Do you think I could just leave this part blank and it'd be okay? We're just going to replace the whole thing with a header image anyway, right?
You are not logged in.
Kizuna Ai wrote:Different55 wrote:More CSRF, now for the likes page.
CSRF..?
D:<i believe it’s a certificate.
Are you **** sure?
Explain tell me but what it is CSRF?
Yan Joshua knows as Nightmore, 7kudmath, Ygor Matheus, Kogor, Koya and RQ aka ~
I'm a professional artist, talented in various art forms, and also a programmer.
I had been playing Everybody Edits for four years ago. ~
Learning English and Japanese, Portugal ~
Native Portuguese speaker, fluent ~
20 years old, April 5, 2003. ~
He/Him ~
Contact information:
Discord: Kenny 💀#0578
In-game: 7KUDMATH
Xbox: YanJoshuaRQ
Steam: YanJoshuaRQ
Offline
CSRF stands for "Cross-Site Request Forgery", if I'm correct.
Essentially means you're able to make requests (like change the theme of another user) that you're no supposed to be able to.
Offline
Fixed another CSRF bug in the PM system, this one allowing users to delete other people's folders.
In the case of this latest round of bugs, it's less "change the theme of another user" and more "trick another user into changing their theme."
"Sometimes failing a leap of faith is better than inching forward"
- ShinsukeIto
Offline
- change the theme of another user
so accounts alts?
Yan Joshua knows as Nightmore, 7kudmath, Ygor Matheus, Kogor, Koya and RQ aka ~
I'm a professional artist, talented in various art forms, and also a programmer.
I had been playing Everybody Edits for four years ago. ~
Learning English and Japanese, Portugal ~
Native Portuguese speaker, fluent ~
20 years old, April 5, 2003. ~
He/Him ~
Contact information:
Discord: Kenny 💀#0578
In-game: 7KUDMATH
Xbox: YanJoshuaRQ
Steam: YanJoshuaRQ
Offline
Last edited messages now appear in the post header.
Mods and admins can now review edit history and restore from it from within the forums.
After reviewing the needs of the gamestaff, I've created a new "gamestaff" permission that only enables editing of some posts in limited circumstances. Instead of locking down individual parts of the the "moderator" permission, this is starting from nothing and building up from there. Additional abilities can be whitelisted as needed.
"Sometimes failing a leap of faith is better than inching forward"
- ShinsukeIto
Offline
Last edited messages now appear in the post header.
Mods and admins can now review edit history and restore from it from within the forums.
After reviewing the needs of the gamestaff, I've created a new "gamestaff" permission that only enables editing of some posts in limited circumstances. Instead of locking down individual parts of the the "moderator" permission, this is starting from nothing and building up from there. Additional abilities can be whitelisted as needed.
Ok the addition is cool but did you remove xeno's editing powers
and also topic lock powers outside game business
Offline
Different55 wrote:I've created a new "gamestaff" permission that only enables editing of some posts in limited circumstances.
Does this include other users posts?
Yes. See below.
Different55 wrote:Last edited messages now appear in the post header.
Mods and admins can now review edit history and restore from it from within the forums.
After reviewing the needs of the gamestaff, I've created a new "gamestaff" permission that only enables editing of some posts in limited circumstances. Instead of locking down individual parts of the the "moderator" permission, this is starting from nothing and building up from there. Additional abilities can be whitelisted as needed.
Ok the addition is cool but did you remove xeno's editing powers
and also topic lock powers outside game business
They can edit in forums they've been whitelisted for. They can't edit or post in locked topics, can't (currently) lock or unlock topics, and they can't edit silently since that's only used in extremely limited moderation tasks and so isn't useful for gamestaff at all.
In forums where they're whitelisted their editing abilities are pretty limited. Now that edit history manipulation is easily available to all forum staff (instead of being lost in a random log only I know about) I expect that won't be a problem for anyone.
"Sometimes failing a leap of faith is better than inching forward"
- ShinsukeIto
Offline
Diff, why should Xeno moderate anything on these forums at all? We have forum mods for that.
I remember when we originally gave Nou mod permissions, it was so he could edit topics where Thanel was the owner.
If that's still needed, let staff edit the first post in every topic in Game Business (it's always a staff post).
