Experimental Discord bot written in Python
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

crosspostcog.py 15KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368
  1. """
  2. Cog for detecting spam messages posted in multiple channels.
  3. """
  4. import re
  5. from datetime import datetime, timedelta, timezone
  6. from typing import Optional
  7. from discord import Member, Message, utils as discordutils, TextChannel
  8. from discord.ext.commands import Cog
  9. from config import CONFIG
  10. from rocketbot.cogs.basecog import BaseCog, BotMessage, BotMessageReaction, CogSetting
  11. from rocketbot.collections import AgeBoundList, AgeBoundDict
  12. from rocketbot.storage import Storage
  13. from rocketbot.utils import str_from_timedelta
  14. class SpamContext:
  15. """
  16. Data about a set of duplicate messages from a user.
  17. """
  18. def __init__(self, member: Member) -> None:
  19. self.member: Member = member
  20. self.age: datetime = datetime.now()
  21. self.bot_message: Optional[BotMessage] = None
  22. self.is_kicked: bool = False
  23. self.is_banned: bool = False
  24. self.is_autobanned: bool = False
  25. self.spam_messages: set[Message] = set()
  26. self.deleted_messages: set[Message] = set()
  27. self.unique_channels: set[TextChannel] = set()
  28. self.duplicate_count: int = 0
  29. class CrossPostCog(BaseCog, name='Crosspost Detection'):
  30. """
  31. Detects a user posting in multiple channels in a short period
  32. of time: a common pattern for spammers.
  33. These used to be identical text, but more recent attacks have had small
  34. variations, such as different imgur URLs. It's reasonable to treat
  35. posting in many channels in a short period as suspicious on its own,
  36. regardless of whether they are identical.
  37. Repeated posts in the same channel aren't currently detected, as this can
  38. often be for a reason or due to trying a failed post when connectivity is
  39. poor. Minimum message length can be enforced for detection.
  40. """
  41. SETTING_ENABLED = CogSetting(
  42. 'enabled',
  43. bool,
  44. default_value=False,
  45. brief='crosspost detection',
  46. description='Whether crosspost detection is enabled.',
  47. )
  48. SETTING_WARN_COUNT = CogSetting(
  49. 'warncount',
  50. int,
  51. default_value=5,
  52. brief='number of messages to trigger a warning',
  53. description='The number of unique channels messages are ' + \
  54. 'posted in by the same user to trigger a mod warning. The ' + \
  55. 'messages need not be identical (see dupewarncount).',
  56. min_value=2,
  57. )
  58. SETTING_DUPE_WARN_COUNT = CogSetting(
  59. 'dupewarncount',
  60. int,
  61. default_value=3,
  62. brief='number of identical messages to trigger a warning',
  63. description='The number of unique channels identical messages are ' + \
  64. 'posted in by the same user to trigger a mod warning.',
  65. min_value=2,
  66. )
  67. SETTING_BAN_COUNT = CogSetting(
  68. 'bancount',
  69. int,
  70. default_value=9999,
  71. brief='number of messages to trigger a ban',
  72. description='The number of unique channels messages are ' + \
  73. 'posted in by the same user to trigger an automatic ban. The ' + \
  74. 'messages need not be identical (see dupebancount). Set ' + \
  75. 'to a large value to effectively disable, e.g. 9999.',
  76. min_value=2,
  77. )
  78. SETTING_DUPE_BAN_COUNT = CogSetting(
  79. 'dupebancount',
  80. int,
  81. default_value=9999,
  82. brief='number of identical messages to trigger a ban',
  83. description='The number of unique channels identical messages are ' + \
  84. 'posted in by the same user to trigger an automatic ban. Set ' + \
  85. 'to a large value to effectively disable, e.g. 9999.',
  86. min_value=2,
  87. )
  88. SETTING_MIN_LENGTH = CogSetting(
  89. 'minlength',
  90. int,
  91. default_value=1,
  92. brief='minimum message length',
  93. description='The minimum number of characters in a message to be ' + \
  94. 'checked for duplicates. This can help ignore common short ' + \
  95. 'messages like "lol" or a single emoji.',
  96. min_value=1,
  97. )
  98. SETTING_TIMESPAN = CogSetting(
  99. 'timespan',
  100. timedelta,
  101. default_value=timedelta(seconds=60),
  102. brief='time window to look for dupe messages',
  103. description='The number of seconds of message history to look at '
  104. 'when looking for duplicates. Shorter values are preferred, '
  105. 'both to detect bots and avoid excessive memory usage.',
  106. min_value=timedelta(seconds=1),
  107. )
  108. STATE_KEY_RECENT_MESSAGES = "CrossPostCog.recent_messages"
  109. STATE_KEY_SPAM_CONTEXT = "CrossPostCog.spam_context"
  110. def __init__(self, bot):
  111. super().__init__(
  112. bot,
  113. config_prefix='crosspost',
  114. short_description='Manages crosspost detection and handling.',
