Subject | Repo | Branch | Lines +/- | |
---|---|---|---|---|
Enable anonymous cookie blocking | operations/mediawiki-config | master | +1 -3 |
Details
Status | Subtype | Assigned | Task | ||
---|---|---|---|---|---|
Open | None | T52039 Proposed changes to default settings (tracking) | |||
Resolved | dmaza | T191922 Enable $wgCookieSetOnIpBlock by default after the IP cookie block feature is fully tested and released | |||
Declined | None | T233597 Refactor ApiMain to use OutputPage::sendCacheControl | |||
Resolved | dbarratt | T196575 Add block cookie for browser-based API edits (including VisualEditor & MobileFrontend) | |||
Resolved | • TBolliger | T120734 Epic ⚡️ Improve MediaWiki's blocking tools | |||
Resolved | dmaza | T152462 Add cookie when blocking anonymous users | |||
Resolved | dbarratt | T192017 Enable anon cookie blocking on all Wikimedia wikis |
Event Timeline
It looks like the limited release in T196121: Enable set cookie with IP/IP-Range blocks when blocking logged-out users on itwiki is not causing any problems and we can proceed with this task. The numbers in Graphite look reasonable and I found no reports of unexpected blocking problems on Italian Wikipedia's major discussion locations (Talk:Main Page, Information desk, Oracle, Bar, or their talk page for blocking policies.)
Let's take this into our next sprint!
Before you move forward with this, could you please make sure legal updates the cookie statement accordingly? There was information about the block cookie in the old template that was shown, but that is no longer being used. I emailed them about this but haven't heard back.
As you may know, some admins in the EU are worried they could theoretically be sued for issuing a cookie by blocking someone. I don't think this is something you or them should worry about (because it's the software that issues the cookie, not the admin), but the cookie statement should be reflected to reduce worries.
Thank, you @MusikAnimal for reminding me — it's probably good to triple check with Legal. If I remember correctly Legal already signed-off on releasing this without adjusting the cookie policy because this type of cookie is used for site stability, not for monetization.
If you sent a recent email to them, could you please CC me into the thread?
Change 444246 had a related patch set uploaded (by Dbarratt; owner: Dbarratt):
[operations/mediawiki-config@master] Enable anonymous cookie blocking
Deployment has been added to the schedule:
https://wikitech.wikimedia.org/wiki/Deployments#deploycal-item-20180711T2300
Change 444246 merged by jenkins-bot:
[operations/mediawiki-config@master] Enable anonymous cookie blocking
Mentioned in SAL (#wikimedia-operations) [2018-07-11T23:17:46Z] <thcipriani@deploy1001> Synchronized wmf-config/InitialiseSettings.php: SWAT: [[gerrit:444246|Enable anonymous cookie blocking]] T192017 (duration: 00m 58s)