Last modified: 2012-02-08 01:02:49 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T35392, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 33392 - Users without abusefilter-modify-restricted can remove restricted actions
Users without abusefilter-modify-restricted can remove restricted actions
Status: RESOLVED FIXED
Product: MediaWiki extensions
Classification: Unclassified
AbuseFilter (Other open bugs)
unspecified
All All
: Normal normal (vote)
: ---
Assigned To: Nobody - You can work on this!
: patch, patch-need-review
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2011-12-28 00:39 UTC by Nikola Kovacs
Modified: 2012-02-08 01:02 UTC (History)
3 users (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments
Proposed patch (956 bytes, patch)
2011-12-28 00:39 UTC, Nikola Kovacs
Details

Description Nikola Kovacs 2011-12-28 00:39:28 UTC
Created attachment 9770 [details]
Proposed patch

Users who do not have abusefilter-modify-restricted can remove all the restricted actions from a filter, and then they'll be able to modify it. The code only checks if the new version that's about to be saved has restricted actions, which prevents unprivileged users from adding them, but not removing them. I've attached a patch that also checks if the previous version of the filter had restricted actions.
Comment 1 Andrew Garrett 2012-01-15 02:35:50 UTC
Looks okay to me, still need to test/apply it.
Comment 2 Andrew Garrett 2012-02-08 01:02:49 UTC
Applied in r110906, with some minor style changes.

Thanks for submitting this patch.

Marking RESOLVED FIXED.

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links