Announcement

Collapse
No announcement yet.

New users can paste images in post and not trigger automatic moderation

Collapse
X
Collapse
First Prev Next Last
 
  • Filter
  • Time
  • Show
Clear All
new posts

    New users can paste images in post and not trigger automatic moderation

    vBulletin Version:
    - 5.7.0

    PHP Version:
    - 7.4.32

    Database Version:
    - 8.0.31

    Issue Description: (Include error message(s), if any)
    - New users can paste images in posts

    Affected Browser(s):
    -

    Steps to Reproduce: Expected Result:
    - New users should not be able to include pasted images in posts

    Actual Result: (Include screenshot(s), if possible)
    -

    Registered User usergroup is where all our new registered members get assigned. When they have made three approved posts, they are moved (by Promotion) to Established usergroup, where additional permissions are granted.

    New users can paste images in their posts because there isn't a permission in this usergroup that controls doing so. Unacceptable images can therefore be included, ex: porn.

    How can we prevent pasted images from being included in new user posts?
    The Linux Community has given me much. I do what I can to return the favor!

    #2
    Pasted images like normally uploaded images are attachments. Check the attachments-related permissions (e.g. Can Create Attachments) in the usergroup.
    Helpful? Donate. Thanks!
    Buy me a coffeePayPal QR Code
    Fast VPS Host for vBulletin:
    A2 Hosting & IONOS

    Comment


    • glennrocksvb
      glennrocksvb commented
      Editing a comment
      Also check "Skip Moderation for Posts/Topics With Attachments" permission

    #3
    Click image for larger version

Name:	Create Permissions.png
Views:	103
Size:	56.8 KB
ID:	25936

    As you see above, Can Create Attachments is set to No, yet pasted images can be included; I did just that with my test user. I have screen shots of the sequence of events if you want to see them.

    Originally posted by glennrocksvb View Post
    Skip Moderation for Posts/Topics With Attachments
    That is set to Yes. I'll change that to No.
    The Linux Community has given me much. I do what I can to return the favor!

    Comment


      #4
      Even after setting "Skip Moderation for Posts/Topics With Attachments" to No, and logging in with my test user, I was able to create a first post with a pasted image:

      Click image for larger version  Name:	Screen Shot 2023-01-13 at 1.15.21 PM.png Views:	0 Size:	124.0 KB ID:	25938

      The post doesn't get flagged as requiring Moderation.

      The user can see the post and its content. Guests can see the post and its content. HOWEVER, when I log in with my normal user (happens to be an Administrator), the post is identified in the list of topics/posts in the forum it was made in, but when I open it, the pasted image is NOT visible:

      Click image for larger version

Name:	Screen Shot 2023-01-13 at 1.29.15 PM.png
Views:	103
Size:	120.9 KB
ID:	25939

      BUT, when I click on Edit, the pasted image is visible:

      Click image for larger version

Name:	Screen Shot 2023-01-13 at 1.31.10 PM.png
Views:	95
Size:	184.1 KB
ID:	25940

      Why is this happening?
      The Linux Community has given me much. I do what I can to return the favor!

      Comment


        #5
        This seems to be a bug. When you look at the topic list, can you see the Attachment icon (clip) near the Statistics column for the corresponding topic with pasted images? If so, then the pasted images are considered "attachments".
        Helpful? Donate. Thanks!
        Buy me a coffeePayPal QR Code
        Fast VPS Host for vBulletin:
        A2 Hosting & IONOS

        Comment


          #6
          Does it work if you attach the images normally?
          Helpful? Donate. Thanks!
          Buy me a coffeePayPal QR Code
          Fast VPS Host for vBulletin:
          A2 Hosting & IONOS

          Comment


            #7
            Originally posted by glennrocksvb View Post
            Does it work if you attach the images normally?
            Attempting to attach an image results in:
            Click image for larger version  Name:	First Post attempting to include Attachment.png Views:	0 Size:	84.1 KB ID:	25944

            "You cannot upload attachments in this channel"

            This is the issue; using the function to 'attach' an image results in being denied (what we want), but copy/pasting an image isn't blocked (not what we want). Copy/Paste of an image bypasses the 'rule'.
            The Linux Community has given me much. I do what I can to return the favor!

            Comment


              #8
              Try also setting "Maximum Attachments per Post" permission to 0.
              Helpful? Donate. Thanks!
              Buy me a coffeePayPal QR Code
              Fast VPS Host for vBulletin:
              A2 Hosting & IONOS

              Comment


                #9
                Originally posted by glennrocksvb View Post
                When you look at the topic list, can you see the Attachment icon (clip) near the Statistics column for the corresponding topic with pasted images?
                No.

                And interestingly, I just logged out (as my Admin user) and viewed our Forum as an unlogged in Guest. Looking at the topic list for the post I made (as my 'new' user), there is also no attachment icon. And even more interesting, when I actually view the post, the image still isn't visible. But if again, I log in as my normal user (an Administrator), viewing the post doesn't show the pasted image. If I edit the post, the image is shown.
                The Linux Community has given me much. I do what I can to return the favor!

                Comment


                  #10
                  Originally posted by glennrocksvb View Post
                  Try also setting "Maximum Attachments per Post" permission to 0.
                  Done. I'll test another post to see if I can paste an image.
                  The Linux Community has given me much. I do what I can to return the favor!

                  Comment


                    #11
                    I can still paste an image in a new post with my testing user.

                    Click image for larger version

Name:	Screen Shot 2023-01-13 at 3.54.16 PM.png
Views:	53
Size:	158.7 KB
ID:	25949
                    The Linux Community has given me much. I do what I can to return the favor!

                    Comment


                      #12
                      Try setting the "Space (in bytes) that a user's total attachment usage may consume" option to 1 (byte). Setting 0 means unlimited so just try 1.
                      Helpful? Donate. Thanks!
                      Buy me a coffeePayPal QR Code
                      Fast VPS Host for vBulletin:
                      A2 Hosting & IONOS

                      Comment


                        #13
                        Originally posted by glennrocksvb View Post
                        Try setting the "Space (in bytes) that a user's total attachment usage may consume" option to 1 (byte).
                        Okay, made that change. I'll try anther post in a bit.

                        Something is really flaky! The first post I made wasn't showing the pasted image when I (as logged in Admin user) viewed the post, but was visible if I edited the post. But I logged in as the test user, and when I viewed the post, the image was visible. I then logged out and back in as my Admin user. I viewed the post and the image WAS visible, without having to edit the post!
                        The Linux Community has given me much. I do what I can to return the favor!

                        Comment


                          #14
                          The 'rabbit hole' on this issue goes deeper still!

                          I was just informed by one of our other Admins that he can't see the images in the posts I made! WTF! I see them!!
                          The Linux Community has given me much. I do what I can to return the favor!

                          Comment


                            #15
                            Maybe time to update to 5.7.2
                            Helpful? Donate. Thanks!
                            Buy me a coffeePayPal QR Code
                            Fast VPS Host for vBulletin:
                            A2 Hosting & IONOS

                            Comment

                            Users Viewing This Page

                            Collapse

                            There is 1 user viewing this forum topic.

                            • Guest Guest

                            Latest Posts

                            Collapse

                            Working...
                            X
                            Searching...Please wait.
                            An unexpected error was returned: 'Your submission could not be processed because you have logged in since the previous page was loaded.

                            Please push the back button and reload the previous window.'
                            An unexpected error was returned: 'Your submission could not be processed because the token has expired.

                            Please push the back button and reload the previous window.'
                            An internal error has occurred and the module cannot be displayed.
                            There are no results that meet this criteria.
                            Search Result for "|||"