* SEC-01: add pull-request CI and stop the deploy leaving DOT_ENV on the VPS A merge to main runs the merged commit as root on the club VPS through the self-hosted runner, and this repo has no PR CI, no required review and no status check. - .github/workflows/ci.yml: fmt / clippy / build --locked / test on ubuntu-latest, contents: read, both actions pinned by commit SHA. Never the VPS. - deploy.yml: keep push to main, add workflow_dispatch, permissions contents: read, environment: production, and an if: always() step that removes the .env the deploy writes into the workspace. - .dockerignore: keep that .env, target/ and .git out of the build context. - Dockerfile: --locked on both cargo build --release lines. environment: production gates nothing until required reviewers are configured on the environment itself, and the ruleset still requires zero approving reviews. Both are owner-only and listed in the pull request. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * SEC-01: make cargo fmt and clippy clean so the CI job can go green The CI workflow added in #5 fails on code that predates it: three files were unformatted and `cargo clippy --all-targets -- -D warnings` reported 26 errors. A red check cannot be made a required status check on the protect-main ruleset, which is what this unblocks. `cargo fmt --all` over three files, and 26 clippy errors resolved: 18 via `cargo clippy --all-targets --fix`, the rest by hand. Two fixes uncovered lints that had been masked (an `unnecessary_unwrap` in info.rs behind the needless borrow on the line above, and two `unnecessary_to_owned` at the call sites of a signature that moved from `&String` to `&str`), so 28 fixes for 26 warnings. Three `#[allow]`s where the only real fix would change a signature or a public API: `result_large_err` on `AppState::new` (the large variant is `supabase::Error`, owned by supabase-lib-rs) and `too_many_arguments` on `log_embed` and on the `embed` slash command. No behaviour change. src/ only; .github/, Dockerfile, .dockerignore, Cargo.toml and Cargo.lock are untouched. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * SEC-01: pin actions/checkout in the deploy workflow to a commit SHA deploy.yml runs on the self-hosted VPS runner with passwordless sudo, so a mutable tag on this action is a code-execution path onto that host if the tag is ever moved. Pinned to the commit v4 currently resolves to (11d5960a326750d5838078e36cf38b85af677262), verified against upstream — this is the same code the deploy already runs today, not a version bump. ci.yml is on v7.0.1; the deploy path is deliberately left on v4 so that pinning does not smuggle a major-version change into a workflow whose only test is a live deploy. Raised by Codex review of PR #5 as the one unpinned `uses:` in either workflow. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|---|---|---|
| .github/workflows | ||
| src | ||
| .dockerignore | ||
| .env.example | ||
| .gitignore | ||
| Cargo.lock | ||
| Cargo.toml | ||
| docker-compose.yml | ||
| Dockerfile | ||
| LICENSE | ||
| README.md | ||
DSEC Discord Bot
Deakin Software Engineering Club Discord Bot project. To encourage students to learn Rust and how to work in a practical and collaborative project.
Setup
Setup Rust
Installing Rustup will also install cargo
Linux & MacOS:
curl https://sh.rustup.rs -sSf | sh
Windows:
Download and run rustup-init.exe
Setup Discord Bot Profile on Discord Developers
Note: To contribute, you need to create your own Discord Bot profile and test it yourself in another server.
-
Open Discord Developers and click on "Get Started"
-
Create a New Application, with any name you like
-
Navigate to
Boton the left sidebar- Note down the
Token, the code of your bot will require it. - Enable all the Intents
Presence,Server Members,Message Content- This is required by Discord to ensure popular discord bots do not scrape server message contents without permission.
- Note down the
-
Generate a Discord Bot URL:
- Navigate to
OAuth2on the left sidebar - Scroll down to
OAuth2 URL Generator - Under Scopes, select
bot - Scroll down to
Bot Permissions - Select permissions, or later override it in the invite link.
- DSEC Bot's Permission integer is
4235288712703990.
- Copy the Generated URL, and invite your bot to your Discord server.
OR
https://discord.com/oauth2/authorize?client_id=DISCORD_BOT_ID&permissions=4235288712703990&integration_type=0&scope=bot
- Navigate to
Setup Discord Bot on your machine
Rust with Cargo
- Navigate to directory on your machine
git clone https://github.com/liyunze-coding/DSEC-Discord-Bot- Create
.envfile according to.env.example
- You can ask the committee (or Ryan) for the environment variables on Discord.
- Run
cargo run - You may need to reload Discord to see changes to slash commands.
Or Use Docker
- Make sure Docker engine is running.
- On Windows, open Docker Desktop.
- Run the commands
docker-compose build
docker-compose up
Rules
General Rules
- Follow DSEC Server Rules
- Follow Deakin Code of Conduct
- Follow Discord Terms of Services
Programming Rules
- Do not test in Production
- Do not write malicious code (unless you have obtained permission for white hat hacking)
- Do not spam pull requests
- Do not add your own code formatter, affecting the whole files you edit
To-do
- Membership verification command
- Unit information command
Information
What is Rust?
Rust is memory safe yet performant, making it the ideal programming language for systems programming.
C and C++ require developers to manage memory allocation, which can lead to memory unsafe programs.
Python, Java, C# and Go use the garbage collector so that developers don't need to manually manage memory, but can slow down the program significantly due to lack of low level control.
Rust takes a unique approach, by using an "ownership" and "borrowing" system to prevent memory bugs at compile time.
Hence, Rust is performant and memory safe (when you write it well).
Why Rust?
This is a good opportunity for students at Deakin to learn Rust.
At Deakin, Software Engineering, Computer Science and IT students mostly touch on high level languages such as Python, C# and low level languages such as C++.
More and more developer tools are being written in Rust, including Rolldown, Rspack, Tauri, SWC and many more (Ryan is a web developer, he's only aware of these tools written in Rust).
Rust has its own unique concepts and challenges such as the ownership model and the borrow checker. Its strict rules help prevent programming errors such as data races and memory leaks. The strict rules also help students learn how to think about writing efficient code coming from high level languages.