Un utente fittizio che crea un account completo e pubblica un link riceve numerose segnalazioni di spam

Per ora lo registro come Contribute > Bug, ma potrebbe trattarsi di una Contribute > Feature.

Un utente invia un messaggio di gruppo e scambia molte comunicazioni nel corso di un lungo periodo. Due mesi dopo aver avviato il messaggio di gruppo, l’utente si registra sul sito e viene sbloccato, diventando un utente TL0. Successivamente, l’utente pubblica un argomento che include un link utilizzato in precedenza nel messaggio di gruppo. L’utente viene immediatamente silenziato dal sistema e vengono sollevati numerosi flag a causa della newuser spam host threshold. Un utente non dovrebbe essere “penalizzato” dal sistema per aver pubblicato un argomento perfettamente normale a causa dell’esistenza di un messaggio di gruppo mentre era un utente in fase di staging.

4 Mi Piace

Yes we have had this bug for a long time.

Probably we need to better consider the dates the user “joined” based on staging.

3 Mi Piace

We were just hit by this again, 58 PMs to the moderator group created. We’ve got to fix this…

5 Mi Piace

This happened again. Not a staged account this time, but a normal user getting support and including links. The spam trigger was correct this time (a new user posting links to the same domain), but we still ended up with 33 PMs in the moderator inbox. Consolodating those messages would be nice.

3 Mi Piace

This happened again. Staged user signed up, received only 3 flags (not as bad as in the past), but caused a bit of confusion with the user.

1 Mi Piace

Maybe @featheredtoast can have a look; we get bitten by this regularly so the code needs to be improved.

Probably we need to better consider the dates the user “joined” based on staging.

5 Mi Piace

That sounds like a sane improvement; let me see what I can do here.

6 Mi Piace

This is now merged: previously staged users will now be considered trusted users. :pear:

https://github.com/discourse/discourse/pull/6002

7 Mi Piace

We’re confident this has no security holes, e.g. you can’t game the system by mailing in, then immediately sign up to gain TL1 “for free”?

The main focus here is ensuring that the spam link check is improved.

2 Mi Piace

I get your point, I misunderstood what we wanted to do here sorry - that’s how it is right now (consider someone as a “trusted users” if they come through staged.)

I’ll improve this now - just to confirm, all we want is the spam host check to not trigger, but all other new user checks will still be in place, correct? (the other checks being: max links, max mentions, and max attachments)

1 Mi Piace

It might be safe “enough” if you gate it by time. What I object to is someone emailing team@discourse.org and then IMMEDIATELY signing up with that same email to gain trust level 1. That’s a straight up exploit.

OK I’ve updated this - Now, they will still be considered tl0, but will not trigger the spam if the accounts were created more than 1 week ago to catch the “long email relationship” cases. :banana:

https://github.com/discourse/discourse/commit/68e4e6a5755db4dd974eaeed73d5cfc517449b75

Do we want ‘time until discourse recognizes a mature staged user’ be an additional site setting, or is this sufficient barrier lowering?

6 Mi Piace

I would say one day is probably fine and safe enough; it’s pretty easy to get from TL0 to TL1 if you know what you are doing.

5 Mi Piace

OK, done - this should be good now :fish_cake:

https://github.com/discourse/discourse/commit/2ff226e5091f279ed2aa5b3e707a1acbd74f21fd

6 Mi Piace