this post was submitted on 15 Jun 2023
14 points (100.0% liked)

Lemmy Moderation Tools

10 readers
1 users here now

Welcome

I'm working on a moderation tool to work with Lemmy.

I'm still in early development and discovery. This channel will update the status and respond to questions during development, testing, release, and post-release.

You are encouraged to create posts defining your needs. I also appreciate feedback on status updates. This helps me maintain the right track.

Join us on Matrix!

founded 1 year ago
MODERATORS
 

Here's a laundry list of sort with tons of tools we'd like to see

  • Role for approval of applications (to delegate)
  • Site mods (to delegate from admins)
  • Auto-report posts with certain keywords or domains (for easier time curating without reports)
  • Statistics on growth (user, comments, posts, reports)
    • User total
    • MUA
    • User retention
    • Number of comments
    • Number of posts
    • Number of reports open
    • Number of reports resolved
  • Sort reports
    • by resolved/open
    • by local/remote
  • Different ways to resolved a report
    • Suspend account for a limited amount of time rather than just banning
    • Send warning
  • Account mod info
    • Number of 'strikes' (global and local) and reports
    • Moderation notes
    • Change email
    • Change password
    • Change role
  • Ability to pin messages in a post
  • Admins should be able to purge
  • Filter modlog to local
  • Better federation tools (applications to communities, limiting)
    • Applications to communities to allow safe spaces to exist (people should not be able to just "walk in" on a safe space - similarly to follow requests in Mastodon in a way)
    • Limiting (Lock our communities down from certain instances but still allow people using our instance to talk to people from those instances)

Obviously considering the moment when this is being made - federation tools are our highest priority.

top 8 comments
sorted by: hot top controversial new old
[–] jojo 3 points 1 year ago (1 children)

A few of these are already possible via the API, afaik;

  • Stats
    • User total
    • Number of Active Users (per day, week, month, 6month)
    • Users online
    • Number of; Comments, Posts
    • Number of reports (via iterating reports api)
  • Sort reports;
    • By resolved/open
  • Different ways to resolve a report: (Can be done by client providing quick buttons to perform action next to resolution)
  • Pin messages in a post: This is the ability to "feature" a post, "distinguished" comments are also coming, I saw in the Lemmy commits
  • Admin should be able to purge;
POST /admin/purge/person PurgePerson
POST /admin/purge/community PurgeCommunity
POST /admin/purge/post PurgePost
POST /admin/purge/comment PurgeComment

However, imo, notable absences are;

  • The ability to prevent posting until moderator review
  • Auto-reporting or regex matching per community (right now its a side-wide "slur filter" regex)
  • Better tools, like you said, like notes and strikes
[–] Lionir 3 points 1 year ago

Yeah, a few of these are ultimately UI, not necessarily just missing functionality

Admin should be able to purge;

Only the creator admin can actually purge : https://github.com/LemmyNet/lemmy/issues/2976

[–] towerful 1 points 1 year ago (1 children)

In my opinion "change password" is an outdated way of doing things.
"Send password reset email" would be the correct way.

[–] poke 4 points 1 year ago (2 children)

Emails are optional on some instances. Having both options would be nice. On the other hand, allowing admins to change their users' passwords makes it easier for them to impersonate their users, though that just may be something we accept.

[–] Lionir 3 points 1 year ago (1 children)

Yeah, the issue is people without email but also people with the wrong email. I've caught quite a few typos from our email server not being able to send their approval because the email had a typo. I did send them manually and tell them the error they made.

So, I guess we could just change email but I don't see quite the difference in terms of abuse with regards to change password if I could simply change someone's email and get it anyways.

[–] poVoq@slrpnk.net 3 points 1 year ago

People providing a broken email also make the approval hang. it works approving them, but the admin gui hangs with a spinning icon until you do a full page refresh.

[–] towerful 2 points 1 year ago (1 children)

I understand that emails are optional.
However, if a user wants to recover their account, then they should provide an email (even just a burner).
It's not much, but it would add an extra safe-guard against admin abuse.
Mod logs could show "mod changed email for user x" without any PII. Which would add some insight into potential admin abuse if this happened excessively or if a user complained about it happening to them.
I imagine any admin with postgres skills could delete/suppress the modlog entry tho.

Personally, I wouldn't trust any website if I contacted them with an "I've locked myself out" request, and they replied with a new password.

TL;dr: Regardless, I don't actually have any skin in the mod/admin game.
I can understand that it seems useful.
I am still of the opinion that it is an outdated way to do account recovery.

[–] Gaywallet 1 points 1 year ago* (last edited 1 year ago)

No way to validate it is actually the user if they're locked out. Your info exists on their server, so they can change your password or email trivially. Anyone could disable/enable these kinds of tools that automatically notify, ultimately you shouldn't sign up for an instance you don't trust.