  115. )
  116. self.add_setting(CrossPostCog.SETTING_ENABLED)
  117. self.add_setting(CrossPostCog.SETTING_WARN_COUNT)
  118. self.add_setting(CrossPostCog.SETTING_DUPE_WARN_COUNT)
  119. self.add_setting(CrossPostCog.SETTING_BAN_COUNT)
  120. self.add_setting(CrossPostCog.SETTING_DUPE_BAN_COUNT)
  121. self.add_setting(CrossPostCog.SETTING_MIN_LENGTH)
  122. self.add_setting(CrossPostCog.SETTING_TIMESPAN)
  123. self.max_spam_contexts = 12
  124. async def __record_message(self, message: Message) -> None:
  125. if message.channel.permissions_for(message.author).ban_members:
  126. # User exempt from spam detection
  127. self.__trace("User exempt from crosspost checks")
  128. return
  129. def compute_message_hash(m: Message) -> int:
  130. to_hash = m.content
  131. # URLs sometimes differ per spam message, so simplify them
  132. url_regex = r'http[s]?://(?:[a-zA-Z]|[0-9]|[$-_@.&+]|[!*\(\),]|(?:%[0-9a-fA-F][0-9a-fA-F]))+'
  133. to_hash = re.sub(url_regex, '<url>', to_hash)
  134. # Add attachment metadata
  135. for attachment in m.attachments:
  136. to_hash += f'\n[[ATT: ct={attachment.content_type} s={attachment.size} w={attachment.width} h={attachment.height}]]'
  137. h = hash(to_hash)
  138. self.__trace(f"Message hash for {m.id} is {h}")
  139. return h
  140. min_length = self.get_guild_setting(message.guild, self.SETTING_MIN_LENGTH)
  141. if len(message.attachments) == 0 and len(message.content) < min_length:
  142. # Message too short to count towards spam total
  143. self.__trace(f"Message len {len(message.content)} < {min_length}")
  144. return
  145. # Get config
  146. max_age = timedelta(seconds=self.get_guild_setting(message.guild, self.SETTING_TIMESPAN))
  147. warn_count: int = self.get_guild_setting(message.guild, self.SETTING_WARN_COUNT)
  148. dupe_warn_count: int = self.get_guild_setting(message.guild, self.SETTING_DUPE_WARN_COUNT)
  149. # Record message
  150. recent_messages: AgeBoundList[Message, datetime, timedelta] = Storage.get_state_value(message.guild, self.STATE_KEY_RECENT_MESSAGES)
  151. if recent_messages is None:
  152. recent_messages = AgeBoundList(max_age, lambda index, message : message.created_at)
  153. Storage.set_state_value(message.guild, self.STATE_KEY_RECENT_MESSAGES, recent_messages)
  154. recent_messages.max_age = max_age
  155. recent_messages.append(message)
  156. self.__trace(f"Recent messages now length {len(recent_messages)}")
  157. # Get all recent messages by user
  158. member_messages = [m for m in recent_messages if m.author.id == message.author.id]
  159. message_count = len(member_messages)
  160. self.__trace(f"Found {message_count} messages for {message.author.name}")
  161. if message_count < warn_count and message_count < dupe_warn_count:
  162. self.__trace(f"Bailing because message count {message_count} < warn count {warn_count} and < dupe warn count {dupe_warn_count}")
  163. return
  164. # Look for identical(ish) messages and unique channels
  165. hash_to_channels: dict[int, set[TextChannel]] = {}
  166. unique_channels: set[TextChannel] = set()
  167. max_duplicate_count = 0
  168. for m in member_messages:
  169. message_hash = compute_message_hash(m)
  170. dupe_message_channels: set[TextChannel] = hash_to_channels.get(message_hash)
  171. if dupe_message_channels is None:
  172. dupe_message_channels = set()
  173. hash_to_channels[message_hash] = dupe_message_channels
  174. dupe_message_channels.add(m.channel)
  175. unique_channels.add(m.channel)
  176. max_duplicate_count = max(max_duplicate_count, len(dupe_message_channels))
  177. channel_count = len(unique_channels)
  178. self.__trace(f"Found {len(hash_to_channels)} unique messages, {channel_count} unique channels, {max_duplicate_count} duplicated messages")
  179. if channel_count < warn_count and max_duplicate_count < dupe_warn_count:
  180. self.__trace(f"Bailing because channels {channel_count} < warn count {warn_count} and max dupes {max_duplicate_count} < dupe warn count {dupe_warn_count}")
  181. return
  182. # This person is a problem
  183. spam_lookup: AgeBoundDict[str, SpamContext, datetime, timedelta] = Storage.get_state_value(message.guild, self.STATE_KEY_SPAM_CONTEXT)
  184. if spam_lookup is None:
  185. spam_lookup = AgeBoundDict(
  186. max_age,
  187. lambda key, context : context.age)
  188. Storage.set_state_value(message.guild, self.STATE_KEY_SPAM_CONTEXT, spam_lookup)
  189. key = f'{message.author.id}'
  190. context = spam_lookup.get(key)
  191. if context is not None and message.created_at - context.age > max_age:
  192. context = None
  193. if context is None:
  194. context = SpamContext(message.author)
  195. spam_lookup[key] = context
  196. self.log(message.guild,
  197. f'\u0007{message.author.name} ({message.author.id}) ' + \
  198. f'posted messages in {channel_count} channels.')
