Files
wehub-resource-sync 426e9eeabd
Voice Workbench / headless workbench (mocked backends) (push) Has been cancelled
Voice Workbench / real acoustic lane (nightly, provisioned only) (push) Has been cancelled
ci / test (push) Has been cancelled
ci / lint-and-format (push) Has been cancelled
ci / build (push) Has been cancelled
ci / dev-startup (push) Has been cancelled
gitleaks / gitleaks (push) Has been cancelled
Markdown Links / Relative Markdown Links (push) Has been cancelled
Quality (Extended) / Homepage Build (PR smoke) (push) Has been cancelled
Quality (Extended) / Comment-only diff guard (push) Has been cancelled
Quality (Extended) / Format + Type Safety Ratchet (push) Has been cancelled
Quality (Extended) / Develop Gate (secret scan + UI determinism) (push) Has been cancelled
Quality (Extended) / Develop Gate (lint) (push) Has been cancelled
Chat shell gestures / Chat shell gesture + parity e2e (push) Has been cancelled
Cloud Gateway Discord / Test (push) Has been cancelled
Benchmark Bridge Tests / benchmark (bunx @biomejs/biome check packages/lifeops-bench/src, benchmark-lint) (push) Has been cancelled
Benchmark Bridge Tests / benchmark (bunx vitest run --config packages/lifeops-bench/vitest.config.ts --root packages/lifeops-bench --passWithNoTests, benchmark-tests) (push) Has been cancelled
Build Agent Image / build-and-push (push) Has been cancelled
Dev Smoke / bun run dev onboarding chat (push) Has been cancelled
Dev Smoke / Vite HMR dependency-level smoke (push) Has been cancelled
Electrobun Submodule Guard / electrobun gitlink is fetchable (push) Has been cancelled
Publish @elizaos/example-code / check_npm (push) Has been cancelled
Publish @elizaos/example-code / publish_npm (push) Has been cancelled
Publish @elizaos/plugin-elizacloud / verify_version (push) Has been cancelled
Publish @elizaos/plugin-elizacloud / publish_npm (push) Has been cancelled
Sandbox Live Smoke / Sandbox live smoke (push) Has been cancelled
Snap Build & Test / Build Snap (amd64) (push) Has been cancelled
Snap Build & Test / Build Snap (arm64) (push) Has been cancelled
Test Packaging / elizaos CLI global-install smoke (node + bun) (push) Has been cancelled
Cloud Gateway Webhook / Test (push) Has been cancelled
Cloud Tests / lint-and-types (push) Has been cancelled
Cloud Tests / unit-tests (push) Has been cancelled
Cloud Tests / integration-tests (push) Has been cancelled
Cloud Tests / e2e-tests (push) Has been cancelled
CodeQL Advanced / Analyze (javascript-typescript) (push) Has been cancelled
Deploy Apps Worker (Product 2) / Determine environment (push) Has been cancelled
Deploy Apps Worker (Product 2) / Deploy apps worker to apps-control host (${{ needs.determine-env.outputs.environment }}) (push) Has been cancelled
Deploy Eliza Provisioning Worker / Determine environment (push) Has been cancelled
Deploy Eliza Provisioning Worker / Deploy worker to Hetzner host (${{ needs.determine-env.outputs.environment }} @ ${{ needs.determine-env.outputs.deployment_sha }}) (push) Has been cancelled
Dev Smoke / Classify changed paths (push) Has been cancelled
supply-chain / sbom (push) Has been cancelled
supply-chain / vulnerability-scan (push) Has been cancelled
Build, Push & Deploy to Phala Cloud / build-and-push (push) Has been cancelled
Test Packaging / Validate Packaging Configs (push) Has been cancelled
Test Packaging / Build & Test PyPI Package (push) Has been cancelled
Test Packaging / PyPI on Python ${{ matrix.python }} (push) Has been cancelled
Test Packaging / Pack & Test JS Tarballs (push) Has been cancelled
UI Fixture E2E / ui-fixture-e2e (push) Has been cancelled
UI Fixture E2E / fixture-e2e (push) Has been cancelled
UI Story Gate / story-gate (push) Has been cancelled
vault-ci / test (macos-latest) (push) Has been cancelled
vault-ci / test (ubuntu-latest) (push) Has been cancelled
vault-ci / test (windows-latest) (push) Has been cancelled
vault-ci / app-core wiring tests (push) Has been cancelled
verify-patches / verify patches/CHECKSUMS.sha256 (push) Has been cancelled
Voice Benchmark Smoke / voice-emotion fixture smoke (push) Has been cancelled
Voice Benchmark Smoke / voiceagentbench fixture smoke (push) Has been cancelled
