Port from qwibitai/nanoclaw#3260: adds a third unauthorized_dm_behavior option, 'decline'. Instead of replying with a pairing code (pair) or staying silent (ignore), the gateway sends one short, polite decline to the unknown sender, then stays silent toward that sender for 24 hours. - gateway/config.py: accept 'decline' in the normalizer; new unauthorized_dm_decline_message for custom decline text (round-trips through to_dict/from_dict). - gateway/pairing.py: persisted decline stamps (_declined.json) on PairingStore with has_recent_decline/record_decline; stamps are pruned on write and recorded BEFORE delivery so a send failure can't become a decline storm (nanoclaw's stamp-first pattern). - gateway/run.py: decline branch in the unauthorized-sender path; groups still always silently ignore. - docs: security.md + configuration.md updated. Adapted from TypeScript (NanoClaw's pending_sender_approvals 'decline:' stamp rows) to Hermes' existing PairingStore JSON persistence; the owner-FYI half of nanoclaw's flow is intentionally not ported — Hermes logs the unauthorized attempt, and pairing remains the owner-visible grant path. Rebase onto the decomposed gateway (salvage, #88028): - The unauthorized-sender path moved from gateway/run.py to gateway/run_inbound.py::_hm_admit_event; the decline branch is a sibling helper _hm_send_unauthorized_decline next to _hm_offer_pairing_code. - gateway/config.py now validates the enum via _normalize_choice; the accepted set is the module constant UNAUTHORIZED_DM_BEHAVIORS (used by both from_dict and get_unauthorized_dm_behavior so a per-platform `extra.unauthorized_dm_behavior: decline` is honoured too). The default decline text lives in config as DEFAULT_UNAUTHORIZED_DM_DECLINE_MESSAGE. - Tests trimmed from 5 to 2 invariant tests (send-once-then-silent through the real inbound path; config round-trip + real PairingStore stamp lifecycle with a patched clock instead of rewriting the JSON file).
Website
This website is built using Docusaurus, a modern static website generator.
Installation
yarn
Local Development
yarn start
This command starts a local development server and opens up a browser window. Most changes are reflected live without having to restart the server.
Build
yarn build
This command generates static content into the build directory and can be served using any static contents hosting service.
Deployment
Using SSH:
USE_SSH=true yarn deploy
Not using SSH:
GIT_USER=<Your GitHub username> yarn deploy
If you are using GitHub pages for hosting, this command is a convenient way to build the website and push to the gh-pages branch.
Diagram Linting
CI runs ascii-guard to lint docs for ASCII box diagrams. Use Mermaid (````mermaid`) or plain lists/tables instead of ASCII boxes to avoid CI failures.