Cockatrice/libcockatrice_protocol/libcockatrice/protocol/pb/moderator_commands.proto
BruebachL ed4eb1cb31
Some checks are pending
Build Desktop / Configure (push) Waiting to run
Build Desktop / Debian 13 (push) Blocked by required conditions
Build Desktop / Debian 12 (push) Blocked by required conditions
Build Desktop / Fedora 44 (push) Blocked by required conditions
Build Desktop / Fedora 43 (push) Blocked by required conditions
Build Desktop / Servatrice_Debian 12 (push) Blocked by required conditions
Build Desktop / Ubuntu 26.04 (push) Blocked by required conditions
Build Desktop / Ubuntu 24.04 (push) Blocked by required conditions
Build Desktop / Arch (push) Blocked by required conditions
Build Desktop / macOS 15 (push) Blocked by required conditions
Build Desktop / macOS 13 Intel (push) Blocked by required conditions
Build Desktop / macOS 14 (push) Blocked by required conditions
Build Desktop / macOS 15 Debug (push) Blocked by required conditions
Build Desktop / Windows 10 (push) Blocked by required conditions
Build Docker Image / amd64 & arm64 (push) Waiting to run
[Server/Client/Protocol] Reporting users + moderation queue functionality (#7091)
* [Server/Client/Protocol] Reporting users + moderation queue functionality

Took 6 minutes

Took 3 minutes

Took 8 seconds

Took 11 minutes

Took 12 minutes

Took 7 minutes

Took 15 seconds

Took 2 minutes

Took 1 minute


Took 30 seconds

Took 16 seconds

* CI Fix

Took 6 minutes

* CI Fix

Took 6 minutes

* [Protocol] Add moderation investigation commands

Adds the protocol layer for the moderation investigation suite:
- Command_GetUserSessions/GetUserAlts/GetModeratorLastLogins/ResetUserPassword/RemoveUserAvatar (1013-1017)
- Response extensions 1215-1219 with ServerInfo messages for sessions, alts, and staff logins
- last_login on Response_ReportUserInfo and warning_il on Response_WarnList

Took 2 minutes

* [Utility] Add warning categories parser with infraction levels

Parses the server's 'officialwarnings' setting (comma-separated, optional
'|IL' suffix) into WarningCategory structs so the client can display the
infraction level of each warning category. Includes GTest coverage.

* [Server] Add moderation investigation tools

Implements the server side of the moderation suite:
- getUserSessions/getUserAlts/getModeratorLastLogins/removeUserAvatar DB methods
- Handlers for all five new commands with audit records (PASSWORD_RESET,
  REMOVE_USER_AVATAR); password resets return a generated temporary password
- cmdGetWarnList now reports per-category infraction levels from the
  officialwarnings setting; cmdReportUserInfo reports last_login
- Update servatrice.ini.example with the warning taxonomy
- Password/avatar mutations report RespNameNotFound when the user does not exist

* [Client] Add moderation tab with investigate, password reset, and avatar removal

- New Moderation tab: search a user to show account info, alternate
  accounts, login sessions, and staff last logins; actions to reset the
  user's password (shows the generated temporary password) and remove the
  user's avatar
- 'Investigate user' entry in the user context menu opens the tab pre-loaded
  for that user
- Warning dialog shows the infraction level of each warning category
- Tab wired into TabSupervisor with a moderator-gated menu action, shortcut,
  and tabs.ini persistence (default closed)

* [Server/Client/Protocol] Address PR #7091 review: security, bug, and perf fixes

Security:
- Promote RESET_USER_PASSWORD to admin-only dispatch (was moderator-accessible)
- Reject password reset on users with equal/higher privilege than caller
- Notify affected user via Event_NotifyUser::CUSTOM when password is reset
- Add server-side category whitelist for reports
- Drop reporter name fallback in comment/details authorization (ID-only)
- Force password change: new DB column + login enforcement + client disconnect

Bugs:
- XSS via QTextEdit::append() → insertPlainText() in report tab and utils
- allNotified initialized to true even with empty recipients list
- Warning combo box: use currentData() instead of baked-in display text
- Report resolution now records who resolved (resolved_by column + audit)

Performance:
- IP-correlation subquery: add 6-month window + LIMIT 200
- getUserSessions: clamp limit to 500

Non-blocking:
- Palette-aware colors in report_utils.cpp (dark/light mode)
- Report list pagination: offset/limit fields + total_count in response
- SessionCommand enum gap comment for reserved values 1201-1203

Schema: 36→37 (force_password_change), 37→38 (resolved_by)

Took 12 minutes


Took 16 seconds

* Fix macOs pedantry

Took 5 minutes

---------

Co-authored-by: Lukas Brübach <Bruebach.Lukas@bdosecurity.de>
2026-08-21 15:00:13 +02:00

