Skip to content

Authenticated bot profile

Keep current-bot profile reads behind their own audit gate and the bot-profile toolset. Resolve the target only from the configured and freshly verified current application and bot identities. Accept no caller-selected application or bot ID, guild or channel scope, guild permission, privileged intent, Gateway requirement, generic User object, or raw response. Return only exact IDs, transient untrusted username, avatar and banner presence plus animation state, and bounded unknown-field counts. Never return media hashes, email, locale, flags, decorations, collectibles, or unknown values, and never persist profile text or media state.

Keep changes behind the independent bot-profile change gate, application-wide acknowledgement, process-keyed fresh planning, signed interactive confirmation, host write approval, final fresh remote-and-file match, durable application-wide coordination, atomic one-shot reservation, pending content-free activity, one non-retried sparse current-user PATCH, strict response validation, and independent exact editable-state readback. Accept only the bounded safe username contract and explicit avatar or banner set and clear variants. Never add a generic user or application editor, caller-supplied JSON body, audit reason, immediate mutation path, arbitrary field, or automatic retry, compensation, restore, or rollback.

Image replacement must accept only one bounded canonical process-owned regular single-link JPEG, PNG, or GIF file contained by a dedicated configured root. Reject URLs, CDN references, data URIs, base64 input, arbitrary bytes, relative paths, symlinks, hardlinks, foreign ownership, unstable reads, malformed structures, unsupported formats, and oversized files before reservation. Bind canonical file identity, stable bytes, decoded metadata, and a domain-separated keyed content digest into the plan, then encode the reviewed snapshot internally for Discord. A missing root must leave username changes and image clearance usable while blocking replacement. Never claim remote byte equality because Discord exposes only transformed media hashes after upload.

Require exact requested username and clearance state plus unchanged unrequested fields in both mutation response and fresh readback. For replacement images, require reviewed presence and animation state and exact agreement between the two returned editable profiles. A matching username and clearance of absent media are record-free no-ops; replacement remains a real write because byte equality is unobservable. A known pre-response Discord client refusal may fail. Transport ambiguity, server error, malformed or mismatched evidence, unreadable readback, or failed receipt finalization is uncertain, permanently spends the key, retains the application claim, and blocks same-application profile changes for operator review.

Activity and operation records may contain only exact application and bot IDs, three changed-field booleans, plan and operation-key digests, timestamps, fixed status and verification values, activity ID, and sanitized error category. Never persist username, review reason, local path, file metadata, image dimensions, media or content hash, image bytes, raw operation key, raw request or response, credential, or transport cause.

Canonical source: SECURITY.md

Documentation generated for guildcontrol@0.0.0. Canonical source and edit history remain in the public repository. GuildControl is an independent project and is not affiliated with or endorsed by Discord Inc. Discord is used only to identify the platform that GuildControl connects to.