Page MenuHomePhabricator

Showing Commons 3D file on a local Wikpedia file page results into a warning "...malicious code"
Closed, ResolvedPublic

Description

https://de.wikipedia.org/wiki/Datei:Asad_Al-Lat.stl shows "Warning: This file type may contain malicious code. By executing it, your system may be compromised."

Event Timeline

Restricted Application added a subscriber: Aklapper. · View Herald Transcript
Ramsey-WMF triaged this task as High priority.
Ramsey-WMF moved this task from Untriaged to Next up on the Multimedia board.

Should we enable 3D everywhere, so other wikis are able to display such files? (but don't enable uploads everywhere?)

Should we enable 3D everywhere, so other wikis are able to display such files? (but don't enable uploads everywhere?)

Sounds good to me. Would this be the solution to show a thumbnail in Wikipedia pages too? Like in https://de.wikipedia.org/wiki/Benutzer:Raymond/test

Yeah, that'd also take care of that.

Change 410432 had a related patch set uploaded (by Matthias Mullie; owner: Matthias Mullie):
[mediawiki/extensions/3D@master] MMV is not a hard dependency

https://gerrit.wikimedia.org/r/410432

Change 410433 had a related patch set uploaded (by Matthias Mullie; owner: Matthias Mullie):
[operations/mediawiki-config@master] Load 3D extension on other wikis, for display only

https://gerrit.wikimedia.org/r/410433

Change 410432 merged by jenkins-bot:
[mediawiki/extensions/3D@master] MMV is not a hard dependency

https://gerrit.wikimedia.org/r/410432

Change 410433 merged by jenkins-bot:
[operations/mediawiki-config@master] Load 3D extension on other wikis, for display only

https://gerrit.wikimedia.org/r/410433

Change 413373 had a related patch set uploaded (by Matthias Mullie; owner: Matthias Mullie):
[mediawiki/extensions/3D@wmf/1.31.0-wmf.21] MMV is not a hard dependency

https://gerrit.wikimedia.org/r/413373

Change 413373 merged by jenkins-bot:
[mediawiki/extensions/3D@wmf/1.31.0-wmf.21] MMV is not a hard dependency

https://gerrit.wikimedia.org/r/413373

This has been deployed.
Existing embeds may not work until the cache gets refreshed, but I believe I just purged all of them.