Page MenuHomePhabricator

Remove deprecated raw HTML localisation messages 'copyright' and 'history_copyright' and the hook 'SkinCopyrightFooter'
Closed, ResolvedPublic

Description

In T45646: "MediaWiki:Copyright" message allows raw HTML (MW 1.43) we introduced a replacement and deprecated them. They should be removed in a future MediaWiki release.

QA

Set

$wgRightsPage = 'Foo';

Edit MediaWiki:Copyright
with

EVIL EVIL $1 unless otherwise noted.<img src="http://my_host/index.php?title=Special:UserLogout"/><script>alert('evil!');</script>

Load any page

  • Expected: the message is not shown in the footer. There is no JS alert.

Event Timeline

Change #1145324 had a related patch set uploaded (by Bartosz Dziewoński; author: Bartosz Dziewoński):

[mediawiki/core@master] Remove raw HTML messages 'copyright' and 'history_copyright'

https://gerrit.wikimedia.org/r/1145324

Change #1145324 merged by jenkins-bot:

[mediawiki/core@master] Remove raw HTML messages 'copyright' and 'history_copyright'

https://gerrit.wikimedia.org/r/1145324

Change #1146109 had a related patch set uploaded (by Bartosz Dziewoński; author: Bartosz Dziewoński):

[mediawiki/core@REL1_44] Change $wgAllowRawHtmlCopyrightMessages to default false, deprecate

https://gerrit.wikimedia.org/r/1146109

Change #1146109 merged by jenkins-bot:

[mediawiki/core@REL1_44] Change $wgAllowRawHtmlCopyrightMessages to default false, deprecate

https://gerrit.wikimedia.org/r/1146109