  199. context.age = message.created_at
  200. context.duplicate_count = max_duplicate_count
  201. context.spam_messages.update(member_messages)
  202. context.unique_channels.update(unique_channels)
  203. await self.__update_from_context(context)
  204. async def __update_from_context(self, context: SpamContext):
  205. ban_count = self.get_guild_setting(context.member.guild, self.SETTING_BAN_COUNT)
  206. dupe_ban_count = self.get_guild_setting(context.member.guild, self.SETTING_DUPE_BAN_COUNT)
  207. channel_count = len(context.unique_channels)
  208. if channel_count >= ban_count or context.duplicate_count >= dupe_ban_count:
  209. if not context.is_banned:
  210. max_age = timedelta(seconds=self.get_guild_setting(context.member.guild, self.SETTING_TIMESPAN))
  211. max_age_str = str_from_timedelta(max_age)
  212. await context.member.ban(
  213. reason=f'Rocketbot: Posted in {channel_count} channels within {max_age_str} ' + \
  214. f'({context.duplicate_count} identical). Banned by {self.bot.user.name}.',
  215. delete_message_days=1)
  216. context.is_kicked = True
  217. context.is_banned = True
  218. context.is_autobanned = True
  219. context.deleted_messages |= context.spam_messages
  220. self.__log_ban(context, self.bot.user.name)
  221. else:
  222. # Already banned. Nothing to update in the message.
  223. return
  224. await self.__update_message_from_context(context)
  225. async def __update_message_from_context(self, context: SpamContext) -> None:
  226. first_spam_message: Message = sorted(list(context.spam_messages), key=lambda m: m.created_at)[0]
  227. spam_count = len(context.spam_messages)
  228. channel_count = len(context.unique_channels)
  229. deleted_count = len(context.deleted_messages)
  230. duplicate_count = context.duplicate_count
  231. max_age = timedelta(seconds=self.get_guild_setting(context.member.guild, self.SETTING_TIMESPAN))
  232. max_age_str = str_from_timedelta(max_age)
  233. message = context.bot_message
  234. if message is None:
  235. message_type: int = BotMessage.TYPE_INFO if self.was_warned_recently(context.member) \
  236. else BotMessage.TYPE_MOD_WARNING
  237. message = BotMessage(context.member.guild, '', message_type, context)
  238. message.quote = discordutils.remove_markdown(first_spam_message.clean_content)
  239. self.record_warning(context.member)
  240. if context.is_autobanned:
  241. text = f'User {context.member.mention} auto banned for ' + \
  242. f'posting messages in {channel_count} channels within {max_age_str} ' + \
  243. f'({duplicate_count} identical). Messages from past 24 hours deleted.'
  244. await message.set_reactions([])
  245. await message.set_text(text)
  246. else:
  247. body: str = f'User {context.member.mention} posted '
  248. if duplicate_count == channel_count:
  249. body += f'identical messages in {channel_count} channels within {max_age_str} .'
  250. elif duplicate_count == 1:
  251. body += f'**different** messages in {channel_count} channels within ' + \
  252. f'{max_age_str}. (Showing first one).'
  253. else:
  254. body += f'messages in {channel_count} channels within {max_age_str} ' + \
  255. f'({duplicate_count} are identical, showing first one).'
