Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

remove public access to unvetted proposals #81

Closed
behindtext opened this issue Oct 30, 2017 · 2 comments
Closed

remove public access to unvetted proposals #81

behindtext opened this issue Oct 30, 2017 · 2 comments

Comments

@behindtext
Copy link
Member

when proposals are first submitted, they are considered in the 'unvetted' state and must be manually reviewed by someone who checks that a number of basic requirements are satisfied. since proposals that are unvetted or currently in the process of being vetted could contain inflammatory content, we must deprive users of the ability to externally access this data while a proposal is unvetted. this avoids the scenario of pi being used to effectively serve inflammatory content, albeit via an indirect channel.

as part of fixing this, the censorship token lookup widget in the ui would be removed. users who submit proposals that are ultimately censored should be able to independently verify that their proposal was indeed received and not made public with its censorship token alone. by allowing lookups against a censorship token, whoever is hosting the pi instance may end up inadvertently hosting inflammatory content.

@sndurkin
Copy link
Contributor

sndurkin commented Oct 30, 2017

Unvetted proposals are already only accessible by admin users. I think the only action items here are:

@sndurkin
Copy link
Contributor

The rest of this issue has been addressed in #167.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants