Come together with the global Drupal community in Rotterdam, 28 Sept – 1 Oct 2026. Sessions, contribution, connection, and Early Bird savings until 8 June.
I'm a little wary of adding nofollow to all links (even legitimate links), but I'd like to hear what others think. Maybe this could be used in combination with some sort of process for community vetting of non-spammers.
I think for some links, like event urls and valid links in discussions or wiki pages we do want to keep dofollow. It'd be ok to set nofollow for just signature links I guess. But then, can we get some numbers of how many signature spammers we have on g.d.o? Might be not worth effort.
I think one really good thing to do would be to copy the 'Not a spammer' role / Honeypot setup we have on D.o to g.d.o (and we do have a separate issue for that, I think). First of all, this will provide consistency and less confusion for users once sites have the same setup. Next good step would be to synchronize roles, if user gets 'trusted' status on one website, they automatically get it on another, so don't have to 'prove' themselves twice. Lastly, in the current D.o setup, user profiles of people who don't have 'not a spammer' role are only visible to logged in users. Therefore, not visible to search engines. This hugely helped us prevent profile spam.
I deleted the spam in that thread and we generally quickly delete any spam that's reported.
I think everyone (except spammers, of course) is in favor of adding no-follow to links that are likely spam. The hard part is determining which links are likely to be spam, which is more complex than event links are legitimate and everything else is potentially spam.
Comments
Comment #1
danpros commentedComment #2
sreynen commentedAdjusting title to what I think was the intent of this. Please adjust further if I got it wrong.
Here's a module we could use for this:
https://www.drupal.org/project/nofollowlist
I'm a little wary of adding nofollow to all links (even legitimate links), but I'd like to hear what others think. Maybe this could be used in combination with some sort of process for community vetting of non-spammers.
Comment #3
tvn commentedI think for some links, like event urls and valid links in discussions or wiki pages we do want to keep dofollow. It'd be ok to set nofollow for just signature links I guess. But then, can we get some numbers of how many signature spammers we have on g.d.o? Might be not worth effort.
I think one really good thing to do would be to copy the 'Not a spammer' role / Honeypot setup we have on D.o to g.d.o (and we do have a separate issue for that, I think). First of all, this will provide consistency and less confusion for users once sites have the same setup. Next good step would be to synchronize roles, if user gets 'trusted' status on one website, they automatically get it on another, so don't have to 'prove' themselves twice. Lastly, in the current D.o setup, user profiles of people who don't have 'not a spammer' role are only visible to logged in users. Therefore, not visible to search engines. This hugely helped us prevent profile spam.
Comment #4
danpros commentedI saw lats of spam links, example https://groups.drupal.org/node/442513
When spammer knows if its dofollow than bad links will increased. Events link should using some of kind custom field and only dofollow those links.
Comment #5
sreynen commentedI deleted the spam in that thread and we generally quickly delete any spam that's reported.
I think everyone (except spammers, of course) is in favor of adding no-follow to links that are likely spam. The hard part is determining which links are likely to be spam, which is more complex than event links are legitimate and everything else is potentially spam.
We do have an issue open for sharing roles and honeypot config across sites: #2104697: Use honeypot / drupalorg_honeypot on g.d.o. I also opened #2373261: Allow users to follow each other's posts as a potential means of automatically identifying non-spammers.
Comment #6
sreynen commentedSomething to review after D7 migration.
Comment #7
avpadernoThe only development done on groups.drupal.org is to replace it. The plan seems to migrate it into drupal.org, as described in #2590497: [meta] Proposal to migrate groups into Drupal.org.