Last modified: 2014-10-19 17:52:29 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T62616, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 60616 - Annotations from anonymous users can't be edited/deleted
Annotations from anonymous users can't be edited/deleted
Status: PATCH_TO_REVIEW
Product: MediaWiki extensions
Classification: Unclassified
Annotator (Other open bugs)
unspecified
All All
: Low normal (vote)
: ---
Assigned To: Nobody - You can work on this!
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2014-01-30 11:23 UTC by Gabriel Birke
Modified: 2014-10-19 17:52 UTC (History)
4 users (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description Gabriel Birke 2014-01-30 11:23:00 UTC
Annotations from anonymous users are stored with user id 0. However, the code for updating/deleting annotations checks for user id identity so even logged in users can only edit their own comments. This could result in undeleteable, uneditable  offensive comments all over the wiki.

My proposal for this would be new permissions named "updateannotation" and "deleteannotation" assigned to the sysop user by default. These permissions would allow to bypass the "only update/delete your own annotation" restriction.
Comment 1 Matthew Flaschen 2014-01-31 05:49:26 UTC
I think this makes sense.  It fits the general naming convention (e.g. editusercss vs. editmyusercss).

Related note, until bug 52156 is fixed, there is no history or undeletion (which are quite important on a wiki).
Comment 2 Gerrit Notification Bot 2014-02-03 10:04:06 UTC
Change 110932 had a related patch set uploaded by Chiborg:
New permissions for update/delete of annotations

https://gerrit.wikimedia.org/r/110932

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links