Page MenuHomePhabricator

Wikimini extensions review
Closed, ResolvedPublic8 Estimated Story Points

Description

All extensions:

https://fr.wikimini.org/wiki/Sp%C3%A9cial:Version

For each extension, it could be useful to understand the ones that:

  • "disable": we can disable now, and re-discuss in the future when we will need it
  • "wait": we must wait since now it's very important to ...
  • "keep" we should probably keep it always-on since it's useful for ...

Event Timeline

valerio.bozzolan updated the task description. (Show Details)

secure-include, as I said, is disabled (as was already AWC's forum
extension since around June 2022), by this I mean that LocalSettings do
not call it anymore.

You can safely move the file away as you might have done with AWC to be
sure that it is no more used badly (although it should not as a
standalone file work but who knows…)

LiquidThread is currently unmaintained and has some awful bugs. Didn't
find any security issue yet but don't know what the bugs are about so it
might be linked. However I do not know what will happen to the current
threads when the extension is removed. If it's like StructuredDiscussion
then we're screwed.

Threads ]]: probably unstable - remove?

(The extensions I removed are now there:)

/var/www/wikimini.org/T331153_QUARANTINE_EXTENSIONS

did you put some .htaccess or rule in httpd.conf to forbid any access to
it ?

(Correctly set up owner / permission also works)

Yep it's forbidden since, in short:

# private ↓
/var/www/wikimini.org/T331153_QUARANTINE_EXTENSIONS

# potentially public ↓
/var/www/wikimini.org/www

# much public ↓
/var/www/wikimini.org/www/w

# this and others locations have Deny rules in apache ↓
/var/www/wikimini.org/www/w/extensions

Usually wikis use both probably because Titleblacklists permits an
easier management in the sense of forbidden title and is probably much
efficient (it does not add a full language, it's a simpler parser, and
it warns the user before even attempting the edits).

> [X] Title Blacklist: keep (in the future, evaluate if can be replaced by
AbuseFilter)

Thank you and feel free to continue (I mean for some hours you do not risk edit conflict)

Wow, LiquidThread is still enabled in Hungarian Wikipedia and maybe others:

https://hu.wikipedia.org/wiki/Szerkeszt%C5%91vita:Teszt_Elem%C3%A9r

I think it would be a good idea to update it now and just keep it, since it still supports MediaWiki 1.29+

valerio.bozzolan lowered the priority of this task from High to Medium.Jun 7 2023, 10:17 AM
valerio.bozzolan raised the priority of this task from Medium to High.
ValerioBoz-WMCH set the point value for this task to 8.
ValerioBoz-WMCH claimed this task.
ValerioBoz-WMCH subscribed.

Let's declare this as concluded. We can still comment and update the description. The situation is clearer now.