forked from xsf/xeps
-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathxep-0377.xml
357 lines (347 loc) · 12.8 KB
/
xep-0377.xml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
<?xml version='1.0' encoding='UTF-8'?>
<!DOCTYPE xep SYSTEM 'xep.dtd' [
<!ENTITY % ents SYSTEM 'xep.ent'>
%ents;
]>
<?xml-stylesheet type='text/xsl' href='xep.xsl'?>
<xep>
<header>
<title>Spam Reporting</title>
<abstract>
This document specifies a mechanism by which users can report spam and other
abuse to a server operator or other spam service.
</abstract>
&LEGALNOTICE;
<number>0377</number>
<status>Experimental</status>
<type>Standards Track</type>
<sig>Standards</sig>
<approver>Council</approver>
<dependencies>
<spec>XMPP Core</spec>
<spec>XMPP IM</spec>
<spec>XEP-0191</spec>
</dependencies>
<supersedes/>
<supersededby/>
<shortname>NOT_YET_ASSIGNED</shortname>
&sam;
<revision>
<version>0.3.1</version>
<date>2023-04-03</date>
<initials>egp</initials>
<remark><p>Add XML Schema.</p></remark>
</revision>
<revision>
<version>0.3</version>
<date>2021-06-21</date>
<initials>ssw</initials>
<remark>Rework based on list feedback.</remark>
</revision>
<revision>
<version>0.2</version>
<date>2017-09-11</date>
<initials>XEP Editor (jwi)</initials>
<remark>Defer due to lack of activity.</remark>
</revision>
<revision>
<version>0.1.0</version>
<date>2016-05-25</date>
<initials>ssw</initials>
<remark><p>Initial version approved by the Council.</p></remark>
</revision>
<revision>
<version>0.0.1</version>
<date>2016-05-21</date>
<initials>ssw</initials>
<remark><p>First draft.</p></remark>
</revision>
</header>
<section1 topic='Introduction' anchor='intro'>
<p>
Many spam and abuse prevention techniques rely on users being able to report
other users who are sending unwanted messages, or specific instances of
abuse.
&xep0191; allows users to block spammers, but does not provide a mechanism
for them to report a reason for the block to the server operator.
This specification extends the blocking command to optionally provide an
abuse report.
</p>
</section1>
<section1 topic='Background' anchor='background'>
<p>
This document extends the blocking command instead of providing a separate
reporting IQ because we hypothesize that this will slightly lower the levels
of false reports received by service operators.
We have observed a common pattern on the internet where a user becomes mad
at or disagrees with another user and begins harassing them by replying to
or reporting their every comment even if it is not itself spam or abusive.
However, this sort of behavior cannot continue if the harasser can no longer
read the messages of the person they are stalking.
Giving them a choice between their abusive behavior and being able to
read their targets can possibly force them to break the cycle and only
create valid reports.
</p>
</section1>
<section1 topic='Discovering Support' anchor='disco'>
<p>
Entities that support &xep0030; and abuse reporting using the blocking
command as defined in this spec MUST respond to service discovery requests
with a feature of 'urn:xmpp:reporting:1'.
Support for this namespace also indicates support for the abuse reporting
reasons defined in this document.
For example, a response from a server that supports reporting and
understands the abuse and spam reasons defined later in this specification
might look like the following:
</p>
<example caption="Service discovery information response"><![CDATA[
<iq from='example.net'
id='ku6e51v3'
to='[email protected]/castle'
type='result'>
<query xmlns='http://jabber.org/protocol/disco#info'>
<feature var='urn:xmpp:reporting:1'/>
…
</query>
</iq>]]></example>
</section1>
<section1 topic='Payload' anchor='payload'>
<p>
The payload for reporting abuse to the server takes the form of a
<report/> qualified by the 'urn:xmpp:reporting:1' namespace &VNOTE;.
</p>
<example caption='The most basic report payload'><![CDATA[
<report xmlns="urn:xmpp:reporting:1" reason="urn:xmpp:reporting:spam"/>]]></example>
<p>
Abuse reports MUST include a reason for the report in the "reason" attribute.
</p>
<p>
This document defines the following reasons for a report:
</p>
<dl>
<di>
<dt>urn:xmpp:reporting:spam</dt>
<dd>Used for reporting a JID that is sending unwanted messages.</dd>
</di>
<di>
<dt>urn:xmpp:reporting:abuse</dt>
<dd>Used for reporting general abuse.</dd>
</di>
</dl>
<p>
Reports MAY contain a user provided message explaining or providing context
about the reason for the report.
See also the <link url='#i18n'>Internationalization Considerations</link>
section of this document.
</p>
<example caption='Report with optional reason and text'><![CDATA[
<report xmlns="urn:xmpp:reporting:1" reason="urn:xmpp:reporting:spam">
<text xml:lang="en">
Never came trouble to my house like this.
</text>
</report>]]></example>
</section1>
<section1 topic='Use with the Blocking Command' anchor='blocking'>
<p>
To send a report, a report payload MAY be inserted into an <item/>
node sent as part of a request to block a spammer as defined in &xep0191;.
For example:
</p>
<example caption='Report sent with blocking command'><![CDATA[
<iq from='[email protected]/chamber' type='set' id='block1'>
<block xmlns='urn:xmpp:blocking'>
<item jid='[email protected]'>
<report xmlns="urn:xmpp:reporting:1" reason="urn:xmpp:reporting:abuse"/>
</item>
</block>
</iq>]]></example>
<p>
Servers that receive a blocking command with a report MUST block the JID or
return an error just as they would if no report were present.
Servers then MAY take other actions based on the report, however, such
actions are outside the scope of this document.
</p>
<p>
If the server supports &xep0313; the report MAY also include the stanza-id
of specific messages being reported.
This is done by including copies of each <stanza-id/> element that the
user wishes to report as a child of the <report/> element.
The stanza indicated by the provided stanza-id SHOULD be by the same JID
being reported and blocked.
</p>
<example caption='Report sent with stanza IDs'><![CDATA[
<iq from='[email protected]/chamber' type='set' id='block1'>
<block xmlns='urn:xmpp:blocking'>
<item jid='[email protected]'>
<report xmlns="urn:xmpp:reporting:1" reason="urn:xmpp:reporting:spam">
<stanza-id xmlns='urn:xmpp:sid:0' by='[email protected]' id='28482-98726-73623'/>
<stanza-id xmlns='urn:xmpp:sid:0' by='[email protected]' id='38383-38018-18385'/>
<text xml:lang="en">
Never came trouble to my house like this.
</text>
</report>
</item>
</block>
</iq>]]></example>
</section1>
<section1 topic='Implementation Notes' anchor='impl'>
<p>
Clients that support sending reports as part of the blocking command SHOULD
expose interfaces to both block a JID without reporting it as abuse, and to
block and report a JID.
</p>
<p>
The blocking command may be used to block multiple JIDs at the same time.
When blocking multiple JIDs any abuse report only applies to a single JID.
If the client allows selecting multiple JIDs in an abuse reporting dialog
they SHOULD also allow choosing a separate reason, text, and messages for
each JID.
They MAY choose to only allow reporting a single JID at a time as well when
the "block and report" dialog is accessed, and multiple JIDs when the
"block" dialog is accessed.
</p>
</section1>
<section1 topic='Internationalization Considerations' anchor='i18n'>
<p>
If one or more <text/> elements are present they SHOULD include
'xml:lang' attributes specifying the natural language of the XML character
data.
</p>
</section1>
<section1 topic='Security Considerations' anchor='security'>
<p>
This document introduces no additional security considerations above and
beyond those defined in the documents on which it depends.
</p>
</section1>
<section1 topic='IANA Considerations' anchor='iana'>
<p>This document requires no interaction with &IANA;.</p>
</section1>
<section1 topic='XMPP Registrar Considerations' anchor='registrar'>
<section2 topic='Protocol Namespaces' anchor='registrar-ns'>
<p>This specification defines the following XML namespace:</p>
<ul>
<li>urn:xmpp:reporting:1</li>
</ul>
<p>
Upon advancement of this specification from a status of Experimental to
a status of Draft, the ®ISTRAR; shall add the foregoing namespace to
the registry located at &DISCOFEATURES;, as described in Section 4 of
&xep0053;.
</p>
</section2>
<section2 topic='Namespace Versioning' anchor='registrar-versioning'>
&NSVER;
</section2>
<section2 topic='Abuse Reporting Registry' anchor='registrar-reporting'>
<p>
The XMPP Registrar shall maintain a registry of abuse report reasons.
