Page MenuHomePhabricator

Sysops can unprotect/delete pages they cant edit
Closed, ResolvedPublic


Author: fearow00

When you have a higher-than-sysop protection level (i.e. bureaucrat or siteadmin) on a page, sysops can still unprotect that page or delete and recreate to edit. All actions should be blocked on a page, without having to add extra actions to protect against (protect, unprotect, delete, etc)

Version: 1.12.x
Severity: enhancement



Event Timeline

bzimport raised the priority of this task from to Medium.Nov 21 2014, 9:59 PM
bzimport set Reference to bz11346.
bzimport added a subscriber: Unknown Object (MLST).

fearow00 wrote:

I can provide a link to where this is - also, I cant add protect, unprotect, delete, etc to the protected actions as it doesnt apply. Weird.