Page MenuHomePhabricator

3rd parties: Edit button shows as enabled to anonymous editors.
Closed, ResolvedPublic

Description

If I use the MinervaNeue skin for the MobileFrontend extension and I set the following user rights in MediaWiki via the wgGroupPermissions preference in the LocalSettings.php file:

$wgGroupPermissions['*']['edit'] = false;
$wgGroupPermissions['user']['edit'] = true;

Expected:
As the setting above defines that anonymous users who are not logged in cannot edit a wiki page, I should get some indication I cannot edit.

Actual:
the edit button can still be clicked and I see this


I can continue the edit and its only when I try to save that I hit issues.

Expected: Clicking the edit icon should prompt the user to login in some way.

acceptance criteria

  • Edit icon must show at locked for these users
  • When clicking the edit icon we should show the CtaDrawer just as we do for the watchstar.
  • The messaging of the drawer should use mobile-frontend-edit-login-action

Developer notes

At minimum, we should disable the edit icon to these users (showing edit-locked) based on the check of permissions.

A better solution would be to mimic the CtaDrawer for the watchstar.
The CtaDrawer provides this functionality for the watchstar.

Related: T206813

QA steps

Please verify the edit pencil is performing as expected on both beta cluster and reading web staging.
The 3rd party use case has been tested and verified by @Jdlrobson so no need to check that!

Details

Related Gerrit Patches:

Event Timeline

Restricted Application added a subscriber: Aklapper. · View Herald TranscriptOct 11 2018, 11:07 PM
ovasileva triaged this task as Low priority.Oct 16 2018, 9:16 PM
Bjornskjald added a subscriber: Bjornskjald.EditedNov 2 2018, 11:25 AM

Cannot reproduce, it shows "This page is protected" for me when I'm trying to edit it from anonymous account.

EDIT: can reproduce if the page isn't refreshed after the settings change but I don't think it's not expected behaviour.

Hey @Bjornskjald ! that part of this bug does look fixed to me! Thanks for checking!

However, the message "This page is protected to prevent vandalism." is a little misleading. Ideally, instead of showing that notification message we'd prompt the user to login like so under these circumstances:

You can use mw.config.get('wgRestrictionEdit') to check:

if ( mw.user.isAnon() && mw.config.get('wgRestrictionEdit').indexOf( '*' ) ) {
//show login prompt
} else {
//show permission error
}
Jdlrobson updated the task description. (Show Details)Nov 2 2018, 3:00 PM

Thanks, I'll try to do it.

Jdlrobson updated the task description. (Show Details)

Thanks for looking at this one. I'm moving it to a workboard where I can keep track on this task to help answer any further questions and help review this! Good luck!

Bjornskjald added a comment.EditedNov 2 2018, 3:06 PM

By the way, is it an issue in MobileFrontend? Because I couldn't find that string anywhere in the repo

EDIT: nevermind, it's in MinervaNeue.

Change 471302 had a related patch set uploaded (by Bjornskjald; owner: Bjornskjald):
[mediawiki/skins/MinervaNeue@master] Add drawer when user is not logged in and anonymous edits are disabled

https://gerrit.wikimedia.org/r/471302

Change 471302 merged by jenkins-bot:
[mediawiki/skins/MinervaNeue@master] Add drawer when user is not logged in and anonymous edits are disabled

https://gerrit.wikimedia.org/r/471302

Jdlrobson reassigned this task from Bjornskjald to Ryasmeen.Nov 7 2018, 6:06 PM
Jdlrobson added a project: Product-QA.

Looks good to me on Beta cluster and staging, but it does look a bit different between the two sites. For example, in the images below, the edit icon (upper right) is displayed on beta and does not appear on staging. @ovasileva or @Jdlrobson, is this ok?



Jdlrobson reassigned this task from Ryasmeen to ovasileva.Nov 7 2018, 7:00 PM
Jdlrobson added a subscriber: Ryasmeen.

Reading web staging was outdated. I've updated it now. Given beta cluster was fine, and beta cluster is more up to date, I think we're done here!

ovasileva closed this task as Resolved.Nov 7 2018, 9:29 PM

Looks good, thanks all

Restricted Application added a project: User-Ryasmeen. · View Herald TranscriptNov 7 2018, 9:29 PM
ovasileva updated the task description. (Show Details)Nov 7 2018, 9:30 PM