Warn token in attachments before sending message
Currently, Discord warms when a user tries to send a text message that contains a Discord authentication token, but not when the user uploads a file containing the token as an attachment.
This behavior can be produced in the browser and the Windows app:
- Paste a bot or a user token to a text channel and press Enter.
- Discord pops up a box asking if the user really wants to send it. Click "Edit Message" and clear the message content.
- Save the token as a text file or within a JSON/Python file. Upload the file as the attachment of a message and press Enter.
- Discord sends the message and the attachment without warming. The attachment containing the token can be viewed and downloaded by all members of the channel.
I submit this feedback because I recently sent a JSON file containing my user token accidentally, which I overlooked until 2-3 days later. I have changed my password. I think if Discord detects and warns about authentication tokens in message contents, it should also warn tokens within attachments because source files are often uploaded as attachments.
請登入寫評論。
評論
0 條評論