Last modified: 2012-12-12 16:11:49 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T44777, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 42777 - ApiRemoveClaims must check write mode, tokens
ApiRemoveClaims must check write mode, tokens
Status: VERIFIED FIXED
Product: MediaWiki extensions
Classification: Unclassified
WikidataRepo (Other open bugs)
unspecified
All All
: Unprioritized critical (vote)
: ---
Assigned To: Jeroen De Dauw
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2012-12-06 13:47 UTC by Daniel Kinzler
Modified: 2012-12-12 16:11 UTC (History)
5 users (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description Daniel Kinzler 2012-12-06 13:47:11 UTC
ApiRemoveClaims currently modifies and saves entity data directly, without any checks. It should use EditEntity to perform token and permission checks. It should also implement isWriteMode(), needsToken(), and mustBePosted() to return true.
Comment 1 Daniel Kinzler 2012-12-11 10:52:55 UTC
merged:
Change I33d76687: Use EditEntity in removeclaims and added token requirement
Comment 2 abraham.taherivand 2012-12-12 16:11:49 UTC
Verified in Wikidata demo sprint 26

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links