Deleting own message is logged in the audit log

(#413) Bug Awaiting confirmation moderation

Summary

When a user deletes a message that they created themselves and then delete it, it is still logged to the audit log (even though no special permissions are needed to perform the operation). I don't think this is intended behavior since it will likely spam audit log in big servers, even though the audit log is meant for logs of "administrative" actions. Discord doesn't do this either.

Steps to reproduce

  1. Send a message in a community (guild).
  2. Delete the message.
  3. There will be a new audit log entry stating that you deleted a message in the channel where you sent it.

Environment (optional)

stable build 87 (28da28c), 2026-03-11 14:24:05 UTC, Chrome 144.0.0.0, Linux (x86)

Logs or screenshots (optional)

image
  • 563751523-e6b5ab16-89e6-451b-9937-732c5e7cdb04.png

    563751523-e6b5ab16-89e6-451b-9937-732c5e7cdb04.png

    753×91 | 12 kB

2 comments

Sign in with Fluxer to comment and vote.
Comment by Rex
RexSystem 1 vote
Status changed from Fixed to Awaiting confirmation
This was closed in a bulk cleanup before Fluxer V2 without being checked or fixed. It may work now, so it is waiting for someone to confirm whether the bug still happens.
Comment by @cproudlock
RexSystem 1 vote originally by @cproudlock on GitHub
I looked into this — the fix is straightforward. In packages/api/src/channel/services/message/MessageDeleteService.tsx line 117, the audit log entry is created unconditionally for all guild message deletions:
if (channel.guildId) {
    await this.guildAuditLogService
        .createBuilder(channel.guildId, userId)
        .withAction(AuditLogActionType.MESSAGE_DELETE, message.id.toString())
        // ...
The fix is to add a check so self-deletions are skipped:
if (channel.guildId && message.authorId !== userId) {
The bulkDeleteMessages method correctly always logs since it requires MANAGE_MESSAGES permission (admin action), so that one should stay as-is.