Page MenuHomePhabricator

Enable upload of OpenOffice-files on nowikimedia
Closed, DeclinedPublic

Description

Author: laaknor-wmfbugzilla

Description:
We need to share some files on our public chapter-wiki. Can you enable upload of ODF/ODP/ODT/ODS on no.wikimedia?


Version: unspecified
Severity: enhancement

Details

Reference
bz25131

Event Timeline

bzimport raised the priority of this task from to Lowest.Nov 21 2014, 11:16 PM
bzimport set Reference to bz25131.

It appears that this is only enabled on private wikis. No public wikis on the project have this ability.

It seems to be broken down only by if it is public or private. I imagine its due to exploits possible by uploading those file types.

I will email our tech list and ensure that is why it is this way.

In reviewing this with some of the tech staff, it seems that indeed, open office file formats are not allowed on public projects. Upload of a maliciously crafted OpenOffice document leads to CSRF. Any public wiki with OpenOffice uploads enabled is vulnerable.

That pretty much means we do not enable them on public wikis. Right now your wiki is both public, open registration, and anyone can edit. So we cannot enable these file types on the project.