Release Note

v4.5.0

26 September 2026

Improvements Fixes

Improvements

  • This major security release strengthens protection for members, servers, and CLNR bot hosting.
  • /help now links directly to common tasks, including checking your score, managing reminders, and setting up or troubleshooting CLNR.
  • /score now shows the activity window behind the current score and when it was last calculated.
  • Removal screens now surface setup blockers more clearly and explain when a confirmation is no longer valid or needs to be reopened.
  • If setup is interrupted or a confirmation cannot be completed, CLNR now explains how to check what was already saved and continue safely without blindly repeating changes.
  • Bot messages now better prevent accidental pings from names and other incidental text while preserving intended member, staff, warning, and reward notifications.
  • CSV exports now protect formula-like member names, usernames, and role text from being interpreted as spreadsheet formulas.
  • Queued Discord actions recover more reliably after interruptions, with persistent retry and backoff handling that reduces missed or duplicate delivery attempts.
  • Border Challenge collection and missing-country screens now keep sharing controls more compact and use a neutral publish action.
  • Staff Removal Approval now has additional safeguards for sensitive staff-approved removals.
  • Protected staff targets cannot be removed through the workflow: the server owner, Discord Administrators, members with the configured CLNR admin role, removal staff, CLNR itself, the requester, and members with an inactivity-exempt role are blocked. For an intentional removal, admins can first remove the applicable protected role; the server owner remains protected.
  • /removal off acts as an emergency kill switch for the workflow. The server owner, Discord Administrators, and members with the configured CLNR admin role can turn removals off immediately.
  • When removals are off, CLNR blocks new removal requests, destructive approvals, execution of already-open requests, and delegated inactivity-review Confirm actions. Deny and Cancel remain available so staff can still close existing requests safely.
  • Each staff member can record only one destructive approval every 3 minutes across removal requests and delegated inactivity-review confirmations.
  • After the second approval, CLNR applies a 3-minute safety delay before execution. Once the delay ends, the server owner, a Discord Administrator, or a configured CLNR admin must explicitly press Execute.
  • CLNR allows at most 5 staff-approved removals per rolling 15 minutes across both Staff Removal Approval requests and delegated two-person inactivity-review confirmations. Requests remain open when the cap is reached and can continue once the window clears.
  • CLNR rechecks the kill switch, approver authority, target membership, protected roles, required permissions, Discord role hierarchy, and request validity again immediately before execution.
  • Kick and Ban permissions are handled independently: if CLNR has Kick Members but not Ban Members, staff can still create Kick requests while only the unavailable Ban action is disabled.
  • Two-person inactivity removal confirmation now applies to eligible removals even when an admin confirms first, and live reviews show the member name alongside the non-pinging profile mention.

Fixes

  • Clicking a setup confirmation more than once no longer repeats the change, and admins who have lost permission can no longer apply changes from an already-open confirmation screen.
  • Saving removal settings now responds promptly and shows the persisted settings after the save, reducing confusion when multiple admins make changes around the same time.
  • Cleaning up old AHS score images no longer blocks the bot's other work.
  • Welcome-back notices and inactive-role recovery now require a successfully saved activity and Decay Score update first, preventing rejected or stale history-scan updates from triggering false recovery actions.