Page MenuHomePhabricator
Feed Advanced Search

Feb 2 2024

Lockal added a comment to T334940: All Graphs broken on Wikimedia wikis (due to security issue T336556).

@Nux, just to say, there is ongoing work in T222807.

Feb 2 2024, 10:00 PM · User-zeljkofilipin, Regression, User-notice, Tech Ambassadors & Translators, MediaWiki-extensions-Graph

Aug 10 2023

Lockal added a comment to T343817: Investigate additional ways of locking down language-specific execution for the function-executor.

There is a new Permission Model model in modern NodeJS, by the way. Enabling it allows to control reading, writing (even on r/o environments processes can write to some obscure places like /dev/termination-log), spawning workers and subprocesses. This also blocks all attempts to launch shell / perl / another instance of nodejs / and so on.

Aug 10 2023, 7:49 PM · function-evaluator, Abstract Wikipedia team

Apr 21 2023

Lockal added a comment to T334940: All Graphs broken on Wikimedia wikis (due to security issue T336556).

Disabling extension is an adequate decision. Long time ago I reported about EasyTimeline, nobody disabled this extension, it took few weeks to fix, but again, it was long time ago. Today Wikipedia has have state-level attacks (guess the country), just in February almost every Russian MediaWiki website was attacked (proclaimed as "euro-woodpecker", using wormable payloads with a mix of pre-1.37 stored XSS vulnerabilities and mcrundo to bypass captcha), so nobody wants to know how much damage malicious actors can do in few minutes.

Apr 21 2023, 9:12 AM · User-zeljkofilipin, Regression, User-notice, Tech Ambassadors & Translators, MediaWiki-extensions-Graph

Mar 25 2021

Lockal added a comment to T246035: Videojs player for audio opens a dialog to support subtitles, which is unexpected.

no place for subtitles

Mar 25 2021, 11:06 AM · MW-1.38-notes (1.38.0-wmf.25; 2022-03-07), VideoJS player

Feb 25 2021

Lockal added a comment to T185313: mw.wikibase.entity:getBacklinks (lua API in wikibase client).

There is a long-running experiment in ruwiki about generating family name lists with Listeria with template substitution - https://ru.wikipedia.org/wiki/%D0%A4%D1%83%D0%BA%D0%B0%D0%B4%D0%B0.
Not exactly matches expectations about Lua, but solves use case №1.

Feb 25 2021, 3:06 PM · Automated list generation, Wikidata-Campsite, Wikibase-Lua, Wikidata, MediaWiki-extensions-WikibaseClient

Feb 14 2021

Lockal added a comment to T274731: Wikidata watchlist not filtering out a bot.

Not a bug, I forgot to add bot=1 flag (even though I knew it 10 years ago). Forgot that flooder flag is opt-out and bot flag is opt-in.

Feb 14 2021, 2:41 PM · Growth-Team, MediaWiki-Watchlist, Wikidata

Dec 30 2020

Lockal updated subscribers of T270293: Parsing example queries partially produce errors.

According to https://web.archive.org/web/20190205051545/https://www.wikidata.org/wiki/Wikidata:SPARQL_query_service/queries/examples
previously, syntaxhighlight markup looked like:

<span class="lineno"> 1 </span><span class="c">#defaultView:BarChart</span>

Line numbers were not selectable.

Dec 30 2020, 7:00 PM · Wikibase Suite Team, Wikibase (3rd party installations), Wikidata-Query-Service