176 lines
4.8 KiB
Protocol Buffer

syntax = "proto2";
message ModeratorCommand {
enum ModeratorCommandType {
BAN_FROM_SERVER = 1000;
BAN_HISTORY = 1001;
WARN_USER = 1002;
WARN_HISTORY = 1003;
WARN_LIST = 1004;
VIEWLOG_HISTORY = 1005;
GRANT_REPLAY_ACCESS = 1006;
FORCE_ACTIVATE_USER = 1007;
GET_ADMIN_NOTES = 1008;
UPDATE_ADMIN_NOTES = 1009;
ADD_CARD_ART_RULE = 1010;
REMOVE_CARD_ART_RULE = 1011;
LIST_CARD_ART_RULES = 1012;
GET_USER_SESSIONS = 1013;
GET_USER_ALTS = 1014;
GET_MODERATOR_LAST_LOGINS = 1015;
RESET_USER_PASSWORD = 1016;
REMOVE_USER_AVATAR = 1017;
REPORT_LIST = 1200;
REPORT_ASSIGN = 1201;
REPORT_RESOLVE = 1202;
REPLAY_DOWNLOAD_BY_GAME_ID = 1203;
REPORT_USER_INFO = 1204;
REPORT_STATS = 1205;
}
extensions 100 to max;
}
message Command_BanFromServer {
extend ModeratorCommand {
optional Command_BanFromServer ext = 1000;
}
optional string user_name = 1;
optional string address = 2;
optional uint32 minutes = 3;
optional string reason = 4;
optional string visible_reason = 5;
optional string clientid = 6;
optional uint32 remove_messages = 7;
}
message Command_GetBanHistory {
extend ModeratorCommand {
optional Command_GetBanHistory ext = 1001;
}
optional string user_name = 1;
}
message Command_WarnUser {
extend ModeratorCommand {
optional Command_WarnUser ext = 1002;
}
optional string user_name = 1;
optional string reason = 2;
optional string clientid = 3;
optional uint32 remove_messages = 4;
}
message Command_GetWarnHistory {
extend ModeratorCommand {
optional Command_GetWarnHistory ext = 1003;
}
optional string user_name = 1;
}
message Command_GetWarnList {
extend ModeratorCommand {
optional Command_GetWarnList ext = 1004;
}
optional string mod_name = 1;
optional string user_name = 2;
optional string user_clientid = 3;
}
message Command_ViewLogHistory {
extend ModeratorCommand {
optional Command_ViewLogHistory ext = 1005;
}
optional string user_name = 1; // user that created message
optional string ip_address = 2; // ip address of user that created message
optional string game_name = 3; // client id of user that created the message
optional string game_id = 4; // game number the message was sent to
optional string message = 5; // raw message that was sent
repeated string log_location = 6; // destination of message (ex: main room, game room, private chat)
required uint32 date_range = 7; // the length of time (in minutes) to look back for
optional uint32 maximum_results = 8; // the maximum number of query results
}
message Command_GrantReplayAccess {
extend ModeratorCommand {
optional Command_GrantReplayAccess ext = 1006;
}
optional uint32 replay_id = 1;
optional string moderator_name = 2;
}
message Command_ForceActivateUser {
extend ModeratorCommand {
optional Command_ForceActivateUser ext = 1007;
}
optional string username_to_activate = 1;
optional string moderator_name = 2;
}
message Command_GetAdminNotes {
extend ModeratorCommand {
optional Command_GetAdminNotes ext = 1008;
}
optional string user_name = 1;
}
message Command_UpdateAdminNotes {
extend ModeratorCommand {
optional Command_UpdateAdminNotes ext = 1009;
}
optional string user_name = 1;
optional string notes = 2;
}
message Command_AddCardArtRule {
extend ModeratorCommand {
optional Command_AddCardArtRule ext = 1010;
}
optional string card_name = 1;
optional string card_provider_id = 2;
optional string mode = 3; // "ALLOW" or "DENY"
optional string reason = 4;
}
message Command_RemoveCardArtRule {
extend ModeratorCommand {
optional Command_RemoveCardArtRule ext = 1011;
}
optional string card_name = 1;
optional string card_provider_id = 2;
}
message Command_ListCardArtRules {
extend ModeratorCommand {
optional Command_ListCardArtRules ext = 1012;
}
}
message Command_GetUserSessions {
extend ModeratorCommand {
optional Command_GetUserSessions ext = 1013;
}
optional string user_name = 1;
optional uint32 limit = 2 [default = 110];
}
message Command_GetUserAlts {
extend ModeratorCommand {
optional Command_GetUserAlts ext = 1014;
}
optional string user_name = 1;
}
message Command_GetModeratorLastLogins {
extend ModeratorCommand {
optional Command_GetModeratorLastLogins ext = 1015;
}
}
message Command_RemoveUserAvatar {
extend ModeratorCommand {
optional Command_RemoveUserAvatar ext = 1017;
}
optional string user_name = 1;
}