Last modified: 2013-09-25 19:33:45 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T56408, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 54408 - Configuration to allow account creation only after confirming email
Configuration to allow account creation only after confirming email
Status: NEW
Product: MediaWiki
Classification: Unclassified
User login and signup (Other open bugs)
1.22.0
All All
: Low enhancement (vote)
: ---
Assigned To: Nobody - You can work on this!
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2013-09-20 23:12 UTC by Quim Gil
Modified: 2013-09-25 19:33 UTC (History)
5 users (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description Quim Gil 2013-09-20 23:12:27 UTC
MediaWiki allows the creation of new accounts before confirming email or in fact without providing one at all. Email confirmation is purely optional.

This makes sense in the context of Wikipedia and other Wikimedia sites because these projects made this choice. However, the usual practice in most websites is to have an account created only after confirming email. It is reasonable to expect that most 3rd party MediaWiki admins will expect this functionality, especially when they start seeing dozens of spam accounts created every day.

It's quite trivial for spammers to go through captchas to create new accounts. I'm sure they can also get a system to confirm emails massively, but at least that is a higher level of complexity.


If this is not considered for core then an option would be to integrate this functionality in [[mw:Extension:ConfirmAccount]]. This extension does require email confirmation, but admins must approve all requests manually. Besides, the project seems to be unmaintained...
Comment 1 Bartosz Dziewoński 2013-09-25 17:07:22 UTC
Can't you just restrict editing to users who confirmed their e-mail address? This is, surprisingly, even documented: [[mw:Manual:User rights#Examples]].
Comment 2 Bartosz Dziewoński 2013-09-25 17:08:13 UTC
Huh, there's even [[mw:Manual:$wgEmailConfirmToEdit]] (but this is kinda less documented ;) ).
Comment 3 Quim Gil 2013-09-25 19:04:57 UTC
Sure, but this doesn't prevent account creation.

A regular (and even unknown) wiki will get about 20 spam accounts created every day unless they introduce some kind of antispam measure - and even then bots and spammers are getting better at passing through captchas.

Site admins and communities want to know who are the legitimate users in order to e.g. reach out to them or have some stats. And well, just to have your house clean of rubbish. It's hard to tell spam accounts apart from legitimate silent accounts.
Comment 4 Bartosz Dziewoński 2013-09-25 19:33:45 UTC
Ah. Yeah, you're right.

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links