Page MenuHomePhabricator

R4356th
User

Projects

Today

  • Clear sailing ahead.

Tomorrow

  • Clear sailing ahead.

Saturday

  • Clear sailing ahead.

User Details

User Since
Oct 1 2020, 4:41 PM (68 w, 7 h)
Availability
Available
IRC Nick
R4356th
LDAP User
R4356thwiki
MediaWiki User
R4356th [ Global Accounts ]

Recent Activity

Oct 24 2021

R4356th added a comment to T293341: MassEditRegex is Vulnerable to CSRF Attacks (CVE-2021-46147).

Thank you both!

Oct 24 2021, 7:01 AM · SecTeam-Processed, Vuln-CSRF, MediaWiki-extensions-MassEditRegex, Security

Oct 21 2021

R4356th added a comment to T293341: MassEditRegex is Vulnerable to CSRF Attacks (CVE-2021-46147).

Did you still want to get a change set up to gerrit for review? Looks like I have +2 on that repo, so I could merge it if it passes CI and someone +1s it as confirmed testing and working for master. Let me know.

Oct 21 2021, 3:40 PM · SecTeam-Processed, Vuln-CSRF, MediaWiki-extensions-MassEditRegex, Security

Oct 17 2021

R4356th added a comment to T293341: MassEditRegex is Vulnerable to CSRF Attacks (CVE-2021-46147).

Hi all, definitely haven't touched this for a while so can't help much, but I've eyeballed the patch and it looks fine so I'd be happy to +2 it if I still can.

Oct 17 2021, 12:12 PM · SecTeam-Processed, Vuln-CSRF, MediaWiki-extensions-MassEditRegex, Security

Oct 15 2021

R4356th added a comment to T293341: MassEditRegex is Vulnerable to CSRF Attacks (CVE-2021-46147).
  1. What the Security-Team would suggest, prior to publicly disclosing an issue via gerrit, is for the skin/extension maintainers or discoverers of any vulnerabilities like this, to reach out to as many people as possible (tagging them on this task if they have Phabricator accounts would work) so they can code-review and then deploy this patch to their MediaWiki installations prior to public disclosure. Unfortunately, this can be a tedious process and sites like WikiApiary, while helpful, are not always representative of actual usage of a given skin or extension.
Oct 15 2021, 4:11 PM · SecTeam-Processed, Vuln-CSRF, MediaWiki-extensions-MassEditRegex, Security

Oct 14 2021

R4356th added a comment to T293341: MassEditRegex is Vulnerable to CSRF Attacks (CVE-2021-46147).

Here is a patch but I am not sure how to get it through Gerrit. Does that need to be done by the Security Team even for non-Wikimedia-deployed extensions?

Oct 14 2021, 10:49 AM · SecTeam-Processed, Vuln-CSRF, MediaWiki-extensions-MassEditRegex, Security
R4356th updated subscribers of T293341: MassEditRegex is Vulnerable to CSRF Attacks (CVE-2021-46147).

Adding the author.

Oct 14 2021, 10:38 AM · SecTeam-Processed, Vuln-CSRF, MediaWiki-extensions-MassEditRegex, Security
R4356th added projects to T293341: MassEditRegex is Vulnerable to CSRF Attacks (CVE-2021-46147): MediaWiki-extensions-MassEditRegex, Vuln-CSRF.
Oct 14 2021, 10:38 AM · SecTeam-Processed, Vuln-CSRF, MediaWiki-extensions-MassEditRegex, Security
R4356th created T293341: MassEditRegex is Vulnerable to CSRF Attacks (CVE-2021-46147).
Oct 14 2021, 10:37 AM · SecTeam-Processed, Vuln-CSRF, MediaWiki-extensions-MassEditRegex, Security

Oct 5 2021

R4356th merged T292564: Search box does not suggest Special pages in the new vector into T277363: New search widget API doesn't work in "Special:" and "File:" namespace.
Oct 5 2021, 8:13 PM · Readers-Web-Backlog, Platform Team Workboards (Clinic Duty Team), Vector, Design-Systems-team (Vue.js Search Experience (Vector modern)), Desktop Improvements
R4356th merged task T292564: Search box does not suggest Special pages in the new vector into T277363: New search widget API doesn't work in "Special:" and "File:" namespace.
Oct 5 2021, 8:12 PM · Discovery-Search, Design-Systems-team (Vue.js Search Experience (Vector modern)), MediaWiki-Search

