Skip to content

Conversation

@DicksonWu654
Copy link
Collaborator

@DicksonWu654 DicksonWu654 commented Dec 17, 2025

Frameworks PR Checklist

Integrating w3os discord guide into frameworks

This is from #305. @NFTDreww suggested we merge discord first into frameworks, then work on the other ones. This has alreayd been approved by NFT Drew

  • Describe your changes, substitute this text with the information
  • If you are touching an existing piece of content, tag current contributors from the attribution list
  • If there is a steward for that framework, ask the steward to review it
  • If you're modifying the general outline, make sure to update it in the vocs.config.ts adding the dev: true parameter
  • If you need feedback for your content from the wider community, share the PR in our Discord
  • Review changes to ensure there are no typos, see instructions below

…utor details

- Enhanced the Discord management documentation with a new summary section outlining key security measures.
- Introduced a comprehensive account security checklist for individuals and team members.
- Updated contributor information to include Auditware, reflecting their role and contributions.
- Streamlined content for clarity and improved organization of security measures and guidelines.
@vercel
Copy link

vercel bot commented Dec 17, 2025

@DicksonWu654 is attempting to deploy a commit to the Security Alliance Team on Vercel.

A member of the Team first needs to authorize it.

@vercel
Copy link

vercel bot commented Dec 17, 2025

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Review Updated (UTC)
frameworks Ready Ready Preview, Comment Jan 27, 2026 3:11pm

Request Review

@scode2277 scode2277 added the content:add This issue or PR adds content or suggests to label Dec 17, 2025
@mattaereal mattaereal requested a review from NFTDreww December 17, 2025 23:00
- Updated all checklist items to use proper User Settings paths
- Added instructions for removing phone number and saving backup codes
- Changed Privacy & Safety to Content & Social paths
- Updated DM filtering to use "Filter all" option

Co-authored-by: NFTDreww
- Removed Content Filter section (no longer in Discord)
- Removed "CAPTCHA all accounts" option
- Removed Timeout section (moved to different location)
- Removed Permissions section (now part of community setup flow)
- Removed Membership Screening section (separate flow for age-restricted servers)

Co-authored-by: NFTDreww
- Changed path from "Server Settings > AutoMod" to "Server Settings > Safety Setup > AutoMod"
- Removed deprecated "Explicit image filter" line
- Added recommendation to create private channel for AutoMod logs

Co-authored-by: NFTDreww
- Changed from "Server Settings > Overview" to "Server Settings > Engagement > Default Notification Settings"
- Updated terminology from "Mentions Only" to "Only @mentions"

Co-authored-by: NFTDreww
- Clarified that minimal bots actually need Admin permissions
- Encouraged users to review actual bot permission needs instead of defaulting to Admin
- Updated integration command permissions path to correct location
- Removed non-existent "Allow new integrations" setting

Co-authored-by: NFTDreww
- Removed outdated invite permissions setting from Invites section
- Updated Privacy Settings to use current "Direct Messages" toggle wording

Co-authored-by: NFTDreww
- Removed Manage Channels and Manage Roles from Moderators (too privileged)
- Added appropriate Moderator permissions: View Audit Log, View Server Insights, Kick/Ban/Timeout, messaging, and moderation
- Simplified Members permissions to basic viewing and messaging only
- Removed dangerous permissions like Ban/Kick/Timeout and Manage Messages from Members

Co-authored-by: NFTDreww
- Removed less secure "react to message" suggestion
- Updated Wick bot recommendation to emphasize in-channel captcha verification

Co-authored-by: NFTDreww
- Removed MEE6 link from Logging Setup section
- Removed MEE6 link from Additional Recommendations section
- MEE6 has had multiple security incidents and is not recommended

Co-authored-by: NFTDreww
- Updated Anti-Impersonation Bots section to recommend Hashbot instead of Wick Bot
- Added link to hashbot.com

Co-authored-by: NFTDreww
- Removed Security subsection with QR scan options that Discord no longer has
- Discord has removed this setting from Privacy & Safety

Co-authored-by: NFTDreww
- Added back "CAPTCHA all accounts before they are able to join during a suspected raid" option
- This setting was incorrectly removed; it should be updated, not deleted

Co-authored-by: NFTDreww
- Restructured Integration section to properly group items under the
  "Manage Bot/App > Roles & Members / Channels" path
- This path applies to permission removal, uninstalling, verification,
  and command restriction - not just the last item

Co-authored-by: NFTDreww
- Updated the command permissions restriction note to include the specific path: Manage > Roles & Members / Channels / Command Overrides
- This addition enhances clarity for server administrators on where to manage integration permissions effectively.
- Added explanation of what Cold Admin is and why it's important
- Added Cold Device definition and requirements
- Added detailed step-by-step setup instructions:
  - Creating dedicated email account with 2FA
  - Creating Discord account with proper settings
  - Joining server and transferring ownership safely
- Added usage guidelines and monthly maintenance reminder
- Added critical warning about ownership transfer verification

Co-authored-by: NFTDreww
DicksonWu654 and others added 2 commits January 11, 2026 16:35
- Introduced a new "Guides" section in the sidebar for better navigation
- Added detailed guides for "Community Management" and "Discord Security"
- Updated community management index to link to the new guides
- Removed outdated Discord security link from the community management page
@scode2277
Copy link
Collaborator

@mattaereal this is waiting for your approval on the structure

@mattaereal
Copy link
Collaborator

A few things:

  1. Guides should have their own section, not live along with other domains; it's confusing. I suggest moving Guides alongside Frameworks and Certifications, under Frameworks.
  2. I don't fully understand why only a few have been moved, what defines a guide to be suitable to this new section?
  3. The overviews and vocs.config.ts should be updated accordingly afterward; there are broken links

DicksonWu654 and others added 2 commits January 26, 2026 23:30
- Added a new "Discord" link under the community management section for improved navigation.
- Reorganized the "Guides" section to include a dedicated entry for "Discord Security" with updated links.
- Removed outdated "Discord Security" guide from the community management folder and replaced it with a new link structure.
- Streamlined the overall guides for better clarity and accessibility.
@DicksonWu654
Copy link
Collaborator Author

A few things:

  1. Guides should have their own section, not live along with other domains; it's confusing. I suggest moving Guides alongside Frameworks and Certifications, under Frameworks.
  2. I don't fully understand why only a few have been moved, what defines a guide to be suitable to this new section?
  3. The overviews and vocs.config.ts should be updated accordingly afterward; there are broken links
  1. Moved!
  2. Ah I wanted to create a separate PR for just discord so we an easily talk about how things should be moved. The other content will be moved inside of Implementing W3OSC's account configuration guides into Frameworks #305 after this one is merged / will be merged at the same time if this looks good!
  3. I think it's all fixed now?

@DicksonWu654
Copy link
Collaborator Author

If this looks good Matta we could merge it, then I'll re-format and merge the rest inside of #305

Removed Google link from community management section.
Removed contributors section from the overview of guides.
Copy link
Collaborator

@mattaereal mattaereal left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm.

@mattaereal mattaereal merged commit 929342a into security-alliance:develop Jan 27, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

content:add This issue or PR adds content or suggests to

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants