Last modified: 2013-09-05 17:03:14 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T47019, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 45019 - Checkuser API does not use tokens
Checkuser API does not use tokens
Status: RESOLVED FIXED
Product: MediaWiki extensions
Classification: Unclassified
CheckUser (Other open bugs)
master
All All
: Unprioritized minor (vote)
: ---
Assigned To: Alex Monk
: patch, patch-need-review
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2013-02-14 21:45 UTC by Alex Monk
Modified: 2013-09-05 17:03 UTC (History)
10 users (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments
Add token requirement to Checkuser API (1.09 KB, patch)
2013-03-20 19:12 UTC, Alex Monk
Details
Add token requirement to Checkuser API (953 bytes, patch)
2013-07-04 00:02 UTC, Alex Monk
Details

Description Alex Monk 2013-02-14 21:45:00 UTC
Doesn't leak information, but could be used to have the user perform sensitive write actions unknowingly if I understand correctly.
Comment 1 Alex Monk 2013-03-20 19:12:27 UTC
Created attachment 11962 [details]
Add token requirement to Checkuser API
Comment 2 Alex Monk 2013-07-04 00:02:42 UTC
Created attachment 12745 [details]
Add token requirement to Checkuser API
Comment 3 Chris Steipp 2013-08-26 20:16:10 UTC
Tested and working well so far. I'll deploy this and we'll release it with 1.21.2.
Comment 4 Chris Steipp 2013-08-28 18:38:41 UTC
Deployed
18:37 logmsgbot: csteipp synchronized php-1.22wmf13/extensions/CheckUser
18:36 logmsgbot: csteipp synchronized php-1.22wmf14/extensions/CheckUser
Comment 5 Chris Steipp 2013-09-05 17:03:14 UTC
This was assigned CVE-2013-4306

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links