We build. You grow.

Get best community software here

Start a social network, a fan-site, an education project with oxwall - free opensource community software

What is this? | Forum

Topic location: Forum home » Support » General Questions
Marcus
Marcus Aug 10 '16
I have submit profile picture turned off on registration form BUT some of mine users show as not verified with profile picture how come how were they able to upload the profile picture on registration?
Darryl B Leader
Darryl B Aug 10 '16
I'm guessing you have mandatory approval turned on. It has been a while since I did test accounts, but I am guessing that it could be that they are doing it after registration by editing their profile to do the non-required fields. They aren't suppose to be able to use the site, but may be able to do that.
Marcus
Marcus Aug 11 '16
The thing is that the use shows in admin/users under Unverified means they don't have access to the site functions! And no I do have avatar upload as required!

My guess is that It's a bot that submits avatar but the script doesn't check whether it can be uploaded or not!
Attachments:
  11-8-2016 12.8.20 1.jpg (21Kb)
Darryl B Leader
Darryl B Aug 11 '16
Not sure Marcus. I just went through a registration with mandatory approval on, avatar on sign up was off. The user couldn't do anything. I clicked on all of the links, and the drop down list items, and it wouldn't do anything. The message kept popping up about waiting for approval.
I have the ultimate captcha installed using the re-captcha feature, and noticed that this one makes you select pictures that match the question. Pretty cool.
Marcus
Marcus Aug 12 '16
I think I know what's up! I am showing validate email template to the user which means the user doesn't have access to site's features! But if you know the URL of the feature you can use it despite the fact you are not verified :)
Darryl B Leader
Darryl B Aug 12 '16
Sounds like you've discovered a bug. The urls are shown by hovering over the links. The user shouldn't be considered as a registered member until they are approved. The page they go to after registration should only show the message about waiting for approval, and not have the menu options. That way they couldn't see the urls, and use the work around that you've found.
Darryl B Leader
Darryl B Aug 12 '16
I just went through another demo registration. I tried putting the urls in after I signed up, but that didn't work either. It wouldn't let me proceed by either clicking, or entering the url.  I did this again with mandatory approval on, and avatar off on sign up.
Have you tried this on your site?
Marcus
Marcus Aug 15 '16
Maybe bot can load all the necessary HTML elements to make it work?
ross Team
ross Aug 16 '16
I'm sorry Marcus, but we cannot reproduce that, if "mandatory approve" or " verification of e-mail" is enabled, users can't edit their profiles. 


We need the exact steps how to reproduce the issue, in order to fix it. 

Marcus
Marcus Aug 16 '16
I am not sure buddy how the bots are doing it all I see is users showing in awaiting activation with avatars despite the fact that avatar upload is not showing on sign-up. Notice! Not all users show like that only one or two!