So far I think this is not a security issue (see below) but definitely welcomes more investigation hence playing safe here and filing as a Sec task.
CC'ing @hoo who pinged me in a private message on IRC.
@hoo: If you could provide a specific example that would be georgeous!
- Go to https://phabricator.wikimedia.org/P2621 or https://phabricator.wikimedia.org/P2624 (if you're not their author)
- Get "Access Denied: Restricted File. You do not have permission to view this object."
- Go to https://phabricator.wikimedia.org/paste/
- See "P2621 SPARQL: Films that won most Academy Awards" listed and the content of its first five lines.
- Mention "P2621" on #wikimedia-tech
- Get: <stashbot> P2621 SPARQL: Films that won most Academy Awards - https://phabricator.wikimedia.org/P2621
Testing with P2629 which only @Aklapper and two other users can access, https://phabricator.wikimedia.org/paste/ lists P2629 when being logged in as @Aklapper, but it does not list P2629 when being logged in with my private account @Malyacko. Hence I hope there is just some misconfiguration.