For instance if the user is partially blocked, the block won't be successful and the AF will allow the edit to go through.
Description
Description
Status | Subtype | Assigned | Task | ||
---|---|---|---|---|---|
Restricted Task | |||||
Resolved | Security | Daimona | T272333 Disallow the edit if blocking the user didn't succeed (CVE-2021-31548) |
Event Timeline
Comment Actions
I think a fix for this might be pushed publicly on gerrit, but creating as sec-protected for now.
Comment Actions
For now I'm going to push a hacky patch on gerrit, pretending it's a cleanup, then we can make the task public and discuss better strategies.
Comment Actions
@matej_suchanek Thank you for merging the fix, I forgot to add you as subscriber here. Let's wait until the fix is deployed with the train next week, and then we can make this task public.
Comment Actions
I already backported this yesterday, so considering this works as intended, and there's nothing to hide for now, I'm going to make this task public.