Files
Max LampertandClaude Opus 4.8 57a5daccf9 relay: enforce ban/timeout write-block on command kinds
ingest_event routed command kinds — DM open/add/hide, workflow
define/trigger, approval grant/deny — straight to
command_executor::handle_command and returned before the durable
ban/timeout write-block gate that ordinary writes pass through.
handle_command performs no restriction check of its own, so a banned or
timed-out member could still open DMs, define or trigger workflows, and
grant or deny approvals over signed POST /events. The moderation-command
and relay-admin kinds are also routed around the shared gate, but each
re-checks the ban inside its own handler; command kinds had no such
check.

Enforce the gate before routing command kinds. Command kinds are
ordinary writes, not administrative capability, so they get the full
gate including timeouts — the relay-admin timeout exemption does not
extend to them. Extract the ban/timeout decision into
restriction_block/enforce_moderation_restriction so the command-kind
path and the ordinary-write path share one implementation and cannot
drift; the restriction-state lookup fails closed on a DB error.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Signed-off-by: Max Lampert <maxwell@squareup.com>
2026-07-28 17:55:24 -07:00
..
2026-07-27 14:18:24 -04:00