# 스태프가 초대한 사용자는 승인 절차 생략 허용

**URL:** https://meta.discourse.org/t/allow-users-invited-by-staff-to-skip-approval/231300
**Category:** Feature
**Tags:** invites
**Created:** [6월 28, 2022, 5:14오전 UTC](https://meta.discourse.org/t/allow-users-invited-by-staff-to-skip-approval/231300 "2022-06-28T05:14:49Z")
**Posts on this page:** 1
**Showing post:** 5

<div class="post-metadata">

### Author: ![Stephen](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/stephen/32/95011_2.png) [@Stephen](https://meta.discourse.org/u/Stephen)
#### Post date: [6월 28, 2022, 11:31오전 UTC](https://meta.discourse.org/t/allow-users-invited-by-staff-to-skip-approval/231300/5 "2022-06-28T11:31:50Z")

</div>

> [@nathankershaw](#):
>
> 스태프의 초대장은 명시적인 승인이라고 생각했습니다. 특히 초대장에 사용자 이메일 주소가 포함된 경우 말이죠!

맞습니다. 다만 이 동작은 약 한 달 전에 변경되었습니다:

> [@스태프가 생성한 초대 링크가 must\_approve\_users 요구 사항을 우회합니다](https://meta.discourse.org/t/staff-generated-invites-bypass-the-must-approve-users-requirement/228199):
>
> We’ve had a serious security issue with the invite system. I guess it’s easily reproducible. Our site is on invite-only. In addition, we have checked “must approve users” in the settings. One of our staff issued an invitation with a max use greater than 1, thus not restricted to one email in particular (example below). That invite link circulated, and people could register with it. Yet we expected that when “must approve users” is checked …

저희는 기술 교육용으로 사용 중인 자선 단체/노조의 인스턴스에서도 유사한 영향을 받고 있습니다.

변경 이전에는 스태프가 초대한 사용자가 승인을 우회할 수 있었지만, 이제는 승인 절차와 가입 절차를 모두 거쳐야 합니다. 각 승인 사항을 멤버십 목록과 대조하여 확인해야 하는 번거로움으로 인해 관리 부담이 상당히 증가했습니다.

---

_[View the full topic](https://meta.discourse.org/t/allow-users-invited-by-staff-to-skip-approval/231300)._
