# 不要显示拥有特定徽章的用户名

**URL:** <https://meta.discourse.org/t/do-not-display-the-usernames-that-hold-a-specific-badge/254318>\
**Category:** Support\
**Created:** [2023年二月7日 09:49 UTC](https://meta.discourse.org/t/do-not-display-the-usernames-that-hold-a-specific-badge/254318 "2023-02-07T09:49:27Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Richie](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/richie/32/115110_2.png) [@Richie](https://meta.discourse.org/u/Richie)\
**Post date:** [2023年二月7日 09:49 UTC](https://meta.discourse.org/t/do-not-display-the-usernames-that-hold-a-specific-badge/254318/1 "2023-02-07T09:49:27Z")

</div>

是否有办法隐藏拥有特定徽章的用户列表？

我查看了 [Don't list members having the same badges](https://meta.discourse.org/t/dont-list-members-having-the-same-badges/172240) 和 [https://meta.discourse.org/t/hide-badge-user-list/46471，但它们并不完全符合我们的用例（或者更可能是我们的边缘情况）。](https://meta.discourse.org/t/hide-badge-user-list/46471%EF%BC%8C%E4%BD%86%E5%AE%83%E4%BB%AC%E5%B9%B6%E4%B8%8D%E5%AE%8C%E5%85%A8%E7%AC%A6%E5%90%88%E6%88%91%E4%BB%AC%E7%9A%84%E7%94%A8%E4%BE%8B%EF%BC%88%E6%88%96%E8%80%85%E6%9B%B4%E5%8F%AF%E8%83%BD%E6%98%AF%E6%88%91%E4%BB%AC%E7%9A%84%E8%BE%B9%E7%BC%98%E6%83%85%E5%86%B5%EF%BC%89%E3%80%82)

徽章在我们的社区中非常受欢迎，它们是提高参与度的绝佳资源。

我们的 Discourse 有一些高级类别，仅对订阅者/付费会员可用，我们希望通过个人资料中的金徽章来奖励这些付费会员，在此示例中我们称之为“额外特别会员”。

付费会员的数量是商业敏感数字。

该数字将泄露给任何拥有“额外特别会员”徽章的人，即使它在徽章页面上隐藏了，他们也可以简单地点击自己的徽章，然后看到所有也拥有该徽章的其他会员。

有没有办法阻止人们看到谁还拥有某个特定徽章？🤔

---

<div class="post-metadata">

**Author:** ![Stephen](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/stephen/32/95011_2.png) [@Stephen](https://meta.discourse.org/u/Stephen)\
**Post date:** [2023年二月7日 09:53 UTC](https://meta.discourse.org/t/do-not-display-the-usernames-that-hold-a-specific-badge/254318/2 "2023-02-07T09:53:46Z")

</div>

您不能改用Flair吗？

---

<div class="post-metadata">

**Author:** ![Richie](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/richie/32/115110_2.png) [@Richie](https://meta.discourse.org/u/Richie)\
**Post date:** [2023年二月7日 10:19 UTC](https://meta.discourse.org/t/do-not-display-the-usernames-that-hold-a-specific-badge/254318/3 "2023-02-07T10:19:37Z")

</div>

嗯mmm 🤔

很有可能……

这个警告是否有泄露敏感成员编号的风险？

> 由于这是一个主群组，名称“hidden\_group\_test\_2”将在 CSS 类中使用，任何人都可以查看。

抱歉颜色鲜艳，这只是为了测试：

 ![Screenshot 2023-02-07 at 10.18.26](https://global.discourse-cdn.com/meta/original/4X/6/c/2/6c2e684979cb08beb966befd25727d723c6f2dec.png)

---

<div class="post-metadata">

**Author:** ![Richie](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/richie/32/115110_2.png) [@Richie](https://meta.discourse.org/u/Richie)\
**Post date:** [2023年二月7日 19:05 UTC](https://meta.discourse.org/t/do-not-display-the-usernames-that-hold-a-specific-badge/254318/4 "2023-02-07T19:05:15Z")

</div>

> [@Richie](#):
>
> 这个警告是否会泄露敏感的成员编号？

我不反对泄露隐藏的用户组名称，只要成员列表/计数不被泄露。

---

<div class="post-metadata">

**Author:** ![Richie](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/richie/32/115110_2.png) [@Richie](https://meta.discourse.org/u/Richie)\
**Post date:** [2023年二月7日 20:04 UTC](https://meta.discourse.org/t/do-not-display-the-usernames-that-hold-a-specific-badge/254318/5 "2023-02-07T20:04:54Z")

</div>

> [@Stephen](#):
>
> 您不能改用徽章吗？

我已经进行了一些测试，但不确定这是否适合我们的用例。

（来自我们隐藏群组的）徽章会应用到用户身上，但他们一旦加入我们任何其他群组，他们的徽章就会被他们刚加入的群组的徽章替换。

在他们的个人资料上，他们之后只能选择一个公开群组的徽章，他们完全失去了对特殊成员徽章的访问权限，也无法重新应用它 😕

---

<div class="post-metadata">

**Author:** ![Stephen](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/stephen/32/95011_2.png) [@Stephen](https://meta.discourse.org/u/Stephen)\
**Post date:** [2023年二月7日 20:11 UTC](https://meta.discourse.org/t/do-not-display-the-usernames-that-hold-a-specific-badge/254318/6 "2023-02-07T20:11:38Z")

</div>

您是否在其他组中设置了此项：

![Screenshot 2023-02-07 at 2.09.34 PM](https://global.discourse-cdn.com/meta/original/4X/9/6/3/963251b13b5c60132b3a7f7b5ee1768d3e063fcb.png)

