SECURITY: Flow security fix to make sure EnableFlow is always attributed

classic Classic list List threaded Threaded
3 messages Options
Reply | Threaded
Open this post in threaded view
|

SECURITY: Flow security fix to make sure EnableFlow is always attributed

Matthew Flaschen-2
There is a security fix to ensure that EnableFlow is always properly
attributed.

This may be an issue if you see users maliciously using
Special:EnableFlow on pages that already exist.

It should be merged shortly, but in the meantime, you can download it
from Gerrit (https://gerrit.wikimedia.org/r/#/c/333301/):

git fetch ssh://gerrit.wikimedia.org:29418/mediawiki/extensions/Flow
refs/changes/01/333301/1 && git checkout FETCH_HEAD

Matt Flaschen

_______________________________________________
Wikitech-l mailing list
[hidden email]
https://lists.wikimedia.org/mailman/listinfo/wikitech-l
Reply | Threaded
Open this post in threaded view
|

Re: SECURITY: Flow security fix to make sure EnableFlow is always attributed

Matthew Flaschen-2
On 01/20/2017 05:02 PM, Matthew Flaschen wrote:
> There is a security fix to ensure that EnableFlow is always properly
> attributed.
>
> This may be an issue if you see users maliciously using
> Special:EnableFlow on pages that already exist.

To clarify, the page already existing is fine.  It's just that users
were sometimes converting to Flow when it was not appropriate to do so.

Matt

_______________________________________________
Wikitech-l mailing list
[hidden email]
https://lists.wikimedia.org/mailman/listinfo/wikitech-l
Reply | Threaded
Open this post in threaded view
|

Re: SECURITY: Flow security fix to make sure EnableFlow is always attributed

Matthew Flaschen-2
In reply to this post by Matthew Flaschen-2
On 01/20/2017 05:02 PM, Matthew Flaschen wrote:
> There is a security fix to ensure that EnableFlow is always properly
> attributed.

Backports have been merged for 1.26, 1.27, and 1.28.

However, please note that MW 1.26 is end-of-life, and we are not
supporting either MW 1.26 or Flow 1.26.

Matt Flaschen

_______________________________________________
Wikitech-l mailing list
[hidden email]
https://lists.wikimedia.org/mailman/listinfo/wikitech-l