Page MenuHomePhabricator

API allows suppression of redirects by users without the "suppressredirect" right
Closed, ResolvedPublic

Description

The following pages were moved using the API:
https://pt.wikipedia.org/w/index.php?title=User:Reverta-me/Testes2&diff=prev&oldid=40709971
https://pt.wikipedia.org/w/index.php?diff=40708830
https://pt.wikipedia.org/w/index.php?diff=40708798
The users in question are not in a group which has the "suppressredirect" right, so the edits should have created a redirect, even if the API call specified "noredirect=1" and there should be a warning about that.

Event Timeline

He7d3r raised the priority of this task from to High.
He7d3r updated the task description. (Show Details)
He7d3r changed Security from none to None.
He7d3r added subscribers: He7d3r, DiegoQueiroz.

Looks like a regression from gerrit 166175 / Ic5026384b92a0d68d628397ffe1de6e5b6183f02

Change 176036 had a related patch set uploaded (by Anomie):
API: Check suppressredirect right in ApiMove

https://gerrit.wikimedia.org/r/176036

Patch-For-Review

Change 176038 had a related patch set uploaded (by Reedy):
API: Check suppressredirect right in ApiMove

https://gerrit.wikimedia.org/r/176038

Patch-For-Review

Change 176036 merged by jenkins-bot:
API: Check suppressredirect right in ApiMove

https://gerrit.wikimedia.org/r/176036

Change 176038 merged by jenkins-bot:
API: Check suppressredirect right in ApiMove

https://gerrit.wikimedia.org/r/176038