A preliminary investigation (T326759) has found that the BetaFeatures extension may be affected by IP Masking
Description
Description
Details
Details
Related Changes in Gerrit:
| Subject | Repo | Branch | Lines +/- | |
|---|---|---|---|---|
| Update BetaFeatures for temporary accounts | mediawiki/extensions/BetaFeatures | master | +93 -5 |
| Status | Subtype | Assigned | Task | ||
|---|---|---|---|---|---|
| Restricted Task | |||||
| Resolved | kostajh | T294511 2021 Security Team wikireplicas audit | |||
| Declined | None | T284948 Raw IPs of logged-out users disclosed in wiki-replicas | |||
| Resolved | Niharika | T324492 Temporary accounts - MVP | |||
| Open | None | T326816 [Epic] Update features for temporary accounts | |||
| Resolved | • Dreamy_Jazz | T326916 Prepare BetaFeatures extension for IP Masking | |||
| Resolved | • TThoabala | T337781 Prevent BetaFeatures from setting preferences for temporary accounts |
Event Timeline
Comment Actions
Beta features are opted into via preferences, so afaik, there's nothing else to do here. But someone should audit the code and check.
Comment Actions
Change #1072519 had a related patch set uploaded (by Dreamy Jazz; author: Dreamy Jazz):
[mediawiki/extensions/BetaFeatures@master] Update BetaFeatures for temporary accounts
Comment Actions
Change #1072519 merged by jenkins-bot:
[mediawiki/extensions/BetaFeatures@master] Update BetaFeatures for temporary accounts
Comment Actions
QA has been completed, and the new code change(s) are functioning as expected ("Temporary Account User cannot access Special:BetaFeatures, and will be redirected to the login form, also the Temporary Account User dropdown menu does not contain a link to access Beta Features").
