view mod_report_affiliations/traits.lib.lua @ 6165:e977174082ee

mod_invites_register_api: Use set_password() for password resets Previously the code relied on the (weird) behaviour of create_user(), which would update the password for a user account if it already existed. This has several issues, and we plan to deprecate this behaviour of create_user(). The larger issue is that this route does not trigger the user-password-changed event, which can be a security problem. For example, it did not disconnect existing user sessions (this occurs in mod_c2s in response to the event). Switching to set_password() is the right thing to do
author Matthew Wild <mwild1@gmail.com>
date Thu, 06 Feb 2025 10:24:30 +0000
parents e905ef16efb7
children
line wrap: on
line source

local known_traits = {};

local function trait_added(event)
	local trait = event.item;
	local name = trait.name;
	if known_traits[name] then return; end

	known_traits[name] = trait.probabilities;
end

local function trait_removed(event)
	local trait = event.item;
	known_traits[trait.name] = nil;
end

module:handle_items("account-trait", trait_added, trait_removed);

local function bayes_probability(prior, prob_given_true, prob_given_false)
	local numerator = prob_given_true * prior;
	local denominator = numerator + prob_given_false * (1 - prior);
	return numerator / denominator;
end

local function prob_is_bad(traits, prior)
	prior = prior or 0.50;

	for trait, state in pairs(traits) do
		local probabilities = known_traits[trait];
		if probabilities then
			if state then
				prior = bayes_probability(
					prior,
					probabilities.prob_bad_true,
					probabilities.prob_bad_false
				);
			else
				prior = bayes_probability(
					prior,
					1 - probabilities.prob_bad_true,
					1 - probabilities.prob_bad_false
				);
			end
		end
	end

	return prior;
end

local function get_probability_bad(username, prior)
	local user_traits = {};
	module:fire_event("get-account-traits", { username = username, host = module.host, traits = user_traits });
	local result = prob_is_bad(user_traits, prior);
	return result;
end

return {
	get_probability_bad = get_probability_bad;
};