它位于每个组的“管理/成员资格”下的“效果”中。

如果此项已在该组上设置而不在其他组上设置，则不应覆盖。

主组将决定用户的默认装饰和标题。

---

<div class="post-metadata">

**Author:** ![Richie](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/richie/32/115110_2.png) [@Richie](https://meta.discourse.org/u/Richie)\
**Post date:** [2023年二月7日 21:24 UTC](https://meta.discourse.org/t/do-not-display-the-usernames-that-hold-a-specific-badge/254318/7 "2023-02-07T21:24:51Z")

</div>

是的，它已在我们所有的群组上设置，因此他们会获得他们刚刚加入的群组的徽章。

---

<div class="post-metadata">

**Author:** ![Richie](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/richie/32/115110_2.png) [@Richie](https://meta.discourse.org/u/Richie)\
**Post date:** [2023年二月8日 17:07 UTC](https://meta.discourse.org/t/do-not-display-the-usernames-that-hold-a-specific-badge/254318/8 "2023-02-08T17:07:44Z")

</div>

> [@Richie](#):
>
> 有没有办法阻止人们看到谁只拥有某个特定徽章？🤔

其他的想法是强制所有用户使用一个头衔，例如“访客”，但这可以被他们更改为他们拥有的任何徽章头衔。我认为我无法阻止人们更改他们的头衔。

我想让访客和会员能够识别彼此（例如，通过徽章），但又不泄露我们拥有的“超级特别会员”的数量。

还有其他创新的解决方案或变通方法吗？

我能用“用户字段”做些巧妙的事情吗？

也许创建一个名为“状态”的用户字段，使其在个人资料中可见，但不能由用户编辑。然后我可以通过 API 调用自动更新这个“状态”用户字段吗？（我们触发一个 API 调用将他们添加到组中）

---

<div class="post-metadata">

**Author:** ![Richie](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/richie/32/115110_2.png) [@Richie](https://meta.discourse.org/u/Richie)\
**Post date:** [2023年二月8日 17:32 UTC](https://meta.discourse.org/t/do-not-display-the-usernames-that-hold-a-specific-badge/254318/10 "2023-02-08T17:32:28Z")

</div>

我可能发现了什么：

> [@Richie](#):
>
> 也许创建一个名为“状态”的用户字段，使其在个人资料中可见，但不能由用户编辑。

我创建了一个名为“会员”的用户字段，并且不允许他们编辑：

 ![Screenshot 2023-02-08 at 17.28.00](https://global.discourse-cdn.com/meta/original/4X/e/1/8/e18b5d6cddb809b0bf51801c65b743f1808cbe80.png)

如果我编辑一个用户进行测试，我可以在他们的个人资料中看到“会员：是”：

 ![Screenshot 2023-02-08 at 17.29.39](https://global.discourse-cdn.com/meta/original/4X/b/a/3/ba305a702fc71b2fe4db11158f526772e9400344.png)

但这可能是决定性的：

> [@Richie](#):
>
> 然后我可以通过 API 调用自动更新这个“状态”用户字段吗？

我该如何着手呢？🤔

我已经有一个在某人成为会员时已经进行的 API 调用，我向 Discourse 发送一个 API 调用将他们添加到组中。我能否也发送第二个 API 调用来更新该用户字段？

---

<div class="post-metadata">

**Author:** ![Canapin](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/canapin/32/119591_2.png) [@Canapin](https://meta.discourse.org/u/Canapin)\
**Post date:** [2023年二月9日 16:59 UTC](https://meta.discourse.org/t/do-not-display-the-usernames-that-hold-a-specific-badge/254318/11 "2023-02-09T16:59:45Z")

</div>

> [@Richie](#):
>
> 我也可以发出第二个 API 调用来更新该用户字段吗？

当然 🙂

每次你在 Discourse 中执行任何操作时，都可以查看浏览器开发者工具的网络选项卡，以了解所进行的查询。

例如，在这里我保存了一个用户的个人资料：

 ![image](https://global.discourse-cdn.com/meta/original/4X/8/3/5/835bca9a8d49e0a9deb79ad5ba7ce7ec64c1ef40.png)

你会看到请求 URL，其中提到了用户名，以及请求的类型（PUT）。  
在 Payload 选项卡中，你会看到相关数据：

 ![image](https://global.discourse-cdn.com/meta/original/4X/b/e/8/be844c5f3f9a75e9c2867ed6939b3da9f3ee7a8e.png)

 ![image](https://global.discourse-cdn.com/meta/original/4X/0/4/0/0406eff840bb2aae579f75101d03cecbd8db11c1.png)

自定义字段列为 `user_fields[X]`，其中 X 是自定义字段的编号。

* * *

编辑：我看到你在 #Dev 中已经解决了这个问题，所以，只是为了交叉链接…… 🙂

> [@Updating Custom User Field through the API](https://meta.discourse.org/t/updating-custom-user-field-through-the-api/254515?u=canapin):
>
> I’ve been trying to reverse engineer the updating of a user\_field value. I did this by following the steps in [Reverse engineer the Discourse API](https://meta.discourse.org/t/reverse-engineer-the-discourse-api/20576), I edited a test user and made a note of what was occurring in the network tab of the browser. I can see that I need to PUT to this url: https://example.com/u/my-username-here.json Where I got a bit confused was by not seeing a json payload but instead it’s some formdata. The payload was: user\_fields%5B1%5D=some+dji%2C+some+Autel&user\_fields%5B5…
