Last modified: 2014-01-14 16:41:54 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T61789, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 59789 - CirrusSearch: See if we can get the ip address of the requester into the logs and into Elasticsearch
CirrusSearch: See if we can get the ip address of the requester into the logs...
Status: RESOLVED FIXED
Product: MediaWiki extensions
Classification: Unclassified
CirrusSearch (Other open bugs)
unspecified
All All
: High normal (vote)
: ---
Assigned To: Nik Everett
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2014-01-07 20:26 UTC by Nik Everett
Modified: 2014-01-14 16:41 UTC (History)
5 users (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description Nik Everett 2014-01-07 20:26:48 UTC
See if we can get the ip address of the requester into the logs and into Elasticsearch.
Comment 1 Nik Everett 2014-01-07 20:27:25 UTC
We want this in case we figure out that someone is intentionally issuing queries that are really really nasty.
Comment 2 Gerrit Notification Bot 2014-01-08 21:27:46 UTC
Change 106430 had a related patch set uploaded by Manybubbles:
Add the user to Cirrus logs

https://gerrit.wikimedia.org/r/106430
Comment 3 Kunal Mehta (Legoktm) 2014-01-09 04:11:58 UTC
Are there any privacy policy-related issues that need to be considered for this?

I note that the patch is just logging the user's username (or IP if anonymous), but the bug specifically says IP address.
Comment 4 Sam Reed (reedy) 2014-01-09 04:27:51 UTC
(In reply to comment #3)
> Are there any privacy policy-related issues that need to be considered for
> this?
> 
> I note that the patch is just logging the user's username (or IP if
> anonymous),
> but the bug specifically says IP address.

I guess it'd be we can only keep the data for 3 months (same for other "sensitive" data such as IPs we keep around)
Comment 5 Chad H. 2014-01-09 04:47:38 UTC
I think we're over-logging here...we should only log when bad/slow things happen, not on every single search.

Anyway, I left more detailed comments on the change.
Comment 6 Gerrit Notification Bot 2014-01-14 16:39:33 UTC
Change 106430 merged by jenkins-bot:
Split request logs out from debug logs

https://gerrit.wikimedia.org/r/106430
Comment 7 Nik Everett 2014-01-14 16:41:54 UTC
So this gets properly immortalized: we're only capturing the requester information on requests that take an egregious amount of time.

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links