Page MenuHomePhabricator

GlobalRename notes appear publically
Closed, InvalidPublicSecurity



First occurred in August, as far as I can tell[1]

Note sure why, couldn't figure out how to add notes without rejecting or accepting a request when attempting to reproduce


Event Timeline

Restricted Application added a project: User-DannyS712. · View Herald TranscriptJan 15 2020, 8:56 AM
Restricted Application added a subscriber: Aklapper. · View Herald Transcript
DannyS712 moved this task from Unsorted to Reports on the User-DannyS712 board.Jan 15 2020, 8:57 AM
DannyS712 added subscribers: Urbanecm, Rxy.

Renamers know that the notes are public.

revi removed a subscriber: revi.Jan 15 2020, 9:01 AM
Urbanecm closed this task as Invalid.Jan 15 2020, 9:03 AM

This isn't a security vuln, but intended.

@revi @Urbanecm where exactly do you see the "Create notes..."? I tried to do this at and there is only a "Notes/reasoning" field, and the log entry.

revi removed a subscriber: revi.Jan 15 2020, 9:09 AM

It is probably configured via Mediawiki namespace page to show that interface message.

Oh, thanks. Sorry for the trouble

Legoktm changed the visibility from "Custom Policy" to "Public (No Login Required)".Jan 15 2020, 11:40 AM
Legoktm changed the edit policy from "Custom Policy" to "All Users".