Add suspicious user limitations

This commit is contained in:
MartinBraquet
2026-06-05 11:33:35 +02:00
parent efe7e48d3d
commit bf43bf1503
4 changed files with 16 additions and 1 deletions

View File

@@ -1,6 +1,6 @@
{
"name": "@compass/api",
"version": "1.42.1",
"version": "1.43.0",
"private": true,
"description": "Backend API endpoints",
"main": "src/serve.ts",

View File

@@ -1,5 +1,6 @@
import {type JSONContent} from '@tiptap/core'
import {APIErrors, APIHandler} from 'api/helpers/endpoint'
import {isSuspiciousId} from 'common/moderation/suspicious'
import {Notification} from 'common/notifications'
import {convertComment} from 'common/supabase/comment'
import {type Row} from 'common/supabase/utils'
@@ -56,6 +57,7 @@ const validateComment = async (userId: string, creatorId: string, content: JSONC
if (!creator) throw APIErrors.unauthorized('Your account was not found')
if (creator.isBannedFromPosting) throw APIErrors.forbidden('You are banned')
if (isSuspiciousId(creator.id)) throw APIErrors.forbidden('Suspicious users cannot send messages')
const otherUser = await getPrivateUser(userId)
if (!otherUser) throw APIErrors.notFound('Other user not found')

View File

@@ -1,6 +1,7 @@
import {MAX_COMMENT_JSON_LENGTH} from 'api/create-comment'
import {APIErrors, APIHandler} from 'api/helpers/endpoint'
import {createPrivateUserMessageMain} from 'api/helpers/private-messages'
import {isSuspiciousId} from 'common/moderation/suspicious'
import {createSupabaseDirectClient} from 'shared/supabase/init'
import {getUser} from 'shared/utils'
@@ -16,6 +17,7 @@ export const createPrivateUserMessage: APIHandler<'create-private-user-message'>
const creator = await getUser(auth.uid)
if (!creator) throw APIErrors.unauthorized('Your account was not found')
if (creator.isBannedFromPosting) throw APIErrors.forbidden('You are banned')
if (isSuspiciousId(creator.id)) throw APIErrors.forbidden('Suspicious users cannot send messages')
const pg = createSupabaseDirectClient()
return await createPrivateUserMessageMain(creator, channelId, content, pg, 'private')

View File

@@ -0,0 +1,11 @@
// If used long-term, consider moving to a database (new user column or new table)
export const suspiciousIds = ['K5Y1nuQopYhvNpnycvKyoNQ1FaK2']
// Suspicious users are flagged in between legit and banned:
// They still have access to the app (including viewing profiles), but are not allowed to
// interact too heavily with people so as not to bother them (no DMs or endorsements)
// Mark a user as suspicious if they message too many people or if they get reported once
// (ban them if reported more than once)
export function isSuspiciousId(id: string) {
return suspiciousIds.includes(id)
}