제안: 계정 사칭 시 마지막 접속 날짜에 영향을 주면 안 됩니다

Hey guys

Current behaviour is: When impersonating a user’s account, the last seen date is affected by this action. This behaviour is confusing for other users and our staff since they assume, that the user was actually online at this date/time.

My suggestion is to not count the impersonation towards the last seen date.

Would appreciate your feedback on this :slight_smile:

5개의 좋아요

I have to disagree with this. I am aware of a few forums from my communities that my friends and I have been a part of where the admins behind those forums would maliciously use ”impersonate” to try to get people into trouble.

Staff should have access to the staff logs that show when and who impersonated an account. You should make everyone on your team aware of it.

2개의 좋아요

Admins could always reset that date in the database anyway, or prevent updating the last seen date using a plugin. If you cannot trust the admins then there is nothing you can do.

5개의 좋아요

That’s a flaw in the system more than anything.

One thing that I think could actually help is sending a message to the user that they were impersonated. Yea, this could be undone by plugin makers but most malicious admins are usually teens that get scared by those kinds of stuff or adults that wouldn’t be really able to afford hiring someone to do program the plugin for them.

1개의 좋아요

I think we’re getting a bit distracted from the subject here. The last seen being updated when a user is being impersonated is more confusing than useful.

If we need more auditing about impersonation then that’s a different thing.

By the way, I think you’re making some dangerous assumptions here.

6개의 좋아요

우리의 사용 사례에 대해 빠르게 추가 질문을 드립니다.

우리 주제의 특성상 사용자들은 개인정보 보호에 매우 민감합니다. 그래서 오랜 기간 코어로 활동하던 사용자가 갑자기 다시 나타났을 때, 관리자 위장(impersonation)으로 인해 “마지막 접속” 날짜가 갱신된 경우, 일부 사용자는 불안해하거나 다소 혼란을 겪곤 합니다… :eyes:

2개의 좋아요

새로운 사칭(impersonation) 기능을 사용 중인 경우(숨겨진 사이트 설정 experimental_impersonationtrue로 설정하여 활성화)에는 사용자를 사칭할 때 last_seen_at 타임스탬프가 더 이상 업데이트되지 않습니다.

https://github.com/discourse/discourse/pull/34872

새로운 사칭 기능을 Discourse 호스팅 포럼에 적용하는 것을 계획하고 있습니다.

6개의 좋아요

새로운 임페르소네이션(신원 위장) 기능의 의도가 그 영향을 줄이는 것이라고 파악합니다. 하지만 현재 last_seen_at 외에도 다른 효과들이 존재합니다. 제 판단으로는, 임페르소네이션을 사용할 때 사용자는 해당 유저가 되어 행동하게 됩니다.

대기 중인 알림을 클릭하면? 이제 상대방이 그것을 본 상태가 됩니다.
읽지 않은 게시물을 열면? 이제 상대방이 그것을 읽은 상태가 됩니다.

이 점을 고려할 때, 저는 해당 유저의 동의를 얻어 트러블슈팅 목적으로만 이 기능을 사용할 것입니다. 임페르소네이션 세션 동안의 활동 기록을 제공하면서 사용자에게 알림을 보내는 데는 전혀 문제가 없다고 생각합니다.

1개의 좋아요

음, 근데 내 마지막 IP가 그 사용자에게 공개되게 남아있는 건가요? 제가 관리자로서 임의의 사용자를 사칭할 때 제 IP가 "노출"되는 건가요, 아니면 제가 잘못 알고 있는 건가요?

제 해결책은 해당 섹션을 숨기는 것이었습니다.

image

1개의 좋아요