This is the security I need.IMO, Unregistered / Unconfirmed users shouldn't be allowed to do anything other than read.
How do I make SURE I can make this the case in 1.0.4?
And HUGE thanks for y'all DOCUMENTING this hole!
This is the security I need.IMO, Unregistered / Unconfirmed users shouldn't be allowed to do anything other than read.
I don't totally follow the restrictions on setting up a profile for an unconfirmed user.
I share and understand your concern. I believe what Mike is saying is that most spam bots actually can confirm their memberships and will do so. After that is done, they can just as easily fill in the profile information with spam. What we need, are the tools to make cleaning it up much easier. Also, we should be able to restrict by usergroup, who can enter what details. Some of us would like to give users the ability to enter that data only after they have participated a certain amount. This can also be used as a spam trap. Before they can enter that data, they might try to spam in the forums, in which, we can just ban them before they have permission to edit their profile data.if an unconfirmed user can fill in all his stuff, then there is no need for any kind of registration-process at all.
An unconfirmed user should be limited to be able to enter data into the fields which are listed at the "Registration-page" (domain.com/register) only.
Spam is on the rise and having unconfirmed users posting some crap into various fields, etc. is increasing the workload for webmasters in order to keep a site clean.
While that may be true, that is not the point of this thread. This thread is to inform them of our concerns.Lets keep in mind that xf is still new and I'm sure that the Devs are working on as many features as fast as they can. I have 100% confidence in xf and believe all good things will come in time.
Lets keep in mind that xf is still new and I'm sure that the Devs are working on as many features as fast as they can. I have 100% confidence in xf and believe all good things will come in time.
That might not be so bad being it could be used to pass along info such as your email bounced etc. As long as they can't send, I could live with that. Regardless, I am eagerly awaiting 1.1.On a side note. They can read whatever PMs that are sent to them.
When someones registration email bounces back because it is misspelled, I can leave a PM for them and they will see it when they log in.
Yeah, I agree... that's a useful admin function... I'm less comfortable with the other situations enumerated here and I'd prefer to be able to switch them off ideally DEFAULTED to off and CHOOSE to enable if desired.That might not be so bad being it could be used to pass along info such as your email bounced etc. As long as they can't send, I could live with that. Regardless, I am eagerly awaiting 1.1.
We use essential cookies to make this site work, and optional cookies to enhance your experience.