  256. max_links = 10
  257. for msg in sorted(list(context.spam_messages), key=lambda m: m.created_at)[:max_links]:
  258. body += f'\n- {msg.jump_url}'
  259. if len(context.spam_messages) > max_links:
  260. body += f'\n- ...{len(context.spam_messages) - max_links} more...'
  261. await message.set_text(body)
  262. await message.set_reactions(BotMessageReaction.standard_set(
  263. did_delete = deleted_count >= spam_count,
  264. message_count = spam_count,
  265. did_kick = context.is_kicked,
  266. did_ban = context.is_banned))
  267. if context.bot_message is None:
  268. await self.post_message(message)
  269. context.bot_message = message
  270. async def on_mod_react(self,
  271. bot_message: BotMessage,
  272. reaction: BotMessageReaction,
  273. reacted_by: Member) -> None:
  274. context: SpamContext = bot_message.context
  275. if context is None:
  276. return
  277. channel_count = len(context.unique_channels)
  278. if reaction.emoji == CONFIG['trash_emoji']:
  279. for message in context.spam_messages - context.deleted_messages:
  280. await message.delete()
  281. context.deleted_messages.add(message)
  282. await self.__update_from_context(context)
  283. self.__log_deletion(context, reacted_by.name)
  284. elif reaction.emoji == CONFIG['kick_emoji']:
  285. await context.member.kick(
  286. reason=f'Rocketbot: Posted messages in {channel_count} ' + \
  287. f'channels. Kicked by {reacted_by.name}.')
  288. context.is_kicked = True
  289. await self.__update_from_context(context)
  290. self.__log_kick(context, reacted_by.name)
  291. elif reaction.emoji == CONFIG['ban_emoji']:
  292. await context.member.ban(
  293. reason=f'Rocketbot: Posted messages in {channel_count} ' + \
  294. f'channels. Banned by {reacted_by.name}.',
  295. delete_message_days=1)
  296. context.deleted_messages |= context.spam_messages
  297. context.is_kicked = True
  298. context.is_banned = True
  299. await self.__update_from_context(context)
  300. self.__log_ban(context, reacted_by.name)
  301. def __log_deletion(self, context: SpamContext, by_who: str) -> None:
  302. max_age = timedelta(seconds=self.get_guild_setting(context.member.guild, self.SETTING_TIMESPAN))
  303. max_age_str = str_from_timedelta(max_age)
  304. channel_count = len(context.unique_channels)
  305. duplicate_count = context.duplicate_count
  306. self.log(context.member.guild,
  307. f'{context.member.name} ({context.member.id}) posted ' + \
  308. f'messages in {channel_count} channels withint {max_age_str} ' + \
  309. f'({duplicate_count} identical). Deleted by {by_who}.')
  310. def __log_kick(self, context: SpamContext, by_who: str) -> None:
  311. max_age = timedelta(seconds=self.get_guild_setting(context.member.guild, self.SETTING_TIMESPAN))
  312. max_age_str = str_from_timedelta(max_age)
  313. channel_count = len(context.unique_channels)
  314. duplicate_count = context.duplicate_count
  315. self.log(context.member.guild,
  316. f'{context.member.name} ({context.member.id}) posted ' + \
  317. f'messages in {channel_count} channels within {max_age_str} ' + \
  318. f'({duplicate_count} identical). Kicked by {by_who}.')
  319. def __log_ban(self, context: SpamContext, by_who: str) -> None:
  320. max_age = timedelta(seconds=self.get_guild_setting(context.member.guild, self.SETTING_TIMESPAN))
  321. max_age_str = str_from_timedelta(max_age)
  322. channel_count = len(context.unique_channels)
  323. duplicate_count = context.duplicate_count
  324. self.log(context.member.guild,
  325. f'{context.member.name} ({context.member.id}) posted ' + \
  326. f'messages in {channel_count} channels within {max_age_str} ' + \
  327. f'({duplicate_count} identical). Banned by {by_who}.')
  328. def __trace(self, message):
  329. # print(message)
  330. pass
  331. @Cog.listener()
  332. async def on_message(self, message: Message):
  333. """Event handler"""
  334. if message.author is None or \
  335. message.author.bot or \
  336. message.channel is None or \
  337. message.guild is None:
  338. return
  339. if not self.get_guild_setting(message.guild, self.SETTING_ENABLED):
  340. return
  341. self.__trace("--ON MESSAGE--")
  342. await self.__record_message(message)