mirror of
https://github.com/block/buzz.git
synced 2026-08-18 06:50:31 +02:00
ingest_event routed command kinds — DM open/add/hide, workflow define/trigger, approval grant/deny — straight to command_executor::handle_command and returned before the durable ban/timeout write-block gate that ordinary writes pass through. handle_command performs no restriction check of its own, so a banned or timed-out member could still open DMs, define or trigger workflows, and grant or deny approvals over signed POST /events. The moderation-command and relay-admin kinds are also routed around the shared gate, but each re-checks the ban inside its own handler; command kinds had no such check. Enforce the gate before routing command kinds. Command kinds are ordinary writes, not administrative capability, so they get the full gate including timeouts — the relay-admin timeout exemption does not extend to them. Extract the ban/timeout decision into restriction_block/enforce_moderation_restriction so the command-kind path and the ordinary-write path share one implementation and cannot drift; the restriction-state lookup fails closed on a DB error. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Signed-off-by: Max Lampert <maxwell@squareup.com>