On Tue, Nov 24, 2009 at 7:51 PM,
uncl...@gmail.com
<
uncl...@gmail.com> wrote:
> I think we're good at the moment regarding tightening privledges. I'll take
> responsibility for fixing this one since I unintentionally missed adding
> some basic lockdown. I also need to add the OpenID and CAPCHA modules, any
> other suggestions?
I remember the OpenID mediawiki plugin being problematic (a while ago)
so I tried the OpenID wiki (or what I thought was the OpenID wiki)
itself to see if it was using the OpenID media wiki plugin:
http://wiki2008.openid.net/
Happy to report that the OpenID mediawiki plugin installed there
performed beautifully! I'd suggest the specific plugin they've got
installed.
CAPTCHA maybe for account creation but please not for edits - it's a
terrible participation disincentive/speedbump. Either way it's not
urgent IMHO.
These two points also noted on wiki (where follow-up can go too)
http://wiki.openwebfoundation.org/To-do#wiki_admin
> I'm happy to add Board members as admins, but I'd also wouldn't want to see
> it turn into a free for all.
Thanks much Nate.
I've checked the past 500 edits / 30 days worth of edits and:
* blocked all spamming IPs from anonymous edits
* deleted all pages whose
* content and history were all spam, or
* blank, but previous content and history were all spam
- no need to keep spam-only histories of wiki pages.
Ugly details here:
http://wiki.openwebfoundation.org/Special:RecentChanges
One thing I noticed is that many folks' User pages fell into one of
those two deletion categories noted above.
If you have edited the wiki, I strongly recommend that you
specifically edit/create your User page (click on the small red link
in the header with your name) and add something simple, e.g. here is
what I started with (wiki code)
----------------------------- snip ------------------------
== public domain release ==
{{cc-public-domain-release}}
== see also ==
* hCard: <span class="vcard"><span class="fn">Tantek Çelik</span>
(<span class="url">
http://tantek.com/</span>)</span>
----------------------------- snip ------------------------
That way if/when your user page(s) are spammed again, we'll have
something nice/stable/solid to revert back to.
Thanks,
Tantek
--
http://tantek.com/