Last modified: 2012-04-09 08:42:53 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T36714, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 34714 - Templates used in edit summaries are expanded in e-mail notifications
Templates used in edit summaries are expanded in e-mail notifications
Status: RESOLVED DUPLICATE of bug 35019
Product: MediaWiki
Classification: Unclassified
Email (Other open bugs)
unspecified
All All
: Normal major (vote)
: ---
Assigned To: Nobody - You can work on this!
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2012-02-25 20:18 UTC by MZMcBride
Modified: 2012-04-09 08:42 UTC (History)
4 users (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description MZMcBride 2012-02-25 20:18:55 UTC
If a user causes a e-mail notification (by editing another user's talk page, for example) and the edit summary used contains a template ("{{foo}}", for example), the template will be expanded in the notification e-mail.

A snippet from a recent e-mail notification from the English Wikipedia where the edit summary originally contained "{{User page}} (get rid of it if you want). Consider it to be a suggestion.":

---
The Wikipedia page "User talk:MZMcBride" has been changed on
25 February 2012 by 7&6=thirteen, with the edit summary: <table
class="plainlinks ombox  
ombox-notice " style="margin-left: 0; margin-right: 0; border:1px solid
#ffc9c9; background-color: #fffff3;">
<tr>
<td class="mbox-empty-cell"></td>
<td class="mbox-text" style="font-size: 85%; text-align: center">
---

I played around with https://test.wikipedia.org/wiki/Template:ENotif_expansion_test to see if you could fool an e-mail client into using the wrong subject line. It seems my e-mail client (Microsoft Entourage) is smart enough to not be fooled, at least.

Between the unsanitized HTML and the ability to insert header lookalikes, this feels very dirty. I haven't yet been able to exploit this template expansion with my e-mail client, but I'm not so sure I trust other e-mail clients (cf. bug 25231) to behave reasonably.

There's no real point in the template expansion of the edit summaries, as far as I can tell. I think it should be removed, though this may upset people if they've been relying on the behavior as a hack of some kind.
Comment 1 Nemo 2012-02-28 08:55:18 UTC
This is definitely a bug, which I didn't notice before (?).
Confirmed in 1.19wmf1, as I've just received a notification for https://www.mediawiki.org/w/index.php?title=MediaWiki_1.19%2FRoadmap&diff=504610&oldid=503855 with 

Editor's summary: /* Deployment schedule */ [[File:Yes_check.svg|15px|
]] '''Done'''
Comment 2 Nemo 2012-03-30 11:46:52 UTC
This can get very annoying... http://p.defau.lt/?Ya2vgKhfPdC9ypCLmeb_Vw
Comment 3 Alexandre Emsenhuber [IAlex] 2012-04-09 08:42:53 UTC

*** This bug has been marked as a duplicate of bug 35019 ***

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links