Skip to content

Comment notifications, but without the comment body #1341

Description

@petecooper

Is your feature request related to a problem?

Yes, minor problem at client, potential to grow.

What is the feature?

Article comment notifications in email without the comment content, just a hyperlink to the comment in the admin-side.

There's a comment spam campaign going on, it appears to include human submitters getting past the preview-then-submit tripwire on comments form. The email alert comes from the site server, passes through various commercial SMTP server(s) on various domains and the content is (rightly) classified as spam.

The knock-on effect after some weeks of this happening is that the Textpattern server IP is now considered to be sending spam, and has blacklist entries at 4 organisations. There are no other obvious adverse effects at present, and I can redeploy the server elsewhere, but I have a gut feeling this might affect more sites/people in future.

Potential solutions:

  • have the client log in every so often and check the queue (extra burden, user might forget)
  • send the notification email without the comment content (extra burden to check content, but much lower chance of spam classification)
  • something else I've overlooked

Activity

  1. petecooper commented on Sep 13, 2018

    @petecooper
    MemberAuthor

    Tagging #308 for completeness.

  2. Bloke commented on Sep 13, 2018

    @Bloke
    Member

    Not exactly a solution, but as a temporary measure, can you visit Preferences->Comments and set Email comments to author? to 'None' or 'All but spam'?

    EDIT: We could extend this with another option in future: 'Just notification, no content'.

  3. petecooper commented on Sep 13, 2018

    @petecooper
    MemberAuthor

    Hi @Bloke - that's pretty much what I've done already as a stop-gap. All the spam that gets through is classed as ham (not spam) by Textpattern, unfortunately -- which is making it a bit tricky. The email server has more stringent checking, and their email policy doesn't permit whitelist exceptions (somewhat annoyingly).

  4. Bloke commented on Sep 13, 2018

    @Bloke
    Member

    Right. So we probably need to revisit our heuristics (whatever they may be: I didn't even know we had any!) to update it for 2018 and make it better at ham/spam detection.

    Or, radical outlook, pop a cap in the ass of the current comments system and modularise it so it's a self-contained unit - Admin panel, prefs, article integration, notifications and tags - eject it from core and then gradually iterate to improve the whole darn thing, tags and all, as a separate entity. Dunno.

  5. petecooper commented on Sep 13, 2018

    @petecooper
    MemberAuthor

    My understanding is that there's room to add in known spam check endpoints (Spamhaus et al), and the feedback from there is what defines spam/ham. Out of the box, no spam check endpoints – so it's not really a surprise this is happening. In this case they're using a spam check endpoint, but its not effective…and I assume on those grounds if you defer to their authority, Textpattern is acting as it should.

    Based on the info I have, I'm +1 in favour of modularising it, which then creates a heap of work to get it up to snuff. #308 is the marker for the comments overhaul, maybe best to subsume this issue into the outcomes or work involved with that and keep the noise level to a minimum.

  6. petecooper commented on Sep 18, 2018

    @petecooper
    MemberAuthor

    Added note to #308 - closing this issue.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions