Dedicated 'MANAGE_AUTOMOD' Permission
Current Situation: To manage the AutoMod settings, users need either "Manage Server" or "Administrator" permissions, which grant extensive control beyond AutoMod management, including server settings and role management. This broad access can pose security risks, especially when only AutoMod management is intended.
Problem: Assigning "Manage Server" permissions for AutoMod management inadvertently grants access to numerous unrelated and potentially sensitive functions, such as:
- Modifying server name and icon
- Managing server settings and invites
- Adding or removing bots, which could introduce security vulnerabilities
Proposal: Introduce a "MANAGE_AUTOMOD" permission within Discord's API to exclusively allow moderators to manage AutoMod settings without broader access to server management functions. This targeted permission would enhance security by limiting access to critical functions while enabling moderators to manage AutoMod settings effectively.
Rationale: A dedicated permission for AutoMod management would mitigate the risk of misuse by restricting moderators' access to only necessary functions, ensuring a safer server environment and more granular control over permissions.
DISCLAIMER: This feature request was taken from https://github.com/discord/discord-api-docs/discussions/5485 and changed slightly to improve readability.
Yorum yazmak için lütfen oturum açın.
Yorumlar
0 yorum