Now that edit history manipulation is easily available to all forum staff (instead of being lost in a random log only I know about) I expect that won't be a problem for anyone.
EE staff have never been good at PR.
Even nou once censored new topics to "prevent drama".
It always backfires.
Its always a rationally dumb choice for staff abuse their role.
Yet they still do it and cause drama.
But why do we choose to let them?
I have never thought of programming for reputation and honor. What I have in my heart must come out. That is the reason why I code.
Offline
Even nou once censored new topics to "prevent drama".
It always backfires.
Also the time NVD censored a topic, then censored more topics addressing his censorship.
I thought one of the first "rules" established for the forums, was that NO game staff would have control over the forums. The idea was to keep punishments separate and avoid censorship.
But why do we choose to let them?
This time... it will be different!
Discord: jawp#5123
Offline
Diff, why should Xeno moderate anything on these forums at all? We have forum mods for that.
He's not. That's why this change was made, to prevent them from moderating anything at all. Let me be clear, I don't really think Xeno did anything wrong cleaning up that topic. I do think he did it in an atypical way for how the forum staff would handle it. He's not looped in with all of our processes so while his way of handling it wasn't bad, it wasn't what we would have done.
While their occasional help is appreciated (if awkward), they really don't need to. The permissions that are left are intended (and really only useful for) the original purpose of managing each other's topics.
But why do we choose to let them?
We don't. This update shows that we don't.
"Sometimes failing a leap of faith is better than inching forward"
- ShinsukeIto
Offline
Offline
So they're not allowed to moderate/edit our posts but they still technically can do it?
How can we be reassured that they're not going to edit our posts regardless
They technically can't still do it.
In the past we gave just Xeno mod powers because he needed to be able to make changes to other staff posts. Then we extended that to a few others who needed to all manage one topic without sharing an account. Before now, we just gave them mod powers and locked down banning and warning, which were our main 2 mod powers we figured.
As of this update, they're only able to edit the first posts in forums they "moderate," so it's more like having a shared account without actually sharing anything.
And as of a few hours ago they also have the ability to userlock (so it can't override a modlock, and it doesn't interfere with the original owner's lock in case they don't also have gamestaff permissions) each other's topics and sticky any topic.
Also one more (this time undiscovered) CSRF vulnerability has been fixed.
"Sometimes failing a leap of faith is better than inching forward"
- ShinsukeIto
Offline
Fixed half-missing CSRF token, people should be allowed to close their own topics again.
"Sometimes failing a leap of faith is better than inching forward"
- ShinsukeIto
Offline
Offline
Fixed half-missing CSRF token, people should be allowed to close their own topics again.
that's still not fixed, mate
hey diff why dotn you sticky this topic
thanks hg for making this much better and ty for my avatar aswell
Offline
That's the only active topic out there so it won't ever go down
Offline
Different55 wrote:Fixed half-missing CSRF token, people should be allowed to close their own topics again.
that's still not fixed, mate
Looks fixed to me, what topic are you trying to close that isn't working?
"Sometimes failing a leap of faith is better than inching forward"
- ShinsukeIto
Offline
Nebula wrote:Different55 wrote:Fixed half-missing CSRF token, people should be allowed to close their own topics again.
that's still not fixed, mate
Looks fixed to me, what topic are you trying to close that isn't working?
https://forums.everybodyedits.com/viewt … p?id=46111 that one here
Hey diff, please make last edited message also clickable, it makes it easier to copy post url on phone
Offline
New user registrations temporarily disabled while Diff cleans up the nearly 3000 bot accounts that registered this month and makes the filter racist again.
One bot to rule them all, one bot to find them. One bot to bring them all... and with this cliché blind them.
Offline
Never thought I would see the day where hate wins over love. Disappointed in the direction this community is going in!
Buy replica watches submariner quartz crstyal online at reputable relaible online e-commerce shops based out of sellers. Online casino
Offline
Send love and corn to our lord and master Indifferent55, as user registrations are now enabled again.
One bot to rule them all, one bot to find them. One bot to bring them all... and with this cliché blind them.
Offline
[ Started around 1733249491.9572 - Generated in 0.271 seconds, 10 queries executed - Memory usage: 1.77 MiB (Peak: 2.05 MiB) ]