Page MenuHomePhabricator

Flow: Can bypass any protection and blank pages
Closed, ResolvedPublic


Examples: and

How to reproduce:

Go to [[mw:Special:ApiSandbox]]:

  • action=flow
  • page= page you want to blank
  • params={"topic_list": {"topic": "Topic!", "content": "Content!"}}
  • token=Flow token from API, +\ if you're logged out

Press Make request, and the page will be replaced with the string: "This talk page has been taken over by a [ Flow board]."

Quick fix: Stick a $title->userCan('edit', $this->getUser()) check in ApiFlow

Version: unspecified
Severity: blocker
See Also:



Event Timeline

bzimport raised the priority of this task from to Unbreak Now!.Nov 22 2014, 3:05 AM
bzimport set Reference to bz60218.
bzimport added a subscriber: Unknown Object (MLST).
Legoktm created this task.Jan 19 2014, 1:44 AM
coren added a comment.Jan 19 2014, 1:46 AM

That one's a bad one!

coren added a comment.Jan 19 2014, 1:47 AM

Bumping to highest (this should probably even be immediate).

coren added a comment.Jan 19 2014, 1:50 AM

After brief chat with James_F, bumping to immediate/blocker


Err, didn't mean to change the fields.

cherry-picked to 1.23wmf11 and deployed

Quiddity removed a subscriber: Maryana.Dec 19 2014, 1:33 AM
Restricted Application added a project: Collaboration-Team-Triage. · View Herald TranscriptJan 28 2016, 5:57 PM
Restricted Application added a subscriber: Luke081515. · View Herald Transcript
Ironholds set Security to None.Jan 29 2016, 2:50 PM
Ironholds removed a subscriber: Ironholds.
Restricted Application added a subscriber: Liuxinyu970226. · View Herald TranscriptMon, Feb 10, 10:50 PM