agentscope-ai / agentscope-ai/agentscope

feat(channel): add platform-agnostic inbound access control

Aperta
#2,621 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub
Lingua principale
Python
Stelle
31.6k
Fork
3.5k
Merge medio
1g 16h
PR unite (30g)
103

Descrizione

## Background

PR #2271 highlighted that publicly reachable channel bots can route messages from unknown users or groups into agent sessions. Telegram-specific allowlists were removed from that PR because access control should be consistent across channel implementations.

## Proposal

Add a platform-agnostic inbound access policy in the channel routing layer. The policy should be evaluated before session routing, media download, buffering, or event emission. It should support private-user and group/chat restrictions without adding platform-specific fields to individual channel configs.

## Acceptance criteria

- one shared policy model applies to all channel types
- public access is explicit and visible in configuration
- rejected events do not create sessions or download attachments
- private chats and group chats can be governed independently
- existing channel configurations have a documented compatibility path

Follow-up from #2271.

Guida per i contributori

Apri la guida per i contributori

Direzione di ricerca

Start by reviewing PR #2271 and the channel routing layer described in this issue, then trace how channel configuration, session routing, media downloads, buffering, and event emission currently connect. Define the shared policy and compatibility path across channel types, and verify that configuration makes public access explicit while rejected private and group events stop before downstream processing.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
python
Ambito
backend, security
Tipo di issue
Funzionalità
Difficoltà
5/5
Tempo stimato
Più di una settimana
Stato di attività
Attiva
Chiarezza
Abbastanza chiara
Idoneità per principianti
38/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.