Showing posts with label script. Show all posts
Showing posts with label script. Show all posts

Sunday, August 9, 2015

Removing rogue members from your Plone site

I recently had one of my Plone sites get hit by a "join form attack". Basically a spam bot which started adding new members to my site (we don't use a captcha at the moment). I ended up with far more members in the site than members of the organization. I started deleting them manually using the Zope Management Interface > acl_users > source_users, but that became tedious quickly. So I wrote a command-line script to do the job for me.

In my case the spambot wasn't super smart, all the usernames created by the bot started with capital letters. All my real users had usernames with common letters. This made it easy to filter out the bad guys.

Here's my script in a nutshell:
.
.

I used the special --object-path option to indicate the location of my Plone site, relative to the root of the Zope application server.

My final command looked something like this:

bin/instance_debug --object-path='pathto/sitein/zodb/plone' run member_cleanup.py > members_cleanup_report.txt

The resulting output went to a members_cleanup_report.txt.

Many thanks to the plone.api and plone.docs teams, being able to make use of plone.api.user made it 20 times easier to write the script.

A note about transactions

Before my script would run successfully I had to add a transaction.commit() line, it seems commandline scripts require this.

Parting thoughts

There's a lot more that can be added to the script to make it smarter. For example for certain kinds of sites you could filter based on whether the user has created any content or perhaps it might be based on log in patterns, if they have never logged in or only logged in once.

I'm weighing the pros and cons of having a captcha. At the moment members can't do much except change their portrait pictures and profiles, but I know that some spammers use the portrait for hosting "bad" images, so captchas may have to be introduced.

References

The resources I used included the following references:

http://docs.plone.org/external/plone.api/docs/api/user.html
http://docs.plone.org/develop/plone/misc/commandline.html#scripting-context
https://pypi.python.org/pypi/plone.recipe.zope2instance

Wednesday, May 15, 2013

Bulk adding of users to a Plone site (TTW)

This is a quick way to add new users to a Plone site, very useful in a pinch but probably not very robust (so I make no guarantees). It might possibly serve as the pattern for a "user importer", assuming someone hasn't invented one already.

Everything is done through the web (TTW) using the Zope Management Interface (ZMI), so you'll need to be an administrator.


Add the following script to your Plone instance and give the script a name, I called mine 'addusers'.

out = []
acl_users = context.acl_users
for item in container.temp:
    person = item.split(',') username = person[0]
    password = person[1]
    try:
         acl_users.userFolderAddUser(username,password,['trainee'],'')
    except ValueError, msg:
        out.append("Skipped %s, reason: %s" % (username, msg))
    else:
        out.append("Success with %s" % username)
return out

Note: the use of the role 'trainee' in my example, the role MUST exist for this to work. Also for the Python purists, that "hanging" return statement is perfectly fine, TTW Python scripts run inside Zope and return the output to your browser. If it absolutely bothers you, you can leave it out.

Under the ZMI > properties' add a 'lines' field called 'temp' it should include the usernames and passwords of the newusers (no spaces after the commas)

The 'temp' lines field should look like this:
Maurice,dttrrrsffd
Natalie,55542yylrw
Herman,d5rrrrr6tfdsa
Ryan,r4rffd243faz
Patrick,e443rereew
Sean,erserwrew
Michael,4343243qw
Running the 'addusers' script will now create the users with the passwords that you defined.

Update: July 1, 2013

There are a couple other tools mentioned in the comments of this post which you may also want to look at.
https://pypi.python.org/pypi/atreal.usersinout/

http://plone.org/products/collective.mass_subscriptions - can send out initial passwords in bulk

https://pypi.python.org/pypi/collective.loremipsum - generates fake content and fake users

Tuesday, May 3, 2011

Quick TTW Contenttype Conversion Script

This is a basic working example of a through-the-web (TTW) Plone script that converts one content type into another, in this case I'm converting all News Items to Press Releases. This assumes that you are using the PressRoom add-on on your site.

I gave the script the name: convert_news_to_pressrelease

I've posted the script here:
https://gist.github.com/953299

To use the script, add a new script via the Zope Management Interface (ZMI) of your site:

And paste the content of https://gist.github.com/953299 there.

It should now be possible to append 'convert_news_to_pressrelease' to any container that has news items and they will 'magically' become press releases.

Sign up for my upcoming Plone 5 Book & Video tutorials

plone 5 for newbies book and videos