Page MenuHomePhabricator

"Administrator" is hardcoded in various permission error messages
Open, Needs TriagePublic

Description

A number of error messages either just assume that administrators can always do X and have that hardcoded (e.g. undeletehistorynoadmin) or assume that if a group has right X then it also has the right to do X on the current page and just say "you should be a member of <these groups> to do X" when actually those groups can't do it either (pretty much everything using the badaccess-groups message does that).

This results in misleading error messages after T190015: Create separate user group for editing sitewide CSS/JavaScript that does not include administrators by default (and before that for any extension making non-trivial rights management changes, presumably).

Event Timeline

Krinkle renamed this task from "Administrator" is hardcoded in various permission error messages to "Administrator" is hardcoded in various permission error messages.Apr 1 2019, 3:52 PM

I'm told in T241318 that administrators cannot view the content of deleted css/js pages. So, is it a bug that I can see those edits in Special:DeletedContributions and Special:RevisionDelete?

I'm told in T241318 that administrators cannot view the content of deleted css/js pages. So, is it a bug that I can see those edits in Special:DeletedContributions and Special:RevisionDelete?

T202989: Administrators can no longer view deleted history of js/css pages