opers: TokenList -deny exclusion for commands/privs + auspex-gate hidden chans

commands=/privs= now honour a -token removal (e.g. *,-DIE), threaded through
resolve as deny sets and applied in the command gate + has_priv. WHOIS of a
+I (hidechans) user's channel list now needs users/auspex, not any oper.
This commit is contained in:
Jean Chevronnet 2026-08-29 02:36:56 +00:00
parent e2a64b7806
commit 55863e9cfe
No known key found for this signature in database
GPG key ID: 439666D63A9477E4
3 changed files with 67 additions and 25 deletions

View file

@ -91,7 +91,9 @@ oper {
# grant is refused; its modes/snomasks/vhost are applied on oper-up.
#
# A class also grants privileges — named permissions checked at sensitive points.
# "privs=*" grants all. Standard privileges:
# "*" grants all; a "-token" removes one, so "commands=*,-DIE" is everything but DIE and
# "privs=*,-users/auspex" is every privilege but that (works for commands and privs).
# Standard privileges:
# users/auspex real host+IP and geo (WHOIS/WHO + connect notice), +i users
# channels/auspex secret/private (+s/+p) channels in LIST/WHO/WHOIS
# servers/auspex services (U-lined) servers hidden by hideservices