Announcement crossposts
Do not add a crosspost shortcut that bypasses the dedicated capability gate, exact direct announcement-channel allowlist, confirmed Message Content intent, verified application and bot identities, exact message ID, complete content-bearing message evidence, known default message type, poll absence, non-forwarded reference, complete role and overwrite evidence, VIEW_CHANNEL, READ_MESSAGE_HISTORY, SEND_MESSAGES, authorship-sensitive MANAGE_MESSAGES, a process-keyed content-bound plan, signed interactive confirmation, write approval, final fresh-plan match, atomic one-shot key reservation, pending activity journaling, one non-retried POST, strict response validation, or exact fresh readback. If a client cannot support MCP elicitation, keep crossposting unavailable in that client.
Keep the target surface to direct GUILD_ANNOUNCEMENT channels. Do not accept threads, text channels, polls, forwarded messages, system message types, fuzzy message selection, batches, follower management, or destination selection. An already-crossposted message is a record-free no-op. Expose that Discord does not provide the follower count or destination channels to this operation, so review cannot enumerate or constrain fanout and the connector has no rollback endpoint.
Bind the exact application, bot, guild, connector membership, relevant roles, channel overwrites, effective permissions, authorship class, Message Content intent, full review-relevant message snapshot, flags, and operation-key hash into the opaque keyed digest. Never persist or export message content or unkeyed content hashes, attachment metadata or URLs, embeds, components, profiles, names, follower data, raw operation keys, raw responses, or transport causes. Activity and operation records may contain only exact guild, channel, and message IDs, plan digest, operation-key hash, timestamps, fixed verification and outcome values, activity ID, and sanitized error category.
Accept success only when the POST response and a fresh exact GET preserve the message identity, author, content, attachments, embeds, components, reference, timestamps, type, and unrelated flags, with the CROSSPOSTED bit as the only transition. Treat a known pre-response Discord 4xx as failed. Treat transport errors, Discord 5xx responses, malformed or mismatched responses, failed or drifting readback, and every other indeterminate outcome as uncertain. Never automatically retry, compensate, or claim fanout delivery.
Serialize the same exact channel and message across operation keys inside one process as defense in depth. The production facade also acquires durable exact channel-and-message claims across connector processes sharing the activity-state root. Retain those claims after uncertainty until credential-free exact operator review resolves the receipt; never use leases or elapsed time to infer safety.
Canonical source: SECURITY.md
Documentation generated for guildcontrol@0.0.0. Canonical source and edit history remain in the public repository. GuildControl is an independent project and is not affiliated with or endorsed by Discord Inc. Discord is used only to identify the platform that GuildControl connects to.