Voice Benchmark Smoke / voicebench-quality unit smoke (push) Has been cancelled
Voice Benchmark Smoke / voicebench TypeScript unit (no audio) (push) Has been cancelled
Voice Benchmark Smoke / voice bench smoke summary (push) Has been cancelled
Windows CI / windows ([bun run --cwd packages/app-core test bun run --cwd packages/elizaos test bun run --cwd packages/cloud/shared test], app-and-cli) (push) Has been cancelled
Windows CI / windows ([bun run --cwd packages/scenario-runner test bun run --cwd packages/vault test bun run --cwd packages/security test bun run --cwd plugins/plugin-coding-tools test], framework-packages) (push) Has been cancelled
Windows CI / windows ([bun run --cwd plugins/plugin-elizacloud test bun run --cwd plugins/plugin-discord test bun run --cwd plugins/plugin-anthropic test bun run --cwd plugins/plugin-openai test bun run --cwd plugins/plugin-app-control test bun run --cwd plugins/pl… (push) Has been cancelled
Windows CI / windows ([node packages/scripts/run-turbo.mjs run build --filter=@elizaos/core --filter=@elizaos/shared --filter=@elizaos/agent --concurrency=4 node packages/scripts/run-bash-linux-only.mjs scripts/verify-riscv64-buildpaths.sh node packages/scripts/run… (push) Has been cancelled
Windows CI / windows ([node packages/scripts/run-turbo.mjs run typecheck --filter=@elizaos/core --filter=@elizaos/shared --filter=@elizaos/cloud-shared --concurrency=4 bun run --cwd packages/core test bun run --cwd packages/shared test], core-runtime, 75) (push) Has been cancelled
chore: import upstream snapshot with attribution
2026-07-13 12:43:05 +08:00

246 lines
6.8 KiB
TypeScript

/**
* Owner/entity id resolution and world/entity metadata for Discord. Maps
* Discord user ids to runtime entity ids, keeping bot-application owner
* aliases separate from Discord team admin grants so message attribution stays
* auditable.
*/
import {
createUniqueUuid,
type IAgentRuntime,
type Metadata,
type RolesWorldMetadata,
recordOwnerGrant,
recordRoleGrant,
stringToUuid,
} from "@elizaos/core";
const CANONICAL_OWNER_SETTING_KEYS = ["ELIZA_ADMIN_ENTITY_ID"] as const;
const DISCORD_SNOWFLAKE_PATTERN = /^\d{15,20}$/;
function getCanonicalOwnerId(runtime: IAgentRuntime): string | undefined {
for (const key of CANONICAL_OWNER_SETTING_KEYS) {
const value = runtime.getSetting?.(key);
if (typeof value !== "string") {
continue;
}
const trimmed = value.trim();
if (trimmed.length > 0) {
return trimmed;
}
}
return undefined;
}
function asRecord(value: unknown): Record<string, unknown> | null {
return value && typeof value === "object" && !Array.isArray(value)
? (value as Record<string, unknown>)
: null;
}
function readDiscordSnowflake(value: unknown): string | null {
if (typeof value !== "string") {
return null;
}
const trimmed = value.trim();
return DISCORD_SNOWFLAKE_PATTERN.test(trimmed) ? trimmed : null;
}
function readUserIdFromOwnerLike(value: unknown): string | null {
const owner = asRecord(value);
if (!owner) {
return null;
}
return (
readDiscordSnowflake(owner.id) ??
readDiscordSnowflake(asRecord(owner.user)?.id) ??
readDiscordSnowflake(owner.ownerId) ??
readDiscordSnowflake(owner.ownerUserId)
);
}
export function resolveElizaOwnerEntityId(runtime: IAgentRuntime): string {
const configuredOwnerId = getCanonicalOwnerId(runtime);
if (configuredOwnerId) {
return configuredOwnerId;
}
const agentName = runtime.character?.name?.trim() || runtime.agentId;
return stringToUuid(`${agentName}-admin-entity`);
}
export function resolveDiscordRuntimeEntityId(
runtime: IAgentRuntime,
userId: string,
ownerDiscordUserIds: Iterable<string> = [],
): string {
for (const ownerUserId of ownerDiscordUserIds) {
if (ownerUserId === userId) {
return resolveElizaOwnerEntityId(runtime);
}
}
return createUniqueUuid(runtime, userId);
}
export function extractDiscordOwnerUserIds(application: unknown): string[] {
const applicationRecord = asRecord(application);
if (!applicationRecord) {
return [];
}
const ownerCandidates = new Set<string>();
const directOwnerId = readUserIdFromOwnerLike(applicationRecord.owner);
if (directOwnerId) {
ownerCandidates.add(directOwnerId);
}
const team = asRecord(applicationRecord.team);
const teamOwnerId =
readDiscordSnowflake(team?.ownerId) ??
