Extension:ConfirmEdit/ru

Расширение ConfirmEdit позволяет вам использовать различные техники CAPTCHA, позволяющие защитить вики-проект от   спамеров и других автоматических инструментов редактирования, а также автоматизированных попыток подбора пароля к логину.

ConfirmEdit поставляется с несколькими технологиями/модулями генерации капчи.

Некоторые из этих модулей требуют дополнительных установочных работ:
 * Для модуля MathCaptcha требуется предустановленное приложение TeX и для версий MediaWiki выше 1.17,  -- наличие установленного приложения Math;
 * FancyCaptcha requires running a preliminary setup script in Python;
 * Модуль reCAPTCHA требует получения специальных API ключей (кодовых строк, которые используются как пароли для опознавания того, кто вызывает приложение - так как reCAPTCHA это сторонний продукт, сейчас принадлежащий Google)

Caveats: CAPTCHAs reduce accessibility and cause inconvenience to human users. In addition, they are not 100% effective against bots, and they will not protect your wiki in any way from human spammers. You may wish to use ConfirmEdit in conjunction with other anti-spam features. Regardless of the solution you use, if you have a publicly-editable wiki it's important to keep monitoring the "Recent changes" page.

Установка
ДЛя установки ConfirmEdit нужна MediaWiki версии 1.11.0 или выше  и PHP5 (but revisions on SVN before 21970 are  PHP4-compatible).


 * Загрузите последнюю версию и сохраните ее на вашем компютере.
 * Создайте папку в папке "extensions" с названием ConfirmEdit
 * Переместите загруженные файлы   в папку extensions/ConfirmEdit/
 * Отредактируйте файл LocalSettings.php, который находится в корневой папке вашей  MediaWiki , и добавьте следующую строку в нижнюю часть документа :

Примечание: ConfirmEdit может не работать, если используется с версиями MediaWiki отличными от тех, которые указываются при загрузке приложения.

типы теста CAPTCHA
В приложении используются несколько типов тестов CAPTCHA.

QuestyCaptcha
This module presents a question and the user supplies the answer. You provide the questions in the configuration. This module has proven to offer a strong mechanism against spam bots; it also should have the advantage of a better accessibility, as textual questions can be read by text-to-speech software allowing visually impaired users (but not bots) to answer correctly.

Set the following to enable this CAPTCHA:

It will randomly choose a question from those supplied. The minimum is one. Just change the questions when/if they start proving ineffective; this may never happen if your wiki is not specifically targeted.

You can get even smarter, with questions like «What is the output of "date -u +%V`uname`|sha256sum|sed 's/\W//g'"?».

Asirra
This module displays the Asirra (Animal Species Image Recognition for Restricting Access) widget, created by Microsoft Research. The widget shows 12 random images from the Petfinder pet-adoption website, all of which are of either a cat or a dog, and asks the user to select only the images of cats.

Image recognition is an inherently more difficult task for computers than character recognition; and the use of Petfinder's massive, and ever-changing, database of millions of images makes it seemingly impossible for spammers to attempt to beat the system via some shortcut. It should be noted, though, that some research exists showing that image-recognition software can beat Asirra at least 10% of the time. Still, Asirra may possibly be the most secure of the modules within ConfirmEdit. Or at least it was until late 2012, when it seemed that spammers might be starting to crack it.

Note: in order to use Asirra, you will need to download the latest/trunk version of ConfirmEdit.

Add the following to LocalSettings.php to enable this CAPTCHA:

In addition, you can add any of the following configuration parameters:
 * $wgAsirraEnlargedPosition: Can be one of top, bottom, left, right. Defaults to bottom.
 * $wgAsirraCellsPerRow</tt>: Number of images per row. Defaults to 6</tt>.
 * $wgAsirraScriptPath</tt>: If your extensions directory is outside the document root, or not accessible for any reason, you can set an alternative path to this module's JavaScript scripts here.

ReCaptcha
Этот модуль использует виджет и сервис "reCAPTCHA". Дополнительно к услуге CAPTCHA, он помогает оцифровать старые книги (подробнее о сервисе читайте здесь.)

Для использования этого модуля сперва перейдите по этой ссылке here и получите публичный и личный ключ для своей вики, который позволит серверу сервиса идентифицировать обращения.

Добавьте следующий фрагмент кода в файл LocalSettings.php, ниже  кода включения ConfirmEdit:


 * Recaptcha установлена в комплекте только с версией ConfirmEdit 1.18. Более ранние версии не имеют ReCaptcha php-файла в составе.
 * Unfortunately, as of 2011, some spammers appear to have figured out a way to bypass it, either through character recognition or by using humans. For that reason, it is not necessarily recommended.
 * Part of the weakness of the ReCaptcha module is that ConfirmEdit doesn't include any penalty mechanism, so spam bots can simply keep trying to bypass the CAPTCHA until they get through. This is an issue that is strongly worth addressing in some way.
 * Regardless of its strengths or weaknesses, ReCaptcha can't be implemented on Wikimedia wikis because it produces a third party dependency.

SimpleCaptcha (вычисление)
Эта CAPTCHA используется как основная в приложении. Она генерирует простой математический вопрос(сложение или вычитание), на который требуется ответить пользователю.

Добавьте следующие строки в файл LocalSettings.php в корневой папке вашей MediaWiki, чтобы сделать возможным использование этой капчи:

Note that the display of a trivial maths problem as plaintext yields a captcha which can be trivially solved by automated means; as of 2012, sites using SimpleCaptcha are receiving significant amounts of spam and many automated registrations of spurious new accounts. Wikis currently using this default setting should therefore migrate to VisualMathCaptcha or one of the other CAPTCHAs.

