Since we require login to submit demos, and logged in users have to pass a captcha to register in the first place, we might be able to remove the captcha from the demo submission form. There's nothing like uploading a multi-meg demo and having captcha validation fail.
On the other hand, since demo submissions go live right away, this means spammers only have to pass one captcha to start uploading garbage.
Leaving this bug open for discussion
(In reply to comment #0)
> Since we require login to submit demos, and logged in users have to pass a
> captcha to register in the first place, we might be able to remove the captcha
> from the demo submission form. There's nothing like uploading a multi-meg demo
> and having captcha validation fail.
> On the other hand, since demo submissions go live right away, this means
> spammers only have to pass one captcha to start uploading garbage.
> Leaving this bug open for discussion
Let's remove the captcha and add honeypot fields to the demo submission form then? It should stop bots and won't frustrate real users.
Until we make it so that users need to confirm/enable the demos after submitting, I think we should keep the Captcha there.
Once we make newly submitted demos hidden by default, it might be safer. I don't know how easily hackers could login once to MDN and then run scripts to submit demo spam... but rather not find out. :-)
I'll defer to Luke on the best alternative solution when the time comes.
Will mention this to Holly, who is working on UX.
Hi, i'm interested in fixing this, however I would need help getting around things.
Hi, I have created a pull request for this : https://github.com/mozilla/kuma/pull/3157
Sorry, it's https://github.com/mozilla/kuma/pull/3158
karan, sorry I forgot to assign this. Utkarsh already has a pull request in for it:
Oops, this is Utkarsh's PR: https://github.com/mozilla/kuma/pull/3131
Commits pushed to master at https://github.com/mozilla/kuma
Fixes bug 632204 - Remove reCAPTCHA
* removes the captcha form field from forms and template
* removes django-recaptcha submodule
* remove the recaptcha settings from settings.py
bug 632204 - Removes re-captcha field tests
bug 632204 - remove captcha app from settings
bug 632204 - remove RECAPTCHA from settings_local
bug 632204 - clean up imports
Merge pull request #3165 from groovecoder/remove-recaptcha-632204
r+ by @jezdez Fixes bug 632204 - Remove reCAPTCHA