Essential reading
Parent task description: T325658: Log access to IP addresses of temporary accounts
This task
This task is for:
- Adding the logging infrastructure
- Logging whenever a user enables or disables their access via their preferences
| Tchanders | |
| Apr 25 2023, 3:51 PM |
| F36972768: T335365_IPMasking_EnableDisable_Preferences_Investigate.png | |
| May 2 2023, 7:32 PM |
| F36972766: T335365_IPMasking_EnableDisable_Preferences_CheckUser.png | |
| May 2 2023, 7:32 PM |
| F36972761: T335365_IPMasking_EnableDisable_Preferences.png | |
| May 2 2023, 7:32 PM |
| F36972763: T335365_IPMasking_EnableDisable_Preferences_OnGood.png | |
| May 2 2023, 7:32 PM |
Essential reading
Parent task description: T325658: Log access to IP addresses of temporary accounts
This task
This task is for:
| Status | Subtype | Assigned | Task | ||
|---|---|---|---|---|---|
| Restricted Task | |||||
| Resolved | kostajh | T294511 2021 Security Team wikireplicas audit | |||
| Declined | None | T284948 Raw IPs of logged-out users disclosed in wiki-replicas | |||
| Resolved | Niharika | T324492 Temporary accounts - MVP | |||
| Resolved | Niharika | T325238 [Epic] IP Address Reveal for Privileged Users | |||
| Resolved | Tchanders | T325658 Log access to IP addresses of temporary accounts | |||
| Resolved | Tchanders | T335365 Log when a user enables or disables their access to view temporary account IPs |
Change 910091 had a related patch set uploaded (by Tchanders; author: Tchanders):
[mediawiki/extensions/CheckUser@master] Add logging infrastructure for logging temporary account IP address access
Change 910091 merged by jenkins-bot:
[mediawiki/extensions/CheckUser@master] Add logging infrastructure for logging temporary account IP address access
@Tchanders When in preferences with the revealing IP addresses for temporary accounts are toggled off, Show IP does not show up to reveal the IP addresses. Though in Special: Checkuser and Special: Investigate, you are able to view the IP addresses for temporary accounts as seen in the screenshots below. Before I move this to Done, this is as designed, right?
OS: macOS 13.3
Browsers: Chrome 112, Firefox 112, Safari 16.4
Skins: Vector 2022, 2010, Minerva, Monobook, Timeless
Environment: Local
Pages Tested:
Special: RecentChanges
Special: Watchlist
Special: Checkuser
Special: Investigate
Revision history
Diff
Page Information
Toggle on- Show IP
Toggle Off
CheckUser
Investigate
@GMikesell-WMF - yes this is fine!
If it helps, here's an explanation: essentially once you're using CheckUser, you're (a) a very trusted user who can see IP addresses even of logged-in users, and (b) you're doing a very sensitive investigation for a very good reason which is logged an oversighted. You already have to take a series of very deliberate steps to see the IP addresses listed on Special:CheckUser or Special:Investigate, so there's no preference gating access to it.