discourse ver: 2.7.0.beta4
discourse-chat-integration ver: latest from git as @ 25/02/21
browser: firefox 85.0.1 (64-bit)
os: ubuntu 20.20 (latest patching)
bit off an interesting one.
we have a few discourse first post only to discord transfers which work a treat although the user’s name gets displayed which seems to be a security oversight.
i can’t find anywhere where this is configurable and have a suspicion it may be an oversight?
@Orzo is all it should be displaying
if i’ve had a boy look and there is an article here that i have not managed to find, feel free to point me to it.
Does the full name appear on the Discourse post on the forum, or just the username? (in other words, is the setting prioritize username in ux enabled on your Discourse site?)
i went and checked a couple of things, have not gotten to the specific discord element you mention (removed: brainfart)
checked exactly which attribute “James Mitchell” is contained in under Orzo’s discourse profile I have found that the name doesn’t actually appear anywhere in the user’s account.
I checked a few other posts into discord from discourse with similar string @profile and found the same thing.
that setting prioritize username in ux is enabled.
toggled the setting - did not alter behaviour
installed data browser and confirmed that users.name is what is finding its way to discord
interestingly users.name doesn’t appear editable through the discourse UI - am i having a muppet moment here?
Olá, isso ainda está acontecendo e parece vir do endereço de e-mail, mas apenas de certos usuários - poderia estar pegando o endereço de e-mail e de alguma forma removendo a pontuação e tudo depois do @?
Esta é uma questão de proteção de dados bastante preocupante.
Desculpe desenterrar isso, mas os usuários estão um pouco preocupados - tive que desativar a integração.
O nome vem do campo ‘name’ do Discourse, que é preenchido durante o cadastro (seja pelo usuário digitando, ou obtido do seu sistema de login). Dependendo de como o seu fórum está configurado, esse valor pode estar oculto da interface do usuário, então é definitivamente confuso que ele apareça através da integração de chat.