Since we require login to submit demos, and logged in users have to pass a captcha to register in the first place, we might be able to remove the captcha from the demo submission form. There's nothing like uploading a multi-meg demo and having captcha validation fail. On the other hand, since demo submissions go live right away, this means spammers only have to pass one captcha to start uploading garbage. Leaving this bug open for discussion
(In reply to comment #0) > Since we require login to submit demos, and logged in users have to pass a > captcha to register in the first place, we might be able to remove the captcha > from the demo submission form. There's nothing like uploading a multi-meg demo > and having captcha validation fail. > > On the other hand, since demo submissions go live right away, this means > spammers only have to pass one captcha to start uploading garbage. > > Leaving this bug open for discussion Let's remove the captcha and add honeypot fields to the demo submission form then? It should stop bots and won't frustrate real users.
Until we make it so that users need to confirm/enable the demos after submitting, I think we should keep the Captcha there. Once we make newly submitted demos hidden by default, it might be safer. I don't know how easily hackers could login once to MDN and then run scripts to submit demo spam... but rather not find out. :-) I'll defer to Luke on the best alternative solution when the time comes.
Will mention this to Holly, who is working on UX.
Hi, i'm interested in fixing this, however I would need help getting around things.
Hi, I have created a pull request for this : https://github.com/mozilla/kuma/pull/3157
Sorry, it's https://github.com/mozilla/kuma/pull/3158
karan, sorry I forgot to assign this. Utkarsh already has a pull request in for it: https://github.com/mozilla/kuma/pull/3158/files
Oops, this is Utkarsh's PR: https://github.com/mozilla/kuma/pull/3131
Commits pushed to master at https://github.com/mozilla/kuma https://github.com/mozilla/kuma/commit/f716858711455b2afee850ab5a1b537810bd34dc Fixes bug 632204 - Remove reCAPTCHA * removes the captcha form field from forms and template * removes django-recaptcha submodule * remove the recaptcha settings from settings.py https://github.com/mozilla/kuma/commit/c83e948350c9d5f22d9e6f85cf45e40c5bc6e568 bug 632204 - Removes re-captcha field tests https://github.com/mozilla/kuma/commit/e4d2755b5f69763b8ba895dcd1b12ef81f72ef4b bug 632204 - remove captcha app from settings https://github.com/mozilla/kuma/commit/715c5e7b17a0bb558bc8aea874ab736a89ae94ed bug 632204 - remove RECAPTCHA from settings_local https://github.com/mozilla/kuma/commit/12d56a83d1691d11fc037709297d9efbaf0850b1 bug 632204 - clean up imports https://github.com/mozilla/kuma/commit/9e4c0f6347b5f294f9779ff6570737fa01b1ac23 Merge pull request #3165 from groovecoder/remove-recaptcha-632204 r+ by @jezdez Fixes bug 632204 - Remove reCAPTCHA