readDiscordSnowflake(team?.ownerUserId);
if (teamOwnerId) {
ownerCandidates.add(teamOwnerId);
}
return [...ownerCandidates];
}
// Discord team membership_state: 1 = invited (pending), 2 = accepted.
const TEAM_MEMBERSHIP_ACCEPTED = 2;
export function extractDiscordTeamAdminUserIds(application: unknown): string[] {
const applicationRecord = asRecord(application);
if (!applicationRecord) {
return [];
}
const team = asRecord(applicationRecord.team);
const teamMembers = team?.members;
// Discord.js returns team.members as a Collection (Map-like), not an Array.
// Handle both Array and iterable (Collection/Map) shapes.
const memberIterable: Iterable<unknown> | null = Array.isArray(teamMembers)
? teamMembers
: teamMembers &&
typeof teamMembers === "object" &&
typeof (teamMembers as Iterable<unknown>)[Symbol.iterator] ===
"function"
? (teamMembers as Iterable<unknown>)
: null;
const adminCandidates = new Set<string>();
if (memberIterable) {
for (const entry of memberIterable) {
// Collection/Map yields [key, value] tuples; Array yields values directly.
const member = asRecord(Array.isArray(entry) ? entry[1] : entry);
if (!member) {
continue;
}
const memberId = readUserIdFromOwnerLike(member);
if (!memberId) {
continue;
}
// Connector-admin standing is only for members who actually hold it on
// Discord's side: pending invitees (membership_state 1) have not
// accepted, and read_only members deliberately hold no write access —
// neither may be seeded as an admin (#14712). Members whose state/role
// fields are absent (older discord.js payload shapes) are treated as
// accepted developers.
const membershipStateRaw =
member.membershipState ?? member.membership_state;
const membershipState =
typeof membershipStateRaw === "number" ? membershipStateRaw : null;
if (
membershipState !== null &&
membershipState !== TEAM_MEMBERSHIP_ACCEPTED
) {
continue;
}
if (typeof member.role === "string" && member.role === "read_only") {
continue;
}
adminCandidates.add(memberId);
}
}
return [...adminCandidates];
}
export function parseDiscordOwnerUserIds(value: unknown): string[] {
const rawValues = (() => {
if (Array.isArray(value)) {
return value;
}
if (typeof value !== "string" || value.trim().length === 0) {
return [];
}
try {
const parsed = JSON.parse(value) as unknown;
return Array.isArray(parsed) ? parsed : [];
} catch {
return [];
}
})();
return rawValues
.map((entry) => readDiscordSnowflake(entry))
.filter((entry): entry is string => Boolean(entry));
}
export function buildDiscordWorldMetadata(
runtime: IAgentRuntime,
guildOwnerId: string | undefined,
): Metadata | undefined {
const ownerId = resolveElizaOwnerEntityId(runtime);
const metadata: RolesWorldMetadata = { ownership: { ownerId } };
recordOwnerGrant(metadata, ownerId);
// Discord guild ownership is connector provenance, not app ownership. Record
// it through core's canonical grant helper so the role and its source stay
// paired, and let the connector-admin whitelist decide at read time whether
// the grant can rise above GUEST.
if (guildOwnerId && DISCORD_SNOWFLAKE_PATTERN.test(guildOwnerId)) {
const guildOwnerEntityId = createUniqueUuid(runtime, guildOwnerId);
if (guildOwnerEntityId !== ownerId) {
recordRoleGrant(metadata, guildOwnerEntityId, "ADMIN", "connector_admin");
}
}
return metadata;
}
export function buildDiscordEntityMetadata(
userId: string,
userName: string,
name: string,
globalName?: string,
avatarUrl?: string,
): Metadata {
return {
default: {
username: userName,
name,
...(typeof avatarUrl === "string" && avatarUrl.length > 0
? { avatarUrl }
: {}),
},
discord: {
id: userId,
userId,
userName,
username: userName,
name,
...(typeof globalName === "string" && globalName.length > 0
? { globalName }
: {}),
...(typeof avatarUrl === "string" && avatarUrl.length > 0
? { avatarUrl }
: {}),
},
originalId: userId,
username: userName,
displayName: name,
...(typeof avatarUrl === "string" && avatarUrl.length > 0
? { avatarUrl }
: {}),
};
}