRestUserAPI userApi) { _data = data; _guildApi = guildApi; _userApi = userApi; } private static bool CheckPermission(IEnumerable roles, GuildData data, Snowflake memberId, IGuildMember member, DiscordPermission permission) { var moderatorRole = GuildSettings.ModeratorRole.Get(data.Settings); if (!moderatorRole.Empty() && data.GetOrCreateMemberData(memberId).Roles.Contains(moderatorRole.Value)) { return true; } return roles .Where(r => member.Roles.Contains(r.ID)) .Any(r => r.Permissions.HasPermission(permission) ); } /// /// Checks whether or not a member can interact with another member /// /// The ID of the guild in which an operation is being performed. /// The executor of the operation. /// The target of the operation. /// The operation. /// The cancellation token for this operation. /// /// /// A result which has succeeded with a null string if the member can interact with the target. /// /// A result which has succeeded with a non-null string containing the error message if the member cannot /// interact with the target. /// /// A result which has failed if an error occurred during the execution of this method. /// /// public async Task> CheckInteractionsAsync( Snowflake guildId, Snowflake? interacterId, Snowflake targetId, string action, CancellationToken ct = default) { if (interacterId == targetId) { return Result.FromSuccess($"UserCannot{action}Themselves".Localized()); } var guildResult = await _guildApi.GetGuildAsync(guildId, ct: ct); if (!guildResult.IsDefined(out var guild)) { return Result.FromError(guildResult); } if (interacterId == guild.OwnerID) { return Result.FromSuccess(null); } var botResult = await _userApi.GetCurrentUserAsync(ct); if (!botResult.IsDefined(out var bot)) { return Result.FromError(botResult); } var botMemberResult = await _guildApi.GetGuildMemberAsync(guildId, bot.ID, ct); if (!botMemberResult.IsDefined(out var botMember)) { return Result.FromError(botMemberResult); } var targetMemberResult = await _guildApi.GetGuildMemberAsync(guildId, targetId, ct); if (!targetMemberResult.IsDefined(out var targetMember)) { return Result.FromSuccess(null); } var rolesResult = await _guildApi.GetGuildRolesAsync(guildId, ct); if (!rolesResult.IsDefined(out var roles)) { return Result.FromError(rolesResult); } if (interacterId is null) { return CheckInteractions(action, guild, roles, targetMember, botMember, botMember); } var interacterResult = await _guildApi.GetGuildMemberAsync(guildId, interacterId.Value, ct); if (!interacterResult.IsDefined(out var interacter)) { return Result.FromError(interacterResult); } var data = await _data.GetData(guildId, ct); var hasPermission = CheckPermission(roles, data, interacterId.Value, interacter, action switch { "Ban" => DiscordPermission.BanMembers, "Kick" => DiscordPermission.KickMembers, "Mute" or "Unmute" => DiscordPermission.ModerateMembers, _ => throw new Exception() }); return hasPermission ? CheckInteractions(action, guild, roles, targetMember, botMember, interacter) : Result.FromSuccess($"UserCannot{action}Members".Localized()); } private static Result CheckInteractions( string action, IGuild guild, IReadOnlyList roles, IGuildMember targetMember, IGuildMember botMember, IGuildMember interacter) { if (!targetMember.User.IsDefined(out var targetUser)) { return new ArgumentNullError(nameof(targetMember.User)); } if (botMember.User == targetMember.User) { return Result.FromSuccess($"UserCannot{action}Bot".Localized()); } if (targetUser.ID == guild.OwnerID) { return Result.FromSuccess($"UserCannot{action}Owner".Localized()); } var targetRoles = roles.Where(r => targetMember.Roles.Contains(r.ID)).ToList(); var botRoles = roles.Where(r => botMember.Roles.Contains(r.ID)); var targetBotRoleDiff = targetRoles.MaxOrDefault(r => r.Position) - botRoles.MaxOrDefault(r => r.Position); if (targetBotRoleDiff >= 0) { return Result.FromSuccess($"BotCannot{action}Target".Localized()); } var interacterRoles = roles.Where(r => interacter.Roles.Contains(r.ID)); var targetInteracterRoleDiff = targetRoles.MaxOrDefault(r => r.Position) - interacterRoles.MaxOrDefault(r => r.Position); return targetInteracterRoleDiff < 0 ? Result.FromSuccess(null) : Result.FromSuccess($"UserCannot{action}Target".Localized()); } }