Improvements
- This major security release strengthens protection for members, servers, and CLNR bot hosting.
-
/helpnow links directly to common tasks, including checking your score, managing reminders, and setting up or troubleshooting CLNR. -
/scorenow shows the activity window behind the current score and when it was last calculated. - Removal screens now surface setup blockers more clearly and explain when a confirmation is no longer valid or needs to be reopened.
- If setup is interrupted or a confirmation cannot be completed, CLNR now explains how to check what was already saved and continue safely without blindly repeating changes.
- Bot messages now better prevent accidental pings from names and other incidental text while preserving intended member, staff, warning, and reward notifications.
- CSV exports now protect formula-like member names, usernames, and role text from being interpreted as spreadsheet formulas.
- Queued Discord actions recover more reliably after interruptions, with persistent retry and backoff handling that reduces missed or duplicate delivery attempts.
- Border Challenge collection and missing-country screens now keep sharing controls more compact and use a neutral publish action.
- Staff Removal Approval now has additional safeguards for sensitive staff-approved removals.
- Protected staff targets cannot be removed through the workflow: the server owner, Discord Administrators, members with the configured CLNR admin role, removal staff, CLNR itself, the requester, and members with an inactivity-exempt role are blocked. For an intentional removal, admins can first remove the applicable protected role; the server owner remains protected.
-
/removal offacts as an emergency kill switch for the workflow. The server owner, Discord Administrators, and members with the configured CLNR admin role can turn removals off immediately. - When removals are off, CLNR blocks new removal requests, destructive approvals, execution of already-open requests, and delegated inactivity-review Confirm actions. Deny and Cancel remain available so staff can still close existing requests safely.
- Each staff member can record only one destructive approval every 3 minutes across removal requests and delegated inactivity-review confirmations.
- After the second approval, CLNR applies a 3-minute safety delay before execution. Once the delay ends, the server owner, a Discord Administrator, or a configured CLNR admin must explicitly press
Execute. - CLNR allows at most 5 staff-approved removals per rolling 15 minutes across both Staff Removal Approval requests and delegated two-person inactivity-review confirmations. Requests remain open when the cap is reached and can continue once the window clears.
- CLNR rechecks the kill switch, approver authority, target membership, protected roles, required permissions, Discord role hierarchy, and request validity again immediately before execution.
- Kick and Ban permissions are handled independently: if CLNR has
Kick Membersbut notBan Members, staff can still create Kick requests while only the unavailable Ban action is disabled. - Two-person inactivity removal confirmation now applies to eligible removals even when an admin confirms first, and live reviews show the member name alongside the non-pinging profile mention.
Fixes
- Clicking a setup confirmation more than once no longer repeats the change, and admins who have lost permission can no longer apply changes from an already-open confirmation screen.
- Saving removal settings now responds promptly and shows the persisted settings after the save, reducing confusion when multiple admins make changes around the same time.
- Cleaning up old AHS score images no longer blocks the bot's other work.
- Welcome-back notices and inactive-role recovery now require a successfully saved activity and Decay Score update first, preventing rejected or stale history-scan updates from triggering false recovery actions.