Change the API a little bit for users only maybe? #3416
-
I wanted to do a discussion regarding API, and came here instead of https://dis.gd/feedback, because on feedback it might end up somewhere, where it will never be seen or take a long time until it gets seen by atleast someone. So, not sure how many know about the issue with "spam bots" or "scam bots", well basically user bots that join servers DM users phishing stuff. That's the issue. Now, these user bots can access the API and let's say a server puts members in a place that can't see other verified members. What the user bot can do, is to get a list of all members on the server. And I think that's maybe a little bit too much information that is accessed for a user. Since the client doesn't see everyone on the member list, but only those that they have access to in the channels they see. But maybe there are a few more things that a user token shouldn't be able to access but a bot token should, and maybe it should be changed for the user token. So that they still work with Discord, but don't have stuff that they don't need. Now, I'm not sure but I guess, just changing that the user can't fetch everyone in the server requires Discord to probably change how things work, so it may not be a good solution. It also may not be a good solution, because a normal user can just join and get all the IDs and give them to the user bot and then it just opens a DM with everyone. Maybe a user on Discord shouldn't be able to open a DM with someone, if the user ID is not cached. But I'm not sure if that will help in a way, because maybe it is really easy to cache a user without requiring any access to something. |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment
-
This won’t be changed - we won’t make the product worse to fight spam when when still have ways of fighting it in different avenues |
Beta Was this translation helpful? Give feedback.
This won’t be changed - we won’t make the product worse to fight spam when when still have ways of fighting it in different avenues