User Details
- User Since
- Nov 18 2019, 7:30 PM (325 w, 5 d)
- Availability
- Available
- LDAP User
- Mstyles
- MediaWiki User
- MStyles (WMF) [ Global Accounts ]
Mon, Feb 9
Security access granted
Mon, Feb 2
@abi_ Great, I'll post the review by the end of February so you have plenty of time.
Wed, Jan 28
@abi_ Is this project still scheduled for deployment on Jan 31? I wanted to follow up on the timeline.
Sat, Jan 24
Fri, Jan 23
Tue, Jan 20
Jan 9 2026
Wikibase Extension
+ (T409737, CVE-2026-22710) - Stored XSS through autocomment system messages
https://gerrit.wikimedia.org/r/q/I8505700afda8096ef4e183280494232152767004
Jan 8 2026
@Urbanecm_WMF I'm not sure what's causing the failures. I'll take a look.
@SomeRandomDeveloper thank you and I see I used the wrong tag for gerrit, apologies!
Jan 7 2026
Jan 6 2026
CVE/Backport Assignments
Jan 5 2026
@Urbanecm following up on this task in the new year
Dec 19 2025
Dec 16 2025
Dec 12 2025
Since this is a simple extension rename, an application security review is not needed
Dec 9 2025
Dec 8 2025
Dec 5 2025
Since all users now have 2FA access I'm declining this task as I don't think it's relevant anymore.
Dec 4 2025
@Adarsh2406 your patch looks pretty good and it addressed a lot of the issues that @Reedy mentioned. I wonder if you would be interested in reopening your patch?
Now that we have 2FA and all users have access to it (T399664) I'm marking this as resolved.
As all of the cleanup work is either merged or deployed and all users have access to 2FA, I'm marking this as resolved.
Dec 1 2025
Nov 20 2025
Nov 18 2025
Nov 17 2025
Nov 12 2025
Nov 10 2025
Security issue access has been granted
Nov 6 2025
Nov 5 2025
Nov 4 2025
We decided to not show timestamps for recovery codes per the designs, unless this is referring to something else
Oct 29 2025
I assume they should all have index=-1. Otherwise, tabbing through the page takes you to the footer before it takes you to the form inputs.
Oct 28 2025
We're in the process of improving passkey support and are planning to make major changes in the next few weeks. I think the changes should allow a greater variety of passkeys to work. Right now we've limited passkeys to roaming only, so you should not be getting an error
@dom_walden what do you think the tab order should be for the images listed? Outside of the WebAuthn error page, I think that the other pages seem to tab okay and the tab index increases. Is it that the bottom of the page has tab index set to 0 that's an issue for the other pages?
