Don't shoot me if I'm wrong, but as far as I know you can post "something" (a comment or so) with more URLs than defined with the 'Maximum allowed URLs'-setting, and your message will bypass the spam-filter as long as:
- you don't put http:// or https:// or ftp:// or mailto: in front of your URL or email address (for example:
www.example.com)
- AND the 'URL filter' (which turns web and e-mail addresses into clickable links) is enabled for the input format that is used for a (visitor's) user role
As far as I understand the spam module('s code), the "second pass" (grab urls from unsanitized string) of the spam_tokenize function should/could be extended by using more code from Drupal's built in URL filter method.
Doing so will catch more potential spam links, I think.
Any feedback is welcome.
Comments
Comment #1
jeremy commentedPatches to improve the spam module's detection of URLs is certainly welcome.
Comment #2
jeremy commentedEfforts to improve the URL filter will happen in the 5.x-3.x development branch of the module.
Comment #3
jeremy commentedPostponing issue. I would like to see the url filtering improved, but this is not a show stopper at this time. Postponing until after we are in beta, or until someone comes along with a patch.
Comment #4
pieterdcPatch created against 6.x-1.x-dev (as Drupal 5 is almost unsupported).
But I guess this patch could easily be backported.
Ready for testing because.. as far as I tested it, it works ;-)
Comment #5
gnassar commentedThere probably is a good reason for this that I just haven't come up with yet -- but why wouldn't we just run the text through _filter_url() and then test that, instead of duping its internals here?
Comment #6
pieterdcBecause _filter_url() changes the text, but the Spam module needs to know how many and which links were found in that piece of text.
Comment #7
gnassar commentedCommitted. Thank you for the great patch.
Comment #8
jeremy commented@gnasser, please include a link to the CVS commit message when you commit patches for future reference.
Comment #9
gnassar commentedCrud. I did forget to do it on this one, didn't I? And I'd been so good about it on all the others... :)
http://drupal.org/cvs?commit=469868