Page MenuHomePhabricator

User without bot permission able to flag revision as bot.
Closed, DeclinedPublic

Description

A vandal has been able to flag edits as if they were made by a bot on en.wiktionary and en.wikiversity. I was unable to do this merely by using the API edit with an "&bot" on a user without permissions, so I suspect it is some other bug.

The edits on en.wiktionary can be found here:
http://en.wiktionary.org/w/index.php?namespace=3&tagfilter=&from=20110924021000&hidebots=&hideanons=1&hideliu=1&title=Special%3ARecentChanges

Same user on en.wikibooks:
http://en.wikibooks.org/w/index.php?namespace=0&tagfilter=&hidebots=&hideanons=1&hideliu=1&title=Special%3ARecentChanges


Version: 1.17.x
Severity: major

Details

Reference
bz31129

Event Timeline

bzimport raised the priority of this task from to Unbreak Now!.Nov 21 2014, 11:50 PM
bzimport set Reference to bz31129.
bzimport added a subscriber: Unknown Object (MLST).

You can see, that the rollback is marked as bot too. This is a mediawiki function to hide the rollbacks made with action=rollback from the recentchanges. ([[meta:Help:Reverting#Bot rollback]]

Ruy Pugliesi is a global rollbacker ([[meta:Global_rollback]]) and he has the permission "rollback" and "markbotedits"