Closed
Bug 700718
Opened 14 years ago
Closed 12 years ago
It's too easy to create a group on Mozillians.org
Categories
(Participation Infrastructure :: Phonebook, defect, P3)
Participation Infrastructure
Phonebook
Tracking
(Not tracked)
VERIFIED
FIXED
People
(Reporter: felix, Unassigned)
References
Details
(Whiteboard: [infrasec:dos])
With any POST request to edit profiles, I can end up creating groups. This might seem sane at first, but I can, using some script, send several requests each causing the creation of a large number of groups. From what I can tell, this definitely hogs up CPU on the server as it takes on the order of minutes to create ~10000 groups.
See:
https://mozillians.org/en-US/u/6d7abdc827
and making groups?page=xxx meaningless
https://mozillians.org/en-US/groups?page=530
Comment 1•14 years ago
|
||
I would disagree that this was a higher priority if we only allowed Vouched Mozillians to add groups, but we allow non-vouched users (possible spammers) to do so too.
We should look into limiting the number of groups users can create if they're non-vouched.
Severity: major → normal
Priority: -- → P2
Target Milestone: --- → 1.3
| Reporter | ||
Updated•14 years ago
|
Whiteboard: [infrasec:dos]
Updated•14 years ago
|
Component: mozillians.org → Phonebook
Product: Websites → Community Tools
QA Contact: mozillians-org → phonebook
Target Milestone: 1.3 → ---
Version: unspecified → other
Comment 2•13 years ago
|
||
Let's do this:
* Restrict group creation to vouched users
* Attach a creator to the group (if it's not already there)
This will probably prevent the spam issue contemplated, and give us a way to clean up and ban if the issue ever surfaces.
Priority: P2 → P3
Comment 3•12 years ago
|
||
The suggestions in comment 2 have now been implemented. Creating groups is done explicitly, and elegantly through a new form. Each new group is associated with a curator, who is the creator.
Marking as resolved, thanks to the excellent work in bug 936569.
Status: NEW → RESOLVED
Closed: 12 years ago
Resolution: --- → FIXED
You need to log in
before you can comment on or make changes to this bug.
Description
•