FancyCaptcha
This module displays a stylized image of a set of characters. The Python Imaging Library must be installed in order to create the set of images initially, but isn't needed after that.


 * 1) Add the following lines to LocalSettings.php</tt> in the root of your MediaWiki installation:
 * 2) In LocalSettings.php, set the variable $wgCaptchaDirectory</tt> to the directory where you will store Captcha images.  Below it set $wgCaptchaSecret</tt> to your passphrase.
 * 3) Create the images by running the following, where:
 * 4) * font is a path to some font, for instance AriBlk.TTF.
 * 5) * wordlist is a path to some word list, for instance /usr/share/dict/words. (Note: on Debian/Ubuntu, the 'wbritish' and 'wamerican' packages provide such lists. On Fedora, use the 'words' package).
 * 6) * key is the the exact passphrase you set $wgCaptchaSecret</tt> to. Use quotes if necessary.
 * 7) * output is the path to where the images should be stored (defined in $wgCaptchaDirectory</tt>).
 * 8) * count is how many images to generate.
 * 9) * An example, assuming you're in the extensions/ConfirmEdit directory (font location from Ubuntu 6.06, probably different on other operating systems):
 * 10) * If you are not satisfied with the results of the words you've generated you can simply remove the images and create a new set. Comic_Sans_MS_Bold.ttf seems to generate relatively legible words, and you could also edit the last line of captcha.py to increase the font size from the default of 40.
 * 11) Put the images you get into captcha directory in your installation
 * 12) Edit your wiki's LocalSettings.php: specify full path to your captcha directory in $wgCaptchaDirectory and secret key you've been using while generating captures in $wgCaptchaSecret
 * 1) * If you are not satisfied with the results of the words you've generated you can simply remove the images and create a new set. Comic_Sans_MS_Bold.ttf seems to generate relatively legible words, and you could also edit the last line of captcha.py to increase the font size from the default of 40.
 * 2) Put the images you get into captcha directory in your installation
 * 3) Edit your wiki's LocalSettings.php: specify full path to your captcha directory in $wgCaptchaDirectory and secret key you've been using while generating captures in $wgCaptchaSecret

See also Generating CAPTCHAs for how Wikimedia Foundation does it.

How to avoid common problems running Python
C:\python\python.exe C:\Ex\CAPTCHA.py --font C:\Ex\FONT.ttf --wordlist C:\Ex\LIST.txt --key=YOURPASSWORD --output C:\Ex\ --count=20
 * 1) Install the most recent version of Python Imaging Library (PIL).
 * 2) Make the installation of Python on a short folder name. Like C:\Python\
 * 3) Create a folder like C:\Ex and place files CAPTCHA.py / FONT.ttf / LIST.txt into the folder.
 * 4) To execute easily, run the following example as a batch file:

MathCaptcha

 * This requires the Math extension to be installed. Until MediaWiki 1.18 this was part of MediaWiki, later versions need to install it manually. See also Extension:Math

This module generates an image using TeX to ask a basic math question.

Set the following to enable this CAPTCHA:

See the readme file in the math folder to install this captcha.

VisualMathCaptcha
The extension VisualMathCaptcha can also be used, in conjunction with ConfirmEdit. See that extension's documentation for how to install and configure it.

Configuration
ConfirmEdit introduces a 'skipcaptcha' permission type to wgGroupPermissions. This lets you set certain groups to never see CAPTCHAs. All of the following can be added to localsettings.php.

Defaults from ConfirmEdit.php:

To skip captchas for users that confirmed their email, you need to both set:

There are five "triggers" on which CAPTCHAs can be displayed:
 * 'edit' - triggered on every attempted page save
 * 'create' - triggered on page creation
 * 'addurl' - triggered on a page save that would add one or more URLs to the page
 * 'createaccount' - triggered on creation of a new account
 * 'badlogin' - triggered on the next login attempt after a failed one. Requires $wgMainCacheType to be set to something other than CACHE_NONE</tt>.

The default values for these are:

The triggers,   and   can be configured per namespace using the   setting. If there is no  for the current namespace, the normal   apply. So suppose that in addition to the above  defaults we configure the following:

Then the CAPTCHA will not trigger when adding URLs to a talk page, but on the other hand user will need to solve a CAPTCHA any time they try to edit a page in the project namespace, even if they aren't adding a link.

A common alternate setting is to have a CAPTCHA only for unregistered users, on every edit. This can be accomplished by:

URL and IP whitelists
It is possible to define a whitelist of known "good" sites for which the CAPTCHA should not kick in, when the 'addurl' action is triggered.

Sysop users can do this by editing the system message page called MediaWiki:Captcha-addurl-whitelist. The expected format is a set of regex's one per line. Comments can be added with # prefix. You can see an example of this usage here, on OpenStreetMap.

This set of whitelist regexes can also be defined using the $wgCaptchaWhitelist config variable in LocalSettings.php, to keep the value(s) a secret.

Some other variables you can add to LocalSettings.php: These are described more thoroughly in the code comments
 * $wgCaptchaWhitelistIP - List of IP ranges to allow to skip the CAPTCHA
 * $ceAllowConfirmedEmail - Allow users who have confirmed their e-mail addresses to post URL links

Test plan
See ConfirmEdit Test Plan.

Authors
The basic framework was designed largely by Brion Vibber, who also wrote the SimpleCaptcha and FancyCaptcha modules. The Asirra module was written by Bachsau. The MathCaptcha module was written by Rob Church. The QuestyCaptcha module was written by Benjamin Lees. The reCAPTCHA module was written by Mike Crawford and Ben Maurer. Additional maintenance work was done by Yaron Koren.

См. также

 * Anti-spam features
 * Extension:SpamRegex
 * Extension:KittenAuth
 * Manual:$wgSpamRegex
 * Manual:Combating spam/ru