diff --git a/fluxer_api/src/api/infrastructure/AvatarService.ts b/fluxer_api/src/api/infrastructure/AvatarService.ts index b6ffd1326..619b6699e 100644 --- a/fluxer_api/src/api/infrastructure/AvatarService.ts +++ b/fluxer_api/src/api/infrastructure/AvatarService.ts @@ -108,7 +108,7 @@ export class AvatarService { type: 'base64', base64: base64Data, version: 2, - nsfw: 'block', + nsfw: 'allow', }), kind, errorPath, @@ -163,7 +163,7 @@ export class AvatarService { type: 'base64', base64: base64Data, version: 2, - nsfw: 'block', + nsfw: 'allow', }), kind: 'avatar', errorPath, diff --git a/fluxer_api/src/api/infrastructure/EntityAssetService.ts b/fluxer_api/src/api/infrastructure/EntityAssetService.ts index bcb77a6b8..305d81f4c 100644 --- a/fluxer_api/src/api/infrastructure/EntityAssetService.ts +++ b/fluxer_api/src/api/infrastructure/EntityAssetService.ts @@ -403,7 +403,7 @@ export class EntityAssetService { type: 'base64', base64: base64Data, version: 2, - nsfw: 'block', + nsfw: 'allow', }), kind, errorPath, diff --git a/fluxer_api/src/api/webhook/WebhookService.ts b/fluxer_api/src/api/webhook/WebhookService.ts index 82109db3b..306c66aca 100644 --- a/fluxer_api/src/api/webhook/WebhookService.ts +++ b/fluxer_api/src/api/webhook/WebhookService.ts @@ -586,7 +586,7 @@ export class WebhookService { type: 'external', url: avatarUrl, with_base64: true, - nsfw: 'block', + nsfw: 'allow', }); if (!metadata?.base64) { await this.cacheService.set(cacheKey, WEBHOOK_AVATAR_MISSING_CACHE_VALUE, seconds('5 minutes')); diff --git a/fluxer_docs/scripts/VerifyDocsStyle.ts b/fluxer_docs/scripts/VerifyDocsStyle.ts index 349663d91..5a34f0bfb 100644 --- a/fluxer_docs/scripts/VerifyDocsStyle.ts +++ b/fluxer_docs/scripts/VerifyDocsStyle.ts @@ -344,7 +344,7 @@ const ACCEPTED_TABLE_FINDINGS = new Map1 | [error response](/http-api/#error-response) | Body, image, template, bot or unclaimed credential, configured guild limit, or single community policy rejects creation | | 4032 | [error response](/http-api/#error-response) | Email address is unverified, or the name is blocked | -1 The [error code](/http-api/errors/) is `SINGLE_COMMUNITY_CANNOT_CREATE_GUILDS` while the single community policy is active, `BOTS_CANNOT_CREATE_GUILDS` for a bot credential, `UNCLAIMED_ACCOUNT_CANNOT_CREATE_GUILDS` for an unclaimed account, `MAX_GUILDS` at the configured guild limit, `GUILD_TEMPLATE_INVALID` for a rejected template, `EXPLICIT_CONTENT_CANNOT_BE_SENT` for an explicit icon, and `INVALID_FORM_BODY` otherwise +1 The [error code](/http-api/errors/) is `SINGLE_COMMUNITY_CANNOT_CREATE_GUILDS` while the single community policy is active, `BOTS_CANNOT_CREATE_GUILDS` for a bot credential, `UNCLAIMED_ACCOUNT_CANNOT_CREATE_GUILDS` for an unclaimed account, `MAX_GUILDS` at the configured guild limit, `GUILD_TEMPLATE_INVALID` for a rejected template, and `INVALID_FORM_BODY` otherwise 2 The [error code](/http-api/errors/) is `GUILD_CREATION_EMAIL_VERIFICATION_REQUIRED` for an unverified email address and `CONTENT_BLOCKED` for a blocked name or body string @@ -652,7 +652,7 @@ Every field is optional. An omitted field preserves its current value, and a fie 1 The value is normalised and trimmed before its length is measured, and the normalised name is scanned against the instance phrase and URL blocklists, so a match returns 403 `CONTENT_BLOCKED` -2 The accepted encoding, byte ceiling, and format set are the ones listed by [Create guild](#create-guild), and an image the media classifier marks as explicit is rejected with 400 `EXPLICIT_CONTENT_CANNOT_BE_SENT`. No guild feature gates an animated icon on write, but the `a_` prefix is stripped from the returned hash while the guild lacks `ANIMATED_ICON` +2 The accepted encoding, byte ceiling, and format set are the ones listed by [Create guild](#create-guild). No guild feature gates an animated icon on write, but the `a_` prefix is stripped from the returned hash while the guild lacks `ANIMATED_ICON` 3 The channel must exist in this guild and be a text channel, and is otherwise rejected with `SYSTEM_CHANNEL_MUST_BE_IN_GUILD` or `SYSTEM_CHANNEL_MUST_BE_TEXT` @@ -694,7 +694,7 @@ Send the current array with the intended changes applied. A feature without the | 4032 | [error response](/http-api/#error-response) | Guild is unavailable, the name is blocked, `MANAGE_GUILD` or ownership is absent, or sudo mode is required | | 4043 | [error response](/http-api/#error-response) | Guild does not exist | -1 The [error code](/http-api/errors/) is `TWO_FACTOR_REQUIRED` for a caller who holds `MANAGE_GUILD` but cannot exercise it, `EXPLICIT_CONTENT_CANNOT_BE_SENT` for an