Skip to content

feat: arbiterGaming self-assign role bot - #3

Merged
SUaDtL merged 3 commits into
mainfrom
sprint/arbiter-self-assign
Jun 15, 2026
Merged

SUaDtL merged 3 commits into
mainfrom
sprint/arbiter-self-assign

Conversation

@SUaDtL

@SUaDtL SUaDtL commented Jun 15, 2026

Copy link
Copy Markdown
Owner

Summary

Second chartered bot (from discordArbiter's arbiter-self-assign-bot charter), built via /ca:sprint and scaffolded with tools/new-bot (first real exercise of the per-bot convention). 52 bot tests; full suite 239 green; lint/format/types clean.

Behavior

  • Self-serve #roles menu: a select-menu for colors (single-select — picking one removes any other color) and toggle buttons for game pings + GameNight. Ephemeral confirmations; nothing posted publicly per interaction.
  • Owns exactly 12 roles (7 colors + Helldivers + 3 config placeholders + GameNight), creates any missing on startup positioned below its own role, and never touches any other role (Admin/Mod/Member/Founding Four are off-limits).
  • Admin-gated /post-role-menu; menu re-binds after restart via a persisted message id.

Security (elevated surface: Manage Roles + GuildMembers privileged intent)

security-reviewer PASS — 0 critical/high. Make-or-break checks hold:

  • Only-12 boundary guarded at three layers (catalog, handlers, and the role-editor mutation layer — a defense-in-depth isManagedRole guard added per review).
  • Custom-ID forgery resistance — a forged selfassign:ping:Admin resolves to undefined and is rejected.
  • Admin gate (perms + runtime re-check), least-privilege [Guilds, GuildMembers], no-PII, env-only token.

Shared changes

  • @discord-bots/bot-core: new generic JsonValueStore<T> (menu-id persistence).
  • .gitattributes (eol=lf) — fixes Windows-CRLF vs Linux-LF prettier --check inconsistency.

Follow-ups (tracked)

  • [NEEDS-TRIAGE: new-bot-convention] — the generator + dungeon-herald use a Windows-fragile launch guard (no-ops on Windows; fine on Linux/Docker). Fix in the upcoming Docker PR.
  • [CONFIRM-03] — operator renames the 3 placeholder game-ping roles (Game Slot 2/3/4) before live deploy.
  • [NEEDS-TRIAGE: operator-live-verify] — app setup, role-hierarchy (bot above the 12), Manage Roles invite, run. See bots/arbiter-self-assign/README.md.

🤖 Generated with Claude Code

SUaDtL and others added 3 commits June 14, 2026 21:12
Windows checkouts were getting CRLF and failing 'prettier --check' while
Linux CI (LF) passed. '* text=auto eol=lf' makes LF the source of truth
on every platform; renormalizes the two affected files (no content change).

Co-Authored-By: Claude <noreply@anthropic.com>
Second chartered bot (arbiterGaming self-serve roles), scaffolded via
tools/new-bot:

- Owns exactly 12 roles (7 colors + Helldivers + 3 placeholders +
  GameNight); ensures them on startup, never touches any other role
  (the only-12 boundary, guarded at the catalog, handler, and mutation
  layers).
- Select-menu for single-select colors, toggle buttons for game pings;
  ephemeral confirmations; admin-gated /post-role-menu; menu re-binds
  after restart via a persisted message id.
- Least-privilege intents [Guilds, GuildMembers]; token env-only; no PII.
- Reuses @discord-bots/bot-core; adds a generic JsonValueStore.

Security-reviewed (only-12 + custom-id forgery resistance + admin gate):
0 critical/high. discord.js v14.

CHANGELOG: New arbiterGaming self-assign role bot: pick a color and
toggle game-ping roles from a #roles menu.

Ref: ADR-0001, ADR-0003
Co-Authored-By: Claude <noreply@anthropic.com>
Sprint 2 artifacts: spec (AC-01..12), executable plan (all ACCEPTED),
and the append-only sprint log incl. security-review outcome and the
new-bot launch-guard NEEDS-TRIAGE.

Co-Authored-By: Claude <noreply@anthropic.com>
@SUaDtL
SUaDtL merged commit 99c2102 into main Jun 15, 2026
1 check passed
@SUaDtL
SUaDtL deleted the sprint/arbiter-self-assign branch June 15, 2026 01:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant