Via security@:
To Whom It May Concern, I have experienced some issues changing my password and logging in to Wikipedia on Android. I initially tried to change my password via the mobile site (en.m.wikipedia.org) in Microsoft Edge however when pressing "Change credentials" no further messages appear and the password is not changed. I then attempted to change the password via the desktop site (en.wikipedia.org) in the same mobile browser which was successful. I was wanting to submit a security report with some further information and troubleshooting so I attempted to replicate the issue in Google Chrome on the same device however when attempting to log in I initially received the following message: "Central user log in The provided authentication token is either expired or invalid." After receiving this message I tried clearing the image & file cache and site data for wikipedia.org, and noticed that Chrome appears to open the Wikipedia Android app during the login process, so I updated the app to the latest version along with clearing its cache but leaving the stored data intact. After having done this logging in through Google Chrome advises that the wikipedia site is logged in through a central login, however, when attempting to access the change password page it prompts to login again and when trying to do so, the same error appears as above "Central user log in The provided authentication token is either expired or invalid." I have tried setting Chrome as the default browser to avoid the process opening Edge however this results in the same error. I then tried the process again in Edge after having cleared the stored data & cache for the Wikipedia app and it does login using the central user login, though when attempting to change the password via the mobile site it still displays the same behaviour where the page does not progress and the password is not changed. I have also tried removing the account from the list of accounts on my device (listed as username:wikimedia) however this did not help. As I was able to change my password via the desktop version of the site on my device, the change of password is not my primary concern, but the process using the mobile site along with the expired/invalid token messages. Please let me know if there is anything else I can provide or if you might be aware of why this might be occurring. Thank you for your assistance. Kind Regards, Ryan Putland.