explicit image, and `INVALID_FORM_BODY` otherwise +1 The [error code](/http-api/errors/) is `TWO_FACTOR_REQUIRED` for a caller who holds `MANAGE_GUILD` but cannot exercise it, and `INVALID_FORM_BODY` otherwise 2 The [error code](/http-api/errors/) is `MISSING_ACCESS` for an unavailable guild, `CONTENT_BLOCKED` for a blocked name or body string, `SUDO_MODE_REQUIRED` when an MFA level change is unproven, and `MISSING_PERMISSIONS` for a non-member, a missing `MANAGE_GUILD`, or a non-owner changing the MFA level diff --git a/fluxer_docs/src/content/docs/http-api/users/current-user.mdx b/fluxer_docs/src/content/docs/http-api/users/current-user.mdx index a43e4c269..d2a160d81 100644 --- a/fluxer_docs/src/content/docs/http-api/users/current-user.mdx +++ b/fluxer_docs/src/content/docs/http-api/users/current-user.mdx @@ -139,7 +139,7 @@ An account is unclaimed while it holds no password credential, is not a bot, and Decoded avatar and banner content stays within the resolved `avatar_max_size` limit, which defaults to 10485760 bytes, and a larger payload is rejected with `IMAGE_SIZE_EXCEEDS_LIMIT`. Accepted formats are PNG, JPEG, WebP, GIF, APNG, AVIF, HEIC, HEIF, JPEG XL, and SVG. Anything else, animated AVIF included, is rejected with `INVALID_IMAGE_FORMAT`, and so is content the Media Proxy cannot identify. -Content the explicit media classifier marks is rejected with 400 [`EXPLICIT_CONTENT_CANNOT_BE_SENT`](/http-api/errors/), whose body has the classifier score in a top-level `probability` member. An animated avatar requires the animated avatar entitlement and is otherwise rejected with `ANIMATED_AVATARS_REQUIRE_PREMIUM`. A successfully decoded avatar or non-null banner derives its dominant colour and returns it later as `avatar_color` or `banner_color`. +An animated avatar requires the animated avatar entitlement and is otherwise rejected with `ANIMATED_AVATARS_REQUIRE_PREMIUM`. A successfully decoded avatar or non-null banner derives its dominant colour and returns it later as `avatar_color` or `banner_color`. ### Content blocklists @@ -175,7 +175,7 @@ Supplying `new_password` on a claimed account deletes every other authentication | Status | Body | Condition | | --- | --- | --- | | 200 | [user](/http-api/users/#user-object) object | Account was returned after applying every permitted field | -| 400 | [error response](/http-api/#error-response) | Body, image, tag, password, entitlement, secondary control, or sudo proof is invalid, or the image returns `EXPLICIT_CONTENT_CANNOT_BE_SENT` | +| 400 | [error response](/http-api/#error-response) | Body, image, tag, password, entitlement, secondary control, or sudo proof is invalid | | 403 | [error response](/http-api/#error-response) | Email verification, sudo verification, or a staff-only field is required, or content is blocked | ### Side effects diff --git a/fluxer_docs/src/content/docs/http-api/webhooks.mdx b/fluxer_docs/src/content/docs/http-api/webhooks.mdx index 7b0bab990..e8a8f2912 100644 --- a/fluxer_docs/src/content/docs/http-api/webhooks.mdx +++ b/fluxer_docs/src/content/docs/http-api/webhooks.mdx @@ -829,8 +829,7 @@ The decoded bytes must be at most the resolved [avatar_max_size](/http-api/insta | --- | --- | --- | | 200 | [webhook](#webhook-object) object | Webhook was created | | 4001 | [error response](/http-api/#error-response) | Body or avatar is invalid | -| 4002 | [error response](/http-api/#error-response) | The avatar is blocked as explicit media | -| 4003 | [error response](/http-api/#error-response) | The guild or channel webhook allowance is already reached | +| 4002 | [error response](/http-api/#error-response) | The guild or channel webhook allowance is already reached | | 400 | [error response](/http-api/#error-response) | The caller holds `MANAGE_WEBHOOKS` without an enrolled authenticator in an elevated-MFA guild | | 403 | [error response](/http-api/#error-response) | Credential is a bearer token | | 403 | [error response](/http-api/#error-response) | The account has an outstanding required action | @@ -845,15 +844,12 @@ The decoded bytes must be at most the resolved [avatar_max_size](/http-api/insta 1 An avatar failure names the `avatar` path with `BASE64_LENGTH_INVALID`, `INVALID_BASE64_FORMAT`, `IMAGE_SIZE_EXCEEDS_LIMIT`, or `INVALID_IMAGE_FORMAT` -2 The classifier block has its score in `probability` - -3 The reached allowance is in a top-level member named after its limit key +2 The reached allowance is in a top-level member named after its limit key | Condition | Error | | --- | --- | | Guild or channel webhook allowance reached | 400 `MAX_WEBHOOKS_PER_GUILD` or 400 `MAX_WEBHOOKS_PER_CHANNEL` | | Caller holds the permission but has no enrolled authenticator | 400 `TWO_FACTOR_REQUIRED` | -| Explicit media classifier blocks the avatar | 400 `EXPLICIT_CONTENT_CANNOT_BE_SENT` | | Schema or image failure | 400 `INVALID_FORM_BODY` | | Name is blocked, or the avatar hash is banned | 403 `CONTENT_BLOCKED` | | Account has an outstanding required action | 403 `ACCOUNT_SUSPICIOUS_ACTIVITY` | @@ -946,7 +942,6 @@ The returned webhook object has the destination channel. | --- | --- | --- | | 200 | [webhook](#webhook-object) object | Webhook was updated | | 400 | [error response](/http-api/#error-response) | Body or avatar is invalid | -| 400 | [error response](/http-api/#error-response) | The avatar is blocked as explicit media | | 4001 | [error response](/http-api/#error-response) | The destination channel already holds its maximum webhooks | | 400 | [error response](/http-api/#error-response) | The caller holds `MANAGE_WEBHOOKS` without an enrolled authenticator in an elevated-MFA guild | | 403 | [error response](/http-api/#error-response) | Credential is a bearer token | @@ -969,7 +964,6 @@ The returned webhook object has the destination channel. | --- | --- | | Destination channel already holds its maximum webhooks | 400 `MAX_WEBHOOKS_PER_CHANNEL` | | Caller holds the permission but has no enrolled authenticator | 400 `TWO_FACTOR_REQUIRED` | -| Explicit media classifier blocks the avatar | 400 `EXPLICIT_CONTENT_CANNOT_BE_SENT` | | Schema or image failure | 400 `INVALID_FORM_BODY` | | Name is blocked, or the avatar hash is banned | 403 `CONTENT_BLOCKED` | | Account has an outstanding required action | 403 `ACCOUNT_SUSPICIOUS_ACTIVITY` | @@ -1094,7 +1088,6 @@ Unlike [update webhook](#update-webhook), this body rejects any field it does no | 200 | [token webhook](#token-webhook-object) object | Webhook was updated | | 400 | [error response](/http-api/#error-response) | Path, body, or avatar is invalid | | 400 | [error response](/http-api/#error-response) | The body has an unknown field | -| 400 | [error response](/http-api/#error-response) | The avatar is blocked as explicit media, returning `EXPLICIT_CONTENT_CANNOT_BE_SENT` | | 403 | [error response](/http-api/#error-response) | Name is blocked or the avatar hash is banned, each returning `CONTENT_BLOCKED` | | 404 | [error response](/http-api/#error-response) | Webhook and token pair does not exist, returning `UNKNOWN_WEBHOOK` | @@ -1220,7 +1213,7 @@ An attachment metadata entry whose `id` matches a supplied file index supplies t The operation creates one webhook-authored message, attaches direct multipart files, and resolves forward snapshots and mentions under the allowed mentions policy. -A supplied `username` replaces the author name on this message. A supplied `avatar_url` is fetched for this message, and the webhook's stored name and avatar do not change. When the avatar cannot be fetched, or the explicit media classifier blocks it, Fluxer creates the message without the override. +A supplied `username` replaces the author name on this message. A supplied `avatar_url` is fetched for this message, and the webhook's stored name and avatar do not change. When the avatar cannot be fetched, Fluxer creates the message without the override. The operation updates channel state and search results and emits [Message Create](/gateway/events/#message-create) to sessions that can read the channel. @@ -1454,7 +1447,7 @@ The success body is the literal string `ok` under the `text/html` content type. The converted callback creates one webhook-authored message with the converted content and embeds, and emits [Message Create](/gateway/events/#message-create) to sessions that can read the channel. -A supplied username replaces the author name on that message. A supplied `icon_url` that parses as an absolute URL is fetched through the media boundary and stored as the message avatar, and the stored webhook name and avatar do not change. When the URL cannot be fetched, or the explicit media classifier blocks the image, the callback still succeeds and the message has no avatar override. +A supplied username replaces the author name on that message. A supplied `icon_url` that parses as an absolute URL is fetched through the media boundary and stored as the message avatar, and the stored webhook name and avatar do not change. When the URL cannot be fetched, the callback still succeeds and the message has no avatar override. The webhook execution default applies, and every mention in the converted content is suppressed. The callback has no nonce, so a repeated callback creates a second message.