Page MenuHomePhabricator

Security review for InterwikiSorting Extension
Closed, ResolvedPublic

Description

Project Information

Description of the tool/project

An extension to provide inter language link sorting on all projects.
This is currently done by the Wikibase extension (and the InterwikiSorting extension has simply been factored out)

Description of how the tool will be used at WMF

The extension will be deployed to all sites (that Wikibase is installed on)

Dependencies

List dependencies, or upstream projects that this project relies on

None

Has this project been reviewed before?

please link to tasks or wiki pages of previous reviews

Only regular CR

Working test environment

please link or describe setup process for setting up a test environment

This extension is currently working along side the Cognate extension in this Labs test environment (which you can be given access to)

http://enwiktionary-cognate.wmflabs.org
http://dewiktionary-cognate.wmflabs.org
http://frwiktionary-cognate.wmflabs.org

Simply install as a regular mediawiki extension and configure.

Post-deployment

name of team responsible for tool/project after deployment and primary contact

WMDE / Wikidata / @Lydia_Pintscher

Related Objects

StatusAssignedTask
OpenNone
OpenNone
OpenNone
OpenNone
OpenNone
ResolvedLydia_Pintscher
ResolvedLydia_Pintscher
OpenNone
ResolvedLydia_Pintscher
ResolvedLydia_Pintscher
ResolvedLydia_Pintscher
ResolvedLydia_Pintscher
ResolvedLydia_Pintscher
ResolvedLydia_Pintscher
Resolvedaude
Resolved Addshore
Resolved Addshore
Resolved Addshore
ResolvedBawolff
Resolvedaude
ResolvedNone
OpenNone

Event Timeline

Restricted Application added a subscriber: Aklapper. · View Herald TranscriptOct 25 2016, 11:06 AM
Addshore moved this task from Unsorted 💣 to Active 🚁 on the User-Addshore board.
Addshore moved this task from Active 🚁 to Watching 👀 on the User-Addshore board.

I should not here in theory the deployment of this would be a noop, as this code is already running as part of WikibaseClient.
Some config needs to be adjusted (new names for config vars) but that is about it.

Legoktm added a subscriber: Legoktm.Nov 3 2016, 7:33 PM

Is there a task tracking the deployment of this extension to Wikimedia production?

aude added a subscriber: Reedy.Nov 28 2016, 2:18 PM
aude added a subscriber: aude.
Bawolff closed this task as Resolved.Jan 16 2017, 11:16 PM
Bawolff claimed this task.
Bawolff moved this task from Scheduled to Awaiting remediation on the Security-Team-Reviews board.
Bawolff added a subscriber: Bawolff.

Security review of InterwikiSorting revision 7d48e09104136 (Jan 3, 2017)

Extension looks good. One small (non-security) comment:

  • In InterwikiSorter.php code comment references a doc file which doesn't seem to exist: @see Documentation of "sort" and "interwikiSortOrders" options in docs/options.wiki.
  • In InterwikiSorter.php code comment references a doc file which doesn't seem to exist: @see Documentation of "sort" and "interwikiSortOrders" options in docs/options.wiki.

Doc removed in https://gerrit.wikimedia.org/r/#/c/332886/

Tobi_WMDE_SW moved this task from Done to Demoed on the WMDE-QWERTY-Team board.