Skip to content

Comments

[#8906] Prevent on-site citations#8907

Open
garethrees wants to merge 1 commit intodevelopfrom
8906-prevent-on-site-citations
Open

[#8906] Prevent on-site citations#8907
garethrees wants to merge 1 commit intodevelopfrom
8906-prevent-on-site-citations

Conversation

@garethrees
Copy link
Member

We've seen a few cases where Citations have been added where the source_url is a link to the Alaveteli site.

  • In a few cases the requester has added a Citation linking to the request the citation was added to
  • A user included a confirmation URL, which when followed logged you in to their account
  • In one case a user legitimately added a citation to another request, where the request was based on a previous response

In most cases citations are intended to be more about external sources that link to the platform.

Fixes #8906.

Screenshot 2025-10-02 at 12 25 47

Notes to reviewer

Do we have a helper instead of using the full AlaveteliConfiguration.domain call? Don't think its worth adding just for this, but if we've got something shorter I'll push a fixup.

@garethrees garethrees changed the title Prevent on-site citations [#8906] Prevent on-site citations Oct 2, 2025
@garethrees garethrees force-pushed the 8906-prevent-on-site-citations branch from 82b5eb7 to 1cb0a91 Compare October 2, 2025 11:29
@gbp gbp added the on-staging label Oct 8, 2025
We've seen a few cases where Citations have been added where the
source_url is a link to the Alaveteli site.

* In a few cases the requester has added a Citation linking to the
  request the citation was added to
* A user included a confirmation URL, which when followed logged you in
  to their account
* In one case a user legitimately added a citation to another request,
  where the request was based on a previous response

In most cases citations are intended to be more about external sources
that link to the platform.

Fixes #8906.
@garethrees garethrees force-pushed the 8906-prevent-on-site-citations branch from b10848f to d272ddf Compare January 6, 2026 12:43
@garethrees garethrees marked this pull request as ready for review January 6, 2026 12:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Prevent on-site Citations

2 participants