431 posts
  • 7 Years of Membership
  • Affiliate Level 1
  • Australia
  • Beta Tester
+11 more
john
says

There’s been a forum thread or two around and a few support tickets mentioning that the follow an author link no longer works if you try and put it in a button in your item description or profile.

The short version: we’ve had to disable the link due to certain authors abusing it.

The long version (if you can be bothered):

The way we’d initially built the following system with Ajax didn’t follow security best practices. Usually when setting up a system like that you only allow the code on the other end of the URL to only accept POST requests. When you don’t you’re left with a bad situation where other people can trick you into visiting the URL and the action would be performed against your will. This blog post can give you a good overview of GET vs POST if you’re interested.

Anyways, by the time we’d figured out that we’d deployed something I’d describe as “not ideal” (perhaps a bit generous) it’d started being used in author profiles and item descriptions in a nice way, and no one was taking advantage of the security hole, so we decided to sit back and watch.

Unfortunately, some people started to abuse the feature and set things up to trap users into following them, and so we’ve had to disable the accidental feature we had.

In the longer term we’re hoping to build a little follow widget code you can put into item descriptions, but for right now we’re stuck in a nasty spot where we’re short staffed and can’t build the cool new feature to make up for it, but can’t leave a security hole wide open either when people know about it. Sorry we had to turn this off, and a bigger sorry for not actually writing this notice sooner (instead of waiting for complaints to come in), and hopefully we can do something nice for you all soon to make up for it.

756 posts All things are possible, for one who believes.
  • Weekly Top Seller
  • Elite Author
  • Canada
  • Author Level 11
+11 more
TimMcMorris
says

Hm. Well I hope at least the problem authors were completely banned.

Looking forward to editing the item pages for my entire portfolio.

6231 posts
  • Exclusive Author
  • Elite Author
  • Author Level 8
  • 7 Years of Membership
+13 more
VF
says

I remember in the past, after visiting some author’s profile and item ads, I was added to their follower list unintentionally. Observed it for more than an year with confusion.

2505 posts Small, but tough
  • Affiliate Level 7
  • Author Level 8
  • Beta Tester
  • Collector Level 4
+13 more
EFEKT_Studio
says

Looking forward to editing the item pages for my entire portfolio.

+1

1368 posts
  • Weekly Top Seller
  • 5 Years of Membership
  • Author Level 6
  • Beta Tester
+5 more
Smartik
says

Maybe an idea would be to create an additional button on the sale page beside the “View Portfolio” ?

3724 posts Community Moderator
  • Affiliate Level 8
  • Author Level 6
  • Bundle Boss
  • Collector Level 4
+9 more
quickandeasy
says

any chance you can redirect the url to take you to the users profile?

Just so all those links that are now spread around the site can be utilized :)

2505 posts Small, but tough
  • Affiliate Level 7
  • Author Level 8
  • Beta Tester
  • Collector Level 4
+13 more
EFEKT_Studio
says

any chance you can redirect the url to take you to the uses profile? Just so all those links that are now spread around the site can be utilized :)

Great idea.

179 posts
  • Author Level 10
  • Collector Level 4
  • Top Monthly Author
  • Trendsetter
+6 more
MNKY
says

Have already redirected links to profile page, but would be great to have this announcement on Dashboard for everyone to notice.

1313 posts
  • Affiliate Level 5
  • Author Level 7
  • Beta Tester
  • Collector Level 4
+10 more
LGLab
says

any chance you can redirect the url to take you to the users profile? Just so all those links that are now spread around the site can be utilized :)

+1 :-)

1665 posts
  • Trendsetter
  • Weekly Top Seller
  • Winner
  • Featured Author
+10 more
flashedge
says

Wait a minute. When you made this function you reccomended authors to build follow buttons and now it’s suddenly a bad thing? Do we have to remove our buttons now?

There are honest authors here, who didn’t trick anyone.

by
by
by
by
by
by