Page MenuHomePhabricator

Redirects to potentially annoying/harmful special pages like [[Special:Userlogout]] work
Closed, ResolvedPublic

Description

Author: guanaco

Description:
Redirects that point to pages like [[Special:Userlogout]] will log the user out.
This has been used to vandalize user pages by Michael and/or Mike Church. A
"confirm" button could be added to the logout page to prevent this from working.


Version: 1.3.x
Severity: major
URL: http://www.wikipedia.org/wiki/User:Guanaco/Sandbox

Details

Reference
bz62

Revisions and Commits

Event Timeline

bzimport raised the priority of this task from to High.Nov 21 2014, 6:47 PM
bzimport set Reference to bz62.
bzimport added a subscriber: Unknown Object (MLST).

timwi wrote:

JeLuf just made redirects to [[Special:Userlogin]] impossible. As far as I'm
aware, he also put the change live already.

This doesn't stop all possibilities; [[Special:Userlogout/Yomomma]] works for instance. Re-opening.

Fixed in HEAD with Article.php 1.224

epriestley added a commit: Unknown Object (Diffusion Commit).Mar 4 2015, 8:19 AM