refactor(security): remove unused empty allowlist mode

This commit is contained in:
Peter Steinberger
2026-02-21 19:57:36 +01:00
parent 2ba6de7eaa
commit 51c0893673
2 changed files with 1 additions and 16 deletions

View File

@@ -21,15 +21,12 @@ export function isAllowedParsedChatSender<TParsed extends ParsedChatAllowTarget>
chatId?: number | null;
chatGuid?: string | null;
chatIdentifier?: string | null;
emptyAllowFrom?: "deny" | "allow";
normalizeSender: (sender: string) => string;
parseAllowTarget: (entry: string) => TParsed;
}): boolean {
const allowFrom = params.allowFrom.map((entry) => String(entry).trim());
if (allowFrom.length === 0) {
// Fail closed by default. Callers can opt into legacy "empty = allow all"
// behavior explicitly when a surface intentionally treats an empty list as open.
return params.emptyAllowFrom === "allow";
return false;
}
if (allowFrom.includes("*")) {
return true;