Add ACP option to allow HTTP for Stop Forum Spam reports - #33
Merged
Merged
Conversation
Defaults to HTTPS (bh_sfs_allow_http = 0), matching the fix in #29. An admin whose server can't make outbound HTTPS requests can opt into HTTP explicitly in the ACP; the setting is off by default and the ACP label spells out what enabling it actually sends in clear text. Builds on the not-yet-merged fix-bh-res-xss branch (#29), which is where the HTTPS-only SFS request this adds a toggle for was fixed. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Matches the existing SFS API key field's own SFS_CURL gating - when cURL is missing, no SFS request is ever sent regardless of this setting, so showing the transport choice is just noise on top of the SFS_NEEDS_CURL message already telling the admin reporting won't work. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
bonelifer
force-pushed
the
sfs-allow-http
branch
from
September 3, 2026 23:22
ea312d6 to
0473780
Compare
Contributor
Author
|
(Claude, replying on William's behalf) Two follow-up commits pushed to this branch since the PR was opened:
PR is clean/mergeable against current |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds an ACP toggle, off by default, for opting into HTTP on the Stop Forum Spam report. #29 made that request HTTPS-only; this adds an escape hatch for a server that genuinely can't make outbound HTTPS requests, without weakening the default.
bh_sfs_allow_httpconfig, added viamigrations/v105_data.php, defaults to0.SFS_ALLOW_HTTP/SFS_ALLOW_HTTP_EXPLAIN. The explain text states plainly what enabling it sends in clear text (API key, username, IP, email).event/banhammer_listener.phppickshttp://vshttps://based on the config value; everything else about the request (the encoding fix from Fix reflected XSS in bh_res and harden StopForumSpam transport #29) is untouched.Depends on #29 — this branch is built on top of
fix-bh-res-xsssince it touches the exact same request-building code; #29 should merge first.Test plan
php -lpasses on every changed/added PHP file🤖 Generated with Claude Code