Extension:ConfirmEdit/ja

ConfirmEdit拡張機能を使うと、さまざまなCAPTCHA技術を使って、スパムボットなどの自動編集ツールによるウィキの編集を防いだり、パスワードを推測しようとする自動ログインを無効化したりすることができます.

ConfirmEditはキャプチャを生成するためいくつかの技術やモジュールが同梱されてます.

これらのモジュールの中には、追加の設定作業が必要なものがあります.


 * MathCaptcha requires both the presence of TeX and, for versions of MediaWiki after 1.17, the extension;
 * FancyCaptchaは、Pythonで予備設定スクリプトを実行する必要があります.

欠点
CAPTCHA は、利便性を低下させ、人間の利用者にとっては不便です.

また、ボットに対して100％有効というわけではなく、CAPTCHAを突破するために人手を使うことを厭わないスパマーからWikiを守ることはできません. ConfirmEditは、他のアンチスパム機能と組み合わせて使用することも可能です. どのようなソリューションを使うにしても、公開可能なWikiを持っているならば、「最近の更新」を常に監視することが重要です.

インストール


CAPTCHAの種類
ConfirmEditに含まれるCAPTCHAの種類は多数あります.

QuestyCaptcha
このモジュールは、質問を提示し、利用者がその答えを提供するものです. 設定にある質問を提示します. このモジュールは、スパムボットに対して強力なメカニズムを提供することが証明されています. また、テキスト形式の問題は音声合成ソフトで読み上げることができるため、視覚障害者（ボットではなく）が正しく回答できるという、より良いアクセシビリティの利点もあります. このCAPTCHAを有効にするために、Q&Aを編集している に以下を追加してください.

入力された問題の中から、ランダムに出題されます.

最低でも1つは必要です.
 * QuestyCaptchaは大文字と小文字を区別しません. 答えが「Paris」で利用者が「paris」と書いても、答えが「paris」で利用者が「Paris」と書いても、動作は同じです.
 * 答えに「ó」のような特殊文字がある場合、念のため「ó」入りの答えとそうでない答えを書いてもかまいません. 例えば、答えが「canción」であり、利用者が「cancion」を入力する場合は、 を使用できます.
 * あなたのウィキでインストールしても人間が推測することは簡単です. しかし、自動のプログラムでは難しいです. 理想では、質問のテキストに含まれるべきではありません. キャプチャヘルプメッセージを編集して、そこにキャプチャレスポンスの解決策を提供してみてください.
 * Just change the questions when/if they start proving ineffective; this may never happen if your wiki is not specifically targeted.
 * Don't ever reuse questions already used by you or others in the past: spambots are known to remember a question and its answer forever once they broke it.
 * You can even dynamically generate questy captchas in the configuration. DO NOT use an exact copy of the dynamic questions from the link, they've been cracked by spammers. However, other dynamic questions in the style of the questions presented are highly effective.
 * There is a separate extension to ConfirmEdit called QuestyCaptchaEditor which provides an on-wiki special page for managing QuestyCaptcha question+answer(s) pairings. You may wish to consider installing it if it's desirable to reduce sysadmin intervention when it comes to managing the CAPTCHA questions and their answers.

ReCaptcha (NoCaptcha)
The new generation of ReCaptcha, called NoCaptcha, was introduced by Google back in December 2014 and reduces the need for humans to solve a CAPTCHA. Based on a user-side JavaScript (which can't be controlled by the user the administrator), reCaptcha tries to identify the site user as a human by analyzing their browsing behavior on the page. The user then has to click an "I'm not a robot" checkbox and (in the best case) doesn't have to do anything further to prove they're a human. However, in some cases, the user still has to solve a CAPTCHA image.

This module implements the new ReCaptcha NoCaptcha solution in ConfirmEdit.

You still need a public and a secret key (which you can retrieve from the ReCaptcha admin panel – change v2, v3 not work) and install the plugin with:

There is an additional configuration option for this module, (default: ), which, if set to, sends the IP address of the current user to a server from Google while verifying the CAPTCHA. You can improve the privacy for your users if you keep this set to. However, remember, that this module adds a client side JavaScript code, directly loaded from a server from Google, which already can collect the IP address of the user (combined with other data, too) and can not be limited by a configuration option. This will only work on standard MediaWiki editor.

reCAPTCHA v3
Currently there is no official way to implement version 3 of Google reCAPTCHA.



SimpleCaptcha (計算)
This is the default CAPTCHA.

This module provides a simple addition or subtraction question for the user.

Add the following lines to  in the root of your MediaWiki to enable this CAPTCHA:

Note that the display of a trivial maths problem as plaintext yields a captcha which can be trivially solved by automated means; as of 2012, sites using SimpleCaptcha are receiving significant amounts of spam and many automated registrations of spurious new accounts. Wikis currently using this as the default should therefore migrate to one of the other CAPTCHAs.

FancyCaptcha
This module displays a stylized image of a set of characters.

Pillow must be installed in order to create the set of images initially, but isn't needed after that (can be installed with  in most environments).


