Page MenuHomePhabricator

GlobalRename notes appear publically
Closed, InvalidPublicSecurity

Description

See https://meta.wikimedia.org/wiki/Special:PrefixIndex?prefix=GlobalRenameQueue&namespace=4

First occurred in August, as far as I can tell[1]

Note sure why, couldn't figure out how to add notes without rejecting or accepting a request when attempting to reproduce

[1] https://meta.wikimedia.org/w/index.php?title=Meta:GlobalRenameQueue/Notes/55397&action=history

Event Timeline

Restricted Application added a subscriber: Aklapper. · View Herald Transcript

image.png (62×1 px, 22 KB)

Renamers know that the notes are public.

This isn't a security vuln, but intended.

@revi @Urbanecm where exactly do you see the "Create notes..."? I tried to do this at https://deployment.wikimedia.beta.wmflabs.org/wiki/Special:GlobalRenameQueue/request/36 and there is only a "Notes/reasoning" field, and the log entry.

It is probably configured via Mediawiki namespace page to show that interface message.

Oh, thanks. Sorry for the trouble

Legoktm changed the visibility from "Custom Policy" to "Public (No Login Required)".Jan 15 2020, 11:40 AM
Legoktm changed the edit policy from "Custom Policy" to "All Users".