Last modified: 2013-04-22 16:16:47 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T45137, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 43137 - The API should not return the SHA1 for revisions with the DELETED_TEXT attribute
The API should not return the SHA1 for revisions with the DELETED_TEXT attribute
Status: RESOLVED FIXED
Product: MediaWiki
Classification: Unclassified
API (Other open bugs)
1.21.x
All All
: Normal normal (vote)
: ---
Assigned To: Alex Monk
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2012-12-14 20:27 UTC by orlodrim
Modified: 2013-04-22 16:16 UTC (History)
7 users (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description orlodrim 2012-12-14 20:27:01 UTC
Querying the API with action=query&prop=revisions&rvprop=sha1 returns the SHA1 even for revisions whose content is hidden, for any user.

Example: http://fr.wikipedia.org/w/api.php?action=query&prop=revisions&revids=86537049&rvprop=content|sha1|comment

I think this should not be the case: a revision might be hidden because of a very short string (first name of the contributor, phone number...). In this case it is possible to recover the hidden content from the SHA1 and the text of the next revision.
Comment 1 Alex Monk 2012-12-14 22:45:34 UTC
Gerrit change #38802
Comment 2 Umherirrender 2012-12-21 14:08:59 UTC
successfully merged

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links