Uploaded image for project: 'phpBB3'
  1. phpBB3
  2. PHPBB3-9680

Enforcing Accountability

    XMLWordPrintable

Details

    • Improvement
    • Status: Closed (View Workflow)
    • Minor
    • Resolution: Invalid
    • 3.1.0-dev
    • 3.1.0-a1
    • ACP
    • None

    Description

      Currently users have the ability to clear logs, which removes them from the database. I suggest that they be withheld for a certain amount of time (2 weeks or so, or maybe even configurable) and simply hidden from the logs section of the administration panel. The cron could check and remove entries up to the last purge when they become old enough for removal. The feature will of course need to be reworded to reflect the changes.

      My reasoning for this is mainly for incident purposes. If a user gains access through weak credentials (ie. only forum access and not server access), they often purge the logs. Many shared hosts do not configure their logs for monthly storage and toss them at the end of the day, and users do not often get reports in before that.

      There really isn't a reason to need to purge one's accountability, and some countries may require it (I believe Austria's Data Protection Act requires 3 year storage). For those worried about space, I don't think they will require that much (as opposed to all of those posts), but a cron purge can keep it maintained.

      Attachments

        Activity

          People

            Unassigned Unassigned
            Noxwizard Patrick Webster
            Votes:
            1 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: