[Security] Consolidate domain
Users can login on the below URLs: https://vrchat.com/home/ https://www.vrchat.com/home/ https://vrchat.net/home/ https://www.vrchat.net/home/ https://api.vrchat.cloud/home/ This situation: • confuses browser’s password manager • contributes to users setting low security password • contributes to phishing scams
Incorrect tooltip title on voice-off/mute button for friend request card
Incoming friend request cards have voice-off/mute and block self-moderation buttons included but the voice-off/mute self-mod button has an incorrect HTML title value "Block" causing a mouse-over event to show the text "Block" instead of "Mute" or something else.
No SSL support on help.vrchat.com
help.vrchat.com is supposed to be the point of contact for reporting players if the in-game (self-)moderation and user reporting features aren't enough, but the site doesn't support SSL, so confidential information can't and detailed logs should not be provided there. Upon visiting the website, browsers complain that the certificate is only valid for *.happyfox.com and when accepting the risk to visit the website anyways, you're being presented an nginx 404 error page.
Not long after you log in, the site is logout problem
Refreshing the site, Problems logout in less than 10 seconds, cases
It's unclear how to log in to the support website
After submitting a ticket at help.vrchat.com/new, the message "Your ticket has been created and you can login to track your ticket status" appears. However, there's no login link from the help site, and no ticket information on the main logged-in vrchat website.
Autofocus 2FA field when logging in on the site
Make the website autofocus on 2FA field when logging in to make the login process smoother
Friend filter is too exact
- When searching through the friends list to find someone it expects an exact match or no results are shown. This is a problem in general but a specific use case example is if a friend has the prefix 'The' in their name, you can't find them unless you start the search with 'the' even though you may only know the rest of their name when trying to find them. - The same as above where you can't do a partial filter, you can't search with spaces. if it was partially matching the filter to a name I would expect the filter to be able to omit the spaces and just match the text to text found in a name - Searching for a friend that has a space in their name fails in the friend filter if you search without any spaces but succeeds in the main search bar at the top. It will also fail to find the friend if you type the words in the wrong order whereas it appears succeed in the main user search.
remove naughty word enum from front end
This should not be done on the front end, this should be done entirely on the back end as the content is served to you from the api. This approach may work well for the game client, but all you need to do is open the debugger to see the full list of bad words and other things that get filtered. This list should not be user accessible by any means. Edit: I've been told that filtering does happen on the back end, if this is the case, this list should not exist anywhere on the front end.
Specific user profile not found by user search
The user https://vrchat.com/home/user/usr_615a4795-c8e3-478e-8e78-82fa6abca194 does not appear to be in the website user search index. I've tried searching for "phio.alchemist", "動く城のフィオ", and "phio". While the "phio.alchemist" search finds plenty of alchemists, as well as a "phio.alchemist2", and the "phio" search finds some other phios, none of these searches return the user linked above. However, searching for 動く城のフィオ does find their worlds, from which the user profile is linked.