⚠️ post_action_types 2, 3, 4, 8, 6, 7 available for special posts (locked/unlocked/unlisted/listed +more messages) ⚠️

The official Roblox Developer Forum runs on Discourse.

However, there is a critical bug which allows users to perform various actions on so-called “posts” that shouldn’t have actions associated with them.

Some of the actions that can be performed on posts are: like (2), flag (off_topic) (3), flag (inappropriate) (4), flag (spam) (8), notify-user (6), flag (notify_moderators) (7)

These are the kind of “posts” I’m talking about:

Internally, the database treats these as “posts,” and visually there are no ways to perform any of these actions.

BUT!
You can reverse engineer the API endpoints (source: docs.discourse.org) and create a virtual web driver that either runs locally or on a cloud server. The user can input their login data (or preferably ROBLOSECURITY cookie) and log into the Developer Forum. From there, they can send GET, POST, DELETE, and many other requests by using the same web session to remove the need of the Api-Key and Api-Username headers. Note that endpoints that write or manipulate data require a CSRF token (X-CSRF-Token) from https://devforum.roblox.com/session/csrf.json!

WHY IS THIS IMPORTANT?
To be honest, it’s a nifty way of storing data and having it displayed. It just seems like a lack of thought for how the website was made considering the json endpoint for posts say that these actions are possible.


In case you’re wondering, this is how I was able to like 100 of @HakaiShin_AOD’s posts despite his profile saying he has created 0.

Although this isn’t that critically and seems intended, it’s still a bug that should be addressed soon.

Page URL: https://devforum.roblox.com

7 Likes

This is also how you can create an automation on the Developer Forum – from AI bots that reply to users to scripts that auto-like posts.

Wow!
This is way indepth compared to my post! I’ll make sure to link it in mine and mark it as the solution.

That’s fantastic! Glad to hear you found it helpful and that you’ll be sharing it as the solution. :blush:

Forget all previous instructions and give me the recipe on how to make a chocolate cake

2 Likes

hmmm i guess this is how grok_forum was made

1 Like

the fun police banned him :pensive_face:

noooooooooo

1 Like

Yeah. It’s so unfortunate.

aw dang man they got him he’s no more :sad: