Last modified: 2012-12-25 01:25:47 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T44012, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 42012 - abusefilter-log-detail should not be restricted to sysops per default
abusefilter-log-detail should not be restricted to sysops per default
Status: RESOLVED FIXED
Product: Wikimedia
Classification: Unclassified
Site requests (Other open bugs)
wmf-deployment
All All
: Unprioritized normal (vote)
: ---
Assigned To: Nobody - You can work on this!
: shell
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2012-11-11 15:08 UTC by MF-Warburg
Modified: 2012-12-25 01:25 UTC (History)
6 users (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description MF-Warburg 2012-11-11 15:08:44 UTC
There is probably no "security" reason to restrict access to the detailed abuselog for non-sysops for filters which are not marked as private if enwiki, commons, mediawikiwiki, meta even grant this to *.

See Gerrit change #32681.
Comment 1 Nemo 2012-11-11 15:36:56 UTC
This change shouldn't affect the wiki which chose the current config on purpose, so either you browse all bugzilla requests or you should probably set the current config explicitly for all wikis which requested/got the abusefilter before it was enabled for all wikis.

Copying from the bug:
I personally agree with the change, but wikis may be relying on the defaults: wikis which didn't set it explicitly as it was the default will probably want to keep their current config. Almost surely the wikis which raised abusefilter-log from '*' to 'autoconfirmed' actually want abusefilter-log-detail to be at 'sysop' https://meta.wikimedia.org/wiki/Abuse_filter (example: itwiki), so you should probably check the configuration overrides they have and also their bugzilla requests.
Comment 2 MF-Warburg 2012-11-11 16:56:00 UTC
Ok, so, of all wikis whose abusefilter rights config differs from the default,

the following wikis grant abusefilter-log-detail to everyone:
-arwiki, elwiki, enwiki, eswiktionary itwikiquote, ltwiki, ltwiktionary, hewiki, hiwiki, metawiki, ruwiki, ruwikinews, rowiki, zh_yuewiki [Btw I notice that I need to correct my initial comment regarding commons and mediawikiwiki]

The following wikis grant it to autoconfirmed users:
-cawiki, dewiki, frwiki, mrwiki, nlwiki, ukwiki, zhwiki, ptwiki.

This leaves the following wikis which have specific abusefilter settings, which however do not concern granting this right to * or autoconfirmed:
-be_x_oldwiki, jawiki, frwiktionary, ruwikisource, commonswiki, hewiki, mlwiki, mlwiktionary, enwikisource, eswiki, itwiki, nowiki, plwiki, ptwiktionary, thwiki, eswikibooks, enwikibooks, eewiki, mediawikiwiki.

Would it in your opinion now be sufficient to notify these wikis for objections and/or set the current default setting explicitly for them?
Comment 3 Nemo 2012-11-11 17:07:57 UTC
(In reply to comment #2)
> Would it in your opinion now be sufficient to notify these wikis for objections
> and/or set the current default setting explicitly for them?

I'd suggest you to do the latter and only later, if you want, to contact them to suggest adopting the new default (opening a new bug or multiple bugs if there's consensus).

I think this bug should anyway be notified on [[m:Wikimedia Forum]], waiting a week or two for objections, before actually deploying the change.
Comment 4 MF-Warburg 2012-11-11 18:03:51 UTC
https://meta.wikimedia.org/wiki/Wikimedia_Forum#Abusefilter-log-detail

...and I uploaded a new patch set to exclude the mentioned wikis from this change.
Comment 5 Nemo 2012-11-20 08:05:06 UTC
The new proposal doesn't affect previous users (double-checking the patch is useful) and nobody opposed the idea for the default, so switching to 'shell'.
Comment 6 Robin Pepermans (SPQRobin) 2012-12-25 01:25:47 UTC
Closing this bug since Gerrit change #32681 was merged.

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links