 * 1) Add the following lines to   in the root of your MediaWiki installation:
 * 2) In , set the variable  to the directory where you will store Captcha images. Below it set  to your passphrase.
 * 3) Create the images by running the following:
 * 4) * where font is a path to some font, for instance AriBlk.TTF.
 * 5) * wordlist is a path to some word list, for instance . ( Note: on Debian/Ubuntu, the 'wbritish' and 'wamerican' packages provide such lists. On Fedora, use the 'words' package )
 * 6) * key is the exact passphrase you set to. Use quotes if necessary.
 * 7) * output is the path to where the images should be stored (defined in ).
 * 8) * count is how many images to generate.
 * 9) * An example, assuming you're in the  directory (font location from Ubuntu 6.06, probably different on other operating systems):
 * 10) * If you are not satisfied with the results of the words you've generated you can simply remove the images and create a new set. Comic_Sans_MS_Bold.ttf seems to generate relatively legible words, and you could also edit the last line of captcha.py to increase the font size from the default of 40.
 * 11) Put the images you get into   directory in your installation.
 * 12) Edit your wiki's : specify full path to your captcha directory in  and secret key you've been using while generating captures in.
 * 1) * If you are not satisfied with the results of the words you've generated you can simply remove the images and create a new set. Comic_Sans_MS_Bold.ttf seems to generate relatively legible words, and you could also edit the last line of captcha.py to increase the font size from the default of 40.
 * 2) Put the images you get into   directory in your installation.
 * 3) Edit your wiki's : specify full path to your captcha directory in  and secret key you've been using while generating captures in.

See also Generating CAPTCHAs for how Wikimedia Foundation does it.


 * How to avoid common problems running Python on Windows


 * 1) Install the most recent version of Pillow.
 * 2) Make the installation of Python on a short folder name, like C:\Python\
 * 3) Create a folder like C:\Ex and place files CAPTCHA.py / FONT.ttf / LIST.txt into the folder.
 * 4) To execute easily, run the following example as a batch file:

 C:\python\python.exe C:\Ex\CAPTCHA.py --font C:\Ex\FONT.ttf --wordlist C:\Ex\LIST.txt --key=YOURPASSWORD --output C:\Ex\ --count=20

MathCaptcha
This module generates an image using TeX to ask a basic math question.

Set the following to enable this CAPTCHA: See the  file in the math folder to install this captcha.

hCaptcha
See https://www.hcaptcha.com/

The configuration is similar to ReCaptcha: is also available.

Don't require CAPTCHA from some users
ConfirmEdit introduces a  permission type to. This lets you set certain groups to never see CAPTCHAs. All of the following can be added to. Defaults from : To skip captchas for users that confirmed their email, you need to set both:

Set actions that require CAPTCHA
The following conditions can trigger a CAPTCHA to be displayed:
 * 'edit' - triggered on every attempted page save
 * 'create' - triggered on page creation
 * 'sendemail' - triggered when using Special:Emailuser
 * 'addurl' - triggered on a page save that would add one or more URLs to the page
 * 'createaccount' - triggered on creation of a new account
 * 'badlogin' - triggered after several failed login attempts from the same IP address
 * 'badloginperuser' - triggered after several failed login attempts using the same username

The default values for these are:

The triggers,   and   can be configured per namespace using the  setting. If there is no for the current namespace, the normal  apply. So suppose that in addition to the above defaults we configure the following:

Then the CAPTCHA will not trigger when adding URLs to a talk page, but on the other hand user will need to solve a CAPTCHA any time they try to edit a page in the project namespace, even if they aren't adding a link.

URL and IP whitelists
It is possible to define a whitelist of known good sites for which the CAPTCHA should not kick in, when the  action is triggered.

Sysop users can do this by editing the system message page called MediaWiki:Captcha-addurl-whitelist.

The expected format is a set of regex's one per line.

Comments can be added with  prefix.

You can see an example of this usage on OpenStreetMap.

This set of whitelist regexes can also be defined using the config variable in , to keep the value(s) a secret.

Some other variables you can add to : These are described more thoroughly in the code comments
 * $wgCaptchaWhitelistIP - List of IP ranges to allow to skip the CAPTCHA (you can also use MediaWiki:Captcha-ip-whitelist; see below for details).
 * $ceAllowConfirmedEmail - Allow users who have confirmed their e-mail addresses to post URL links

MediaWiki:Captcha-ip-whitelist can be used to change the whitelisted IP addresses and IP ranges on wiki.

They should be separated by newlines.

If any other character (apart from a valid IP address or range) is found on a line, it will be ignored but leading and trailing whitespace characters are allowed.

For example, a line with only  is considered valid but   will be ignored.



正規表現
The global variable wgCaptchaRegexes accepts an array of regexes to be tested against the page text and will trigger the CAPTCHA in case of a match.

Failed login attempts
When using the  or   triggers, the following configuration variables control how many failed login attempts per-IP and per-user are allowed before a CAPTCHA is required, and how long it takes until the CAPTCHA requirement expires:

The triggers require to be set to something other than   in your , if in doubt the following will always work.

Note that these triggers not trigger CAPTCHAs on API login, but instead block them outright until the CAPTCHA requirement expires.

Wikimedia configuration
For example, wikis use FancyCaptcha with a custom set of images and the default configuration, modified by what follows. This means only unregistered and newly registered users have to pass the CAPTCHA.

EmergencyCaptcha mode
Additionally the shortcut named is designed for use in a limited number of emergency situations, for instance in case of massive vandalism or spam attacks: it changes the default trigger values (see above) into the following: So all anonymous and new users have to solve a CAPTCHA also before being able to save an edit or create a new page, in addition to the normal situation.

速度制限
ConfirmEdit は false CAPTCHA のレート リミットをサポートしています.

の詳細情報とセットアップ方法は を参照してください. 操作キーは  です.

作者
基本的なフレームワークは、主にBrion Vibberが設計し、SimpleCaptchaとFancyCaptchaのモジュールも書きました.

MathCaptchaはRob Churchによって書かれました.

QuestyCaptchaはBenjamin Leesによって書かれました.

追加整備はYaron Korenにより行われました.

脚注
