- Review the extension for code safety
- Review features for effectiveness with core permissions
Description
Description
Status | Subtype | Assigned | Task | ||
---|---|---|---|---|---|
Declined | None | T95954 Deploy Extension:Lockdown to the cluster and enable on OTRS Wiki | |||
Declined | None | T299546 Install Lockdown in zhwiki | |||
Declined | None | T126481 Security review of Extension:Lockdown |
Event Timeline
Comment Actions
marking stalled, pending how discussion goes on T95954 since we might not want to install this extension after all.
Comment Actions
No response on the other bug. Marking declined. Please feel free to reopen when/if this needs a security review for deployment
Overall, I would prefer to have wikis be either all private or all public. If we need partial readability, I would prefer simple solutions like whitelists. MediaWiki is a complex application that overall is not designed for fine grained access controls, so having fine grained access controls implemented in extensions increases the risk of information disclosure significantly.