No description
Find a file
Clupai8o0 959596aff5 SEC-19: harden Discord verification (identical failures, attempt limits, id uniqueness)
Collapse both verification failure paths into one shared verification_failed_embed()
constructor so "not found" and "name mismatch" are byte-identical and can no longer be
used as an oracle for whether a student id holds an Active membership.

Remove the stale in-memory student_cache entirely: it was consulted before the only
query carrying membership_status = "Active", had no TTL and was never evicted, making it
a stale-membership bypass in a long-lived container. fetch_student now runs on every
verification attempt before any role grant.

Add a per-Discord-user failed-attempt counter in AppState
(Mutex<HashMap<UserId, (u32, Instant)>>). After 5 failures in 15 minutes an attempt is
refused with the generic embed and no database round trip. Each failure is logged to the
logs channel with the Discord user id and a timestamp only -- never the submitted name
or student id.

Add an application-level student-id uniqueness check in add_dsec_discord_table: if a
different discord_id already holds the student id, refuse with the generic embed and log
the conflict to the logs channel with both discord ids (not the student id).

The UNIQUE constraint DDL and duplicate sweep on live Supabase are an owner step (see
SECURITY.md); the emailed-OTP possession proof is noted as a follow-up TODO.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017XrE7F9ZuBWdQnS8CZvYDE
2026-08-30 17:10:53 +10:00
.github/workflows Phase 1: bot fixes (BOT-02/03/04/05, COR-03, UXA11Y-11, OPS-04) + Codex hardening (#7) 2026-08-30 16:01:55 +10:00
src SEC-19: harden Discord verification (identical failures, attempt limits, id uniqueness) 2026-08-30 17:10:53 +10:00
.dockerignore SEC-01: pull-request CI on a hosted runner, and stop the deploy leaving DOT_ENV on the VPS (#5) 2026-08-30 15:08:52 +10:00
.env.example Phase 1: bot fixes (BOT-02/03/04/05, COR-03, UXA11Y-11, OPS-04) + Codex hardening (#7) 2026-08-30 16:01:55 +10:00
.gitignore updated gitignore, updated thread title to be leetcode titles 2026-08-10 00:32:15 +10:00
Cargo.lock Phase 1: bot fixes (BOT-02/03/04/05, COR-03, UXA11Y-11, OPS-04) + Codex hardening (#7) 2026-08-30 16:01:55 +10:00
Cargo.toml Phase 1: bot fixes (BOT-02/03/04/05, COR-03, UXA11Y-11, OPS-04) + Codex hardening (#7) 2026-08-30 16:01:55 +10:00
docker-compose.yml Phase 1: bot fixes (BOT-02/03/04/05, COR-03, UXA11Y-11, OPS-04) + Codex hardening (#7) 2026-08-30 16:01:55 +10:00
Dockerfile Phase 1: bot fixes (BOT-02/03/04/05, COR-03, UXA11Y-11, OPS-04) + Codex hardening (#7) 2026-08-30 16:01:55 +10:00
LICENSE updated license 2025-11-22 10:04:16 +11:00
README.md Phase 1: bot fixes (BOT-02/03/04/05, COR-03, UXA11Y-11, OPS-04) + Codex hardening (#7) 2026-08-30 16:01:55 +10:00

DSEC Discord Bot

Deakin Software Engineering Club Discord Bot project. To encourage students to learn Rust and how to work in a practical and collaborative project.

Setup

Setup Rust

Installing Rustup will also install cargo

Linux & MacOS:

curl https://sh.rustup.rs -sSf | sh

Windows:

Download and run rustup-init.exe

Setup Discord Bot Profile on Discord Developers

Note: To contribute, you need to create your own Discord Bot profile and test it yourself in another server.

  1. Open Discord Developers and click on "Get Started"

  2. Create a New Application, with any name you like

  3. Navigate to Bot on the left sidebar

    • Note down the Token, the code of your bot will require it.
    • Enable all the Intents Presence, Server Members, Message Content
      • This is required by Discord to ensure popular discord bots do not scrape server message contents without permission.
  4. Generate a Discord Bot URL:

    1. Navigate to OAuth2 on the left sidebar
    2. Scroll down to OAuth2 URL Generator
    3. Under Scopes, select bot
    4. Scroll down to Bot Permissions
    5. Select permissions, or later override it in the invite link.
    • DSEC Bot's Permission integer is 4235288712703990.
    1. Copy the Generated URL, and invite your bot to your Discord server.

    OR

    1. https://discord.com/oauth2/authorize?client_id=DISCORD_BOT_ID&permissions=4235288712703990&integration_type=0&scope=bot

Setup Discord Bot on your machine

Rust with Cargo

  1. Navigate to directory on your machine
  2. git clone https://github.com/liyunze-coding/DSEC-Discord-Bot
  3. Create .env file according to .env.example
  • You can ask the committee (or Ryan) for the environment variables on Discord.
  1. Run cargo run
  2. You may need to reload Discord to see changes to slash commands.

Or Use Docker

  1. Make sure Docker engine is running.
    • On Windows, open Docker Desktop.
  2. Run the commands
docker-compose build
docker-compose up

Logging

The bot logs at info by default. Do not set RUST_LOG to debug or trace on the VPS or in the DOT_ENV secret: at debug the Supabase client logs the generated query URLs (which contain student IDs) and the service-account email. Adjust the level with RUST_LOG locally only (e.g. RUST_LOG=warn).

Rules

General Rules

  • Follow DSEC Server Rules
  • Follow Deakin Code of Conduct
  • Follow Discord Terms of Services

Programming Rules

  • Do not test in Production
  • Do not write malicious code (unless you have obtained permission for white hat hacking)
  • Do not spam pull requests
  • Do not add your own code formatter, affecting the whole files you edit

To-do

  • Membership verification command
  • Unit information command

Information

What is Rust?

Rust is memory safe yet performant, making it the ideal programming language for systems programming.

C and C++ require developers to manage memory allocation, which can lead to memory unsafe programs.

Python, Java, C# and Go use the garbage collector so that developers don't need to manually manage memory, but can slow down the program significantly due to lack of low level control.

Rust takes a unique approach, by using an "ownership" and "borrowing" system to prevent memory bugs at compile time.

Hence, Rust is performant and memory safe (when you write it well).

Why Rust?

This is a good opportunity for students at Deakin to learn Rust.

At Deakin, Software Engineering, Computer Science and IT students mostly touch on high level languages such as Python, C# and low level languages such as C++.

More and more developer tools are being written in Rust, including Rolldown, Rspack, Tauri, SWC and many more (Ryan is a web developer, he's only aware of these tools written in Rust).

Rust has its own unique concepts and challenges such as the ownership model and the borrow checker. Its strict rules help prevent programming errors such as data races and memory leaks. The strict rules also help students learn how to think about writing efficient code coming from high level languages.

Contributors

Ryan