All abuse report reason registrations shall be defined in separate
specifications (not in this document). Application types defined within
the XEP series MUST be registered with the XMPP Registrar, resulting in
protocol URNs representing the reason.
</p>
®PROCESS;
<code>
<![CDATA[<reason>
<name>The human-readable name of the abuse report reason.</name>
<feature>URN representing the reason.</feature>
<desc>A natural-language summary of the reason.</desc>
<doc>
The document in which the report reason is specified.
</doc>
</reason>]]></code>
</section2>
<section2 topic='Abuse Reporting Reasons' anchor='registrar-reasons'>
<p>This specification defines the following abuse reporting reasons:</p>
<ul>
<li>urn:xmpp:reporting:spam</li>
<li>urn:xmpp:reporting:abuse</li>
</ul>
<p>
Upon advancement of this specification from a status of Experimental to
a status of Draft, the ®ISTRAR; shall add the following definition to
the abuse reporting reasons registry, as described in this document:
</p>
<code><![CDATA[
<reason>
<name>spam</name>
<feature>urn:xmpp:reporting:spam</feature>
<desc>Used to report a JID that was sending spam messages.</desc>
<doc>XEP-0377</doc>
</reason>]]></code>
<code><![CDATA[
<reason>
<name>abuse</name>
<feature>urn:xmpp:reporting:abuse</feature>
<desc>Used to report general abuse that is not covered by a more specific reason.</desc>
<doc>XEP-0377</doc>
</reason>]]></code>
</section2>
</section1>
<section1 topic='XML Schema' anchor='schema'>
<code><![CDATA[
<?xml version='1.0' encoding='UTF-8'?>
<xs:schema
xmlns:xs='http://www.w3.org/2001/XMLSchema'
xmlns:sid='urn:xmpp:sid:0'
xmlns='urn:xmpp:reporting:1'
targetNamespace='urn:xmpp:reporting:1'
elementFormDefault='qualified'>
<xs:annotation>
<xs:documentation>
The protocol documented by this schema is defined in
XEP-0377: https://xmpp.org/extensions/xep-0377.html
</xs:documentation>
</xs:annotation>
<xs:import namespace='http://www.w3.org/XML/1998/namespace'
schemaLocation='https://www.w3.org/2009/01/xml.xsd'/>
<xs:import namespace='urn:xmpp:sid:0'
schemaLocation='xep-0359.xsd'/>
<xs:element name='container'>
<xs:complexType>
<xs:sequence>
<xs:element ref='report' minOccurs='0' maxOccurs='unbounded'/>
</xs:sequence>
</xs:complexType>
</xs:element>
<xs:element name='report'>
<xs:complexType>
<xs:sequence>
<xs:element ref='sid:stanza-id' minOccurs='0' maxOccurs='unbounded'/>
<xs:element ref='text' minOccurs='0' maxOccurs='unbounded'/>
</xs:sequence>
<xs:attribute name='reason' type='xs:string' use='required'/>
</xs:complexType>
</xs:element>
<xs:element name='spam' type='empty'/>
<xs:element name='abuse' type='empty'/>
<xs:element name='text'>
<xs:complexType>
<xs:simpleContent>
<xs:extension base='xs:string'>
<xs:attribute ref="xml:lang" use="optional"/>
</xs:extension>
</xs:simpleContent>
</xs:complexType>
</xs:element>
<xs:simpleType name='empty'>
<xs:restriction base='xs:string'>
<xs:enumeration value=''/>
</xs:restriction>
</xs:simpleType>
</xs:schema>]]></code>
</section1>
<section1 topic='Acknowledgements' anchor='acknowledgements'>
<p>
Thanks to the participants of the XMPP Summit 20 in Austin, TX who
discussed this XEP: specifically to Waqas Hussain, Kevin Smith, Lance
Stout, and Matthew Wild. A special thanks to Daniel Wisnewski for giving
the presentation that kicked off the anti-abuse work.
</p>
<p>
Thanks also (in no particular order) to Jonas Wielicki, Georg Lukas,
Daniel Gultsch, and Matthew Wild for their feedback.
</p>
</section1>
</xep>