Page MenuHomePhabricator

Notification on invisible content in edit summary
Open, Needs TriagePublic

Description

Since we can now notify people by quoting them in the edit summaries, it is now possible to exploit the fact that notification only require to point to a username using a link which content could be a space or an invisible char.

In the contrary to the notifications made "on page", notifications wikicode in the summary is not easily readable and it makes this trick less likely to be found.

This could be an issue and misused to hide notifications in an harassing or canvassing process for example.

Examples :

Event Timeline

Restricted Application added a project: Growth-Team. · View Herald TranscriptApr 9 2019, 11:17 PM
Restricted Application added subscribers: MGChecker, Aklapper. · View Herald Transcript
Scoopfinder updated the task description. (Show Details)Apr 9 2019, 11:17 PM
Niharika added a subscriber: Niharika.EditedMay 8 2019, 7:03 PM

@Scoopfinder The examples you list are not for user notifications, are they? I might be missing the context in the translation.

EDIT: Never mind, I see what you mean! Thanks for flagging this issue for us.

JTannerWMF moved this task from Inbox to External on the Growth-Team board.May 8 2019, 7:07 PM
Scoopfinder updated the task description. (Show Details)May 9 2019, 9:05 AM