Topic: [Feature] Limit access to "Undo selected"

Posted under Site Bug Reports & Feature Requests

Requested feature overview description.

Require at least Privileged rank (or equivalent account permissions) to be able to see and click the "Select All" and "Undo selected" links at the top of the post changes page.

Why would it be useful?

It's become apparent that "Undo selected" is this site's most vulnerable target for causing large-scale, difficult-to-detect, disruptive vandalism quickly and easily. I've just found a second case, and even then enough of the edits are small enough to not immediately arouse suspicion. (Does post #3424402 really have a "long" foreskin? Is that an uvula in post #2458025?) In fact, I only twigged what was going on because of the edit to post #3736435, whose uploader accidentally pasted the description into the tag field, and the vandal undid the uploader's attempt at fixing it. And even then, I wouldn't have spotted it if the uploader hadn't missed one of the invalid tags on their second attempt at removing them.

The user responsible deleted their account soon after, and they never did anything else on the site. The only other case I know of is user #1212407, but this crime is so easy to commit and so difficult to detect that I'm 100% confident there have been others. The only thing preventing it from (probably) being a full-on epidemic is the obscurity of the dangerous tools in question.

What part(s) of the site page(s) are affected?

Post changes page

I second this change, even for an average user who tags a lot, I don't see an use for the super easy undo button. And I presume tag scripts are already limited for privileged users to prevent easy vandalism. The undo button is less flexible than a script, but still abusable.

In my short time in this site, I've only seen a need to use the button twice, and both instances were to fix the same issue the undo button caused, easy tag vandalism made by a random.

It do be really annoyingly disruptive to be working on some tags, only to refresh the page and see someone undid your changes, making a previous post appear again. Nothing like a "Oh shit did I mess something up in this post" scare.

+1 I actually thought this is a tool for privileged+ already. And as you said, it can cause a lot of harm to the site. If the trolls knew how this website works, they could really easily fuck around with us.

I've encountered people doing this a few times, I remember some of them denying doing it on purpose, so I think adding a popup confirmation asking if you actually want to do that could be a good idea.

Other powerful tools like tag scripts are already restricted to priv+ so this wouldn't be out of the ordinary. If people really still want to be a pain they'll find a way, but let's not make it too easy for them.

The only times I've noticed somebody mass reverting stuff is when they revert something I did, like removing an invalid tag from a post, then see the post again the next day and think "Wait a minute... I already did this one". I feel like it's very easy for these to fly under the radar if nobody is going to check whether their edits are reverted or not.

Updated

+1 to the suggestion. Making it priv+ makes sense and that would be consistent with similar levels of tools like tag scripting. So this does seem like a good idea.

Aaand I just discovered my 10,000th edit was using this tool to revert the vandalism on post #3735824. Which consisted of removing an aspect ratio tag added by a bot, of all things.

The undo feature is useful to undo vanalism as well, maybe just make it something that leaves a more noticeable record than a single blue bar among a large list of them.

Since we are on this topic, is there a way to search for post changes I have done, that have also been undone? Manually checking the pages is quite a hassle.

  • 1