Last modified: 2014-05-27 18:38:08 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T64561, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 62561 - Non-admins are able to see the title and edit summary of posts that are within deleted topics in Flow
Non-admins are able to see the title and edit summary of posts that are withi...
Status: NEW
Product: MediaWiki extensions
Classification: Unclassified
Flow (Other open bugs)
unspecified
All All
: Normal normal (vote)
: ---
Assigned To: Nobody - You can work on this!
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2014-03-12 05:13 UTC by Glaisher
Modified: 2014-05-27 18:38 UTC (History)
6 users (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description Glaisher 2014-03-12 05:13:38 UTC
See [[mw:Special:Contributions/93.182.159.63]]

While it makes sense that sysops should be able to see the contents of deleted topics, it doesn't make much sense that other users are able to see the contents of deleted posts in Flow as this doesn't happen with the current system. This is also visible in Special:RecentChanges. The following shows what can be seen from RecentChanges.

* Talk:Sandbox; 03:06 . . (+187)‎ . . 93.182.159.63 (talk) commented on This topic was deleted by Glaisher ( <-- spam contents of the post here --> ).

This how it should appear in RecentChanges, imo. http://www.mediawiki.org/w/index.php?title=Special%3ALog&type=delete&user=&page=Talk%3AFlow+QA 

See also [[mw:Special:Contributions/93.182.133.139]]
Comment 1 Maryana Pinchuk 2014-03-12 19:11:39 UTC
This behavior in Flow is modeled on how regular Mediawiki page deletion works now. See this screenshot of English Wikipedia's recent changes: http://imgur.com/LwZyEpj. The last entry is a page deletion action, and you can see the title of the page even as a logged out user – so if the title were spam, you'd be seeing spam in recent changes/contributions as a non-admin.

Of course, it doesn't *have* to work like this - but we've found that when we try to show things different in rc/contribs/etc., people complain that it doesn't work as expected :)
Comment 2 Quiddity 2014-03-12 20:12:09 UTC
(In reply to Maryana Pinchuk from comment #1)
> This behavior in Flow is modeled on how regular Mediawiki page deletion
> works now. See this screenshot of English Wikipedia's recent changes:
> http://imgur.com/LwZyEpj. The last entry is a page deletion action, and you
> can see the title of the page even as a logged out user – so if the title
> were spam, you'd be seeing spam in recent changes/contributions as a
> non-admin.
> 

Not quite. In your screenshot, we can't see who edited the page that was deleted, nor any of their edit summaries.

Longer explanation:
In regular MediaWiki page deletions, the individual page edits are removed from public view, and only the final page-deletion action is visible to all.

eg. http://i.imgur.com/ivZVvRI.png - Here, #1) User:Derklion makes 2 edits to a page, then in #2) User:Quiddity deletes that page, which removes Derklion's contributions entirely from public view (both RC and Contribs), and places them into the "Deleted user contributions" feed. 

See http://i.imgur.com/QzLAC2t.png for #1) Derklion edits #2) Quiddity deletes the page which hides those edits #3) those 2 edits are now only visible in "deleted user contributions".

(Hopefully that's explained clearly. And our apologies for the imgur links, to those that hate them ;)
Comment 3 Maryana Pinchuk 2014-03-13 17:55:39 UTC
Quiddity - right, that's why I said "modeled on," not "identical to" ;) 

Flow actions are fundamentally different from page edit actions, so they come with extra meta-data that may or may not contain inappropriate material. However, my point stands that if the root issue here is "I think it's bad that some non-admins might see spam/inappropriate words/etc. in contribs or recent changes," then that's no different from the current system today, because deleted page titles can include spam, personal attacks, etc., and are visible to users without admin rights.

Anyway, since we're moving to a more granular revdel-like system of deletion and suppression in the next sprint, I trust the local admins to make the call whether a Flow action and its associated meta-data needs to be deleted or deleted & suppressed.

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links