Page MenuHomePhabricator

action=growthsetmentor ignores blocks
Closed, ResolvedPublicSecurity

Description

While working on T321799, I noticed that action=growthsetmentor API ignores blocks, ie. blocked users can make use of the API.

In the case of action=growthsetmentor, this means:

  • Blocked mentors can harass users by claiming them (this triggers notifications)
  • Blocked mentees can change their own mentor (this does not trigger any notification, so the only issue is the entries in Special:Log).

Details

Related Objects

StatusSubtypeAssignedTask
ResolvedSecurity Urbanecm_WMF

Event Timeline

KStoller-WMF changed the task status from Open to In Progress.Nov 3 2022, 9:01 PM

Change 863025 had a related patch set uploaded (by Urbanecm; author: Urbanecm):

[mediawiki/extensions/GrowthExperiments@master] ApiSetMentor: Respect blocks

https://gerrit.wikimedia.org/r/863025

Urbanecm changed the visibility from "Custom Policy" to "Public (No Login Required)".Dec 1 2022, 7:22 PM
Urbanecm changed the edit policy from "Custom Policy" to "All Users".

Change 863025 merged by jenkins-bot:

[mediawiki/extensions/GrowthExperiments@master] ApiSetMentor: Respect blocks

https://gerrit.wikimedia.org/r/863025