Support Forum

Advanced Search
Forum Scope


Match



Forum Options



Minimum search word length is 3 characters - maximum search word length is 84 characters
general-topic
Thanks Plugin
Avatar
Mr Papa
Simi Valley, CA
SP Master
Free Members
sp_UserOfflineSmall Offline
Nov 2, 2014 - 2:38 pm

okay, I can see a way you could 'hack' the javascript code and trick it into thanking itself (the js is local client so no server risk)... 

but still not sure I see a way to accomplish changing the thanks text... so example would still be nice...

Avatar
Alex T
Member
sp_UserOfflineSmall Offline
Nov 2, 2014 - 3:15 pm

Mr Papa said
okay, I can see a way you could 'hack' the javascript code and trick it into thanking itself (the js is local client so no server risk)... 

but still not sure I see a way to accomplish changing the thanks text... so example would still be nice...

I just sent you a PM with a screenshot.  

Avatar
Mr Papa
Simi Valley, CA
SP Master
Free Members
sp_UserOfflineSmall Offline
Nov 2, 2014 - 4:19 pm

lol... that is not a thanks...  the user simply copy the html for a thanks, pasted it into a post and saved...  you can verify that by checking the actual post content (either edit the post or look in the database)...   I dont believe the post thanks plugin was not used to create that...  and so he didnt hack the js either... but interestingly enough, I was able to replicate such an action, so will put out an update after some testing of the fix... but wont help users doing creative posts...

nothing we can do about that since a user can make up whatever post content they want...  up to moderators to check the content...  or moderate his posts...  you could use the warnings and suspensions plugin to deal with unruly...

Avatar
Alex T
Member
sp_UserOfflineSmall Offline
Nov 2, 2014 - 4:48 pm

Mr Papa said
lol... that is not a thanks...  the user simply copy the html for a thanks, pasted it into a post and saved...  you can verify that by checking the actual post content (either edit the post or look in the database)...   I dont believe the post thanks plugin was not used to create that...  and so he didnt hack the js either... but interestingly enough, I was able to replicate such an action, so will put out an update after some testing of the fix... but wont help users doing creative posts...

nothing we can do about that since a user can make up whatever post content they want...  up to moderators to check the content...  or moderate his posts...  you could use the warnings and suspensions plugin to deal with unruly...

Honestly, it doesn't bother me.  It looks just like the Thanks, except for the text.  I just wanted to make sure that someone can't backdoor...

Here's the code used when I checked the edit:

<div class="spThanksList">The following users say thank you to Pakoon for this useful post:
<p>Pakoon</p>
</div>
Avatar
Mr Papa
Simi Valley, CA
SP Master
Free Members
sp_UserOfflineSmall Offline
Nov 2, 2014 - 6:17 pm

yeah, that was my point...  if you see it when editing the post, its not from the Thanks plugin...  Its not part of the post content and wouldnt show up...

the trouble maker simply copied the code from the thanks display below a post and pasted it into his own post as content...  and edited...

since its not really a thanks, it wont show in his reputation either...

Forum Timezone: Europe/Stockholm
Most Users Ever Online: 1170
Currently Online:
Guest(s) 1
Currently Browsing this Page:
1 Guest(s)
Top Posters:
Mr Papa: 19448
Ike: 2086
Brandon: 864
kvr28: 804
jim: 650
FidoSysop: 577
Conrad_Farlow: 531
fiddlerman: 358
Stefano Prete: 325
Member Stats:
Guest Posters: 620
Members: 17365
Moderators: 0
Admins: 4
Forum Stats:
Groups: 7
Forums: 17
Topics: 10128
Posts: 79626