Zorro_X

Rules spreading PM to 85 users

Recommended Posts

Hi,

First I've contacted Invision support but they've suggested me to disable Automation Rules app and/or contact you.

Yesterday we had a strange behavior in our community : into  a PM I've sent to 2 users then leave the conversation (to let the users talk in private without me) in February 13, the last item of the discussion is also on February 13. Yesterday (April 2) without any user action and knowing that none of the users in the PM can add more than 4 users to a current conversation, 85 users have been added to the conversation, apparently randomly chosen from the users database.

Invision support says "there really is no way for our software to do such a thing, the feature simply doesn't exist"... 

Now we've a confidentiality issue in our system that could randomly and potentially give access any user to any PM... We're very concerned by this security problem.

 

Since last update (Invision V4.4.X and Rules V1.4.6) we've also experienced some other strange behaviors that seems linked to automation rules system : regarding users groups changes, some users got their primary group set as secondary group then their primary group set to none... Others have changed group without any human intervention and without matching any rules of the system.

 

Best regards,

Alexander

Edited by Zorro_X

Share this post


Link to post
Share on other sites

I've no rules set to add 85 random users to a random private message.

I've rules set to change users groups but not in the way shown (primary group set as secondary then no primary group set).

As said, I've first contacted Invision support, here is what they said to me, so it is the only reason why I'm contacting you : 

Quote

When investigating your community, I did notice that you do have the Rules app installed. I do not want to jump to conclusions but this third party application is known for causing some well, unintended behaviors. Do you have any rules setup around the messaging system? If so, specifically around adding or removing individuals in the conversation?

Quote

Hello,  There really is no way for our software to do such a thing, the featue simply doesn't exist, I would disable or uninstall the rules app, then see if you see any further issues.

Quote

Hello,  either that or remove/disable it to see if this repeats, we don't have any way for our software to do what you are describing, so without a third party app gone wrong here it's not really anything on our end. 

... (?)

Edited by Zorro_X

Share this post


Link to post
Share on other sites

If you are concerned that a rule you have configured might be the cause of a problem, you can do a couple of things.

First, you can turn debugging on for the rule(s) in question. Then you can look at its logs to see if it is working as expected when the rule conditions are met.

Secondly, you could create a custom rules log, and then log to it in your rules where you change a member group, etc. This would allow you to look at log entries for more insight.

Share this post


Link to post
Share on other sites

Thankyou, I already use logs to debug.

But :

there are no rules able to perform what happened (add users to a PM).

. some rules seems to be triggered without user interaction (and they're not trigered by a scheduled routine)

. there are no new rules added since last updates (V4.4.X for Invision software and V1.4.6 for rules) and before the updates nothing like that never uses to happen. All rules were already in use before the updates and without such problems.

Share this post


Link to post
Share on other sites

Can you please thel it to Invision, because they say the problem is in your application...

I've no custom code, the only other plug-ins that are runing are MemberMaps and SwipperSlider that does not concern private messages at all...

 

Each time it happened I had to go through SQL to remove all users from the spreaded conversation. It is not a sustainable way to work...

Edited by Zorro_X

Share this post


Link to post
Share on other sites

Reading other posts where IPS seems to not "like" your app, may it be possible IPS has inserted some "incompatible code" to make your app unstable since last update ?

Before V4.4.X I never had such problems (I had others, but not so critical).

Share this post


Link to post
Share on other sites
4 hours ago, Zorro_X said:

Reading other posts where IPS seems to not "like" your app, may it be possible IPS has inserted some "incompatible code" to make your app unstable since last update ?

Before V4.4.X I never had such problems (I had others, but not so critical).

Did you read any posts from users, who have the similar issue like yours? Or are you a unique one? Seeing your unsolved issue, I fear to update my board to 4.4.* now...

Share this post


Link to post
Share on other sites

No, IPS did not insert some code to make rules unstable. 

The mystery of this one is that rules does not have any code in it which adds users to existing conversations.

In other words, it could not be the cause of this. 

Is it possible that someone on your site or in the conversation added the additional users?

Share this post


Link to post
Share on other sites
7 hours ago, Kevin Carwile said:

Is it possible that someone on your site or in the conversation added the additional users?

nope : no one has rights to add more than 4 users to a conversation...

even moderators cannot add more than 10 users...

Share this post


Link to post
Share on other sites
On 4/17/2019 at 2:21 PM, alexis said:

Did you read any posts from users, who have the similar issue like yours? Or are you a unique one? Seeing your unsolved issue, I fear to update my board to 4.4.* now...

Hi, for the moment I seem to be "alone" with that issue...
But like said on my first post, I had other "new" issues since last update. So I recommend you to wait a little before upgrading...

In another hand, I switched back to PHP 7.1 hopping this may "solve" something...

Share this post


Link to post
Share on other sites

Your content will need to be approved by a moderator

Guest
You are commenting as a guest. If you have an account, please sign in.
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.