Sep 25 2021

R4356th added a watcher for Bengali-Sites: R4356th.
Sep 25 2021, 9:05 PM
R4356th moved T291502: One Wikipedia article connected with two items! from Backlog to Closed on the Bengali-Sites board.
Sep 25 2021, 9:04 PM · Bengali-Sites, Wikidata

Sep 22 2021

R4356th committed rEREPc67a07bf5dd1: Replace obsolete hooks (authored by R4356th).
Replace obsolete hooks
Sep 22 2021, 7:31 PM

Sep 11 2021

R4356th moved T274639: Help panel post-edit footers getting truncated from Backlog to Closed on the Bengali-Sites board.
Sep 11 2021, 12:58 PM · MW-1.37-notes (1.37.0-wmf.17; 2021-08-02), Growth-Team (Current Sprint), Growth-Team-Filtering, GrowthExperiments, Bengali-Sites
R4356th moved T273085: Deploy more logos for new DIP pilot wikis from Backlog to Closed on the Bengali-Sites board.
Sep 11 2021, 12:58 PM · Turkish-Sites, Serbian-Sites, Bengali-Sites, Readers-Web-Backlog (Kanbanana-FY-2020-21), Desktop Improvements
R4356th moved T288706: [SPIKE] Gather Phase 2 Wikis' Perceived Opt-Out Deployment Blockers from Backlog to Closed on the Bengali-Sites board.
Sep 11 2021, 12:57 PM · Chinese-Sites, Bengali-Sites, Hindi-Sites, Spanish-Sites, Editing-team (Tracking), DiscussionTools, OWC2020

Sep 4 2021

R4356th awarded T285171: Give a configuration variable for the DarkMode extension to move the dark mode toggle to a better place a Love token.
Sep 4 2021, 10:44 AM · DarkMode

Aug 29 2021

R4356th moved T285738: Prev parameter does not show up for second subpage link of NS:0 using <pages header=1> from Backlog to Closed on the Bengali-Sites board.
Aug 29 2021, 11:14 AM · MW-1.38-notes (1.38.0-wmf.9; 2021-11-16), ProofreadPage, Bengali-Sites
R4356th moved T281533: Announce Planned Reply Tool Opt-Out Deployment (Phase 2 wikis) from Backlog to Closed on the Bengali-Sites board.
Aug 29 2021, 11:13 AM · Chinese-Sites, Bengali-Sites, Hindi-Sites, Spanish-Sites, Editing-team (Tracking), DiscussionTools
R4356th moved T288540: Font-size rules apply to headings in the interface as well as content area (User menu not aligned on bnwiki) from Backlog to Closed on the Bengali-Sites board.
Aug 29 2021, 11:11 AM · MW-1.37-notes (1.37.0-wmf.19; 2021-08-16), Bengali-Sites, Readers-Web-Backlog (Kanbanana-FY-2021-22)

Aug 13 2021

R4356th moved T281797: Remove all bolding of search results on a variety of wikis from Backlog to Closed on the Bengali-Sites board.
Aug 13 2021, 4:41 PM · Readers-Web-Backlog (Kanbanana-FY-2021-22), MW-1.37-notes (1.37.0-wmf.14; 2021-07-12), Vector, WVUI, Design-Systems-team (Vue.js Search Experience (Vector modern)), Bengali-Sites, Desktop Improvements

Aug 11 2021

R4356th added a project to T288540: Font-size rules apply to headings in the interface as well as content area (User menu not aligned on bnwiki): Bengali-Sites.
Aug 11 2021, 1:35 PM · MW-1.37-notes (1.37.0-wmf.19; 2021-08-16), Bengali-Sites, Readers-Web-Backlog (Kanbanana-FY-2021-22)

Jul 14 2021

Ahmad_Kanik awarded T286152: Disable search engine indexing in specific namespaces of Bangla Wikipedia a Like token.
Jul 14 2021, 1:37 PM · Bengali-Sites, Wikimedia-Site-requests
R4356th moved T286152: Disable search engine indexing in specific namespaces of Bangla Wikipedia from Site configuration to Closed on the Bengali-Sites board.

Thank you, @Urbanecm!

Jul 14 2021, 11:28 AM · Bengali-Sites, Wikimedia-Site-requests
R4356th moved T283729: highlightQuery flag as true does not bold dropdown results when pages are translated to certain languages from Backlog to Closed on the Bengali-Sites board.
Jul 14 2021, 9:33 AM · Readers-Web-Backlog, Design-Systems-team (Vue.js Search Experience (Vector modern)), Bengali-Sites, Desktop Improvements
R4356th moved T283898: Turning on MVP on certain Wikis from Backlog to Closed on the Bengali-Sites board.
Jul 14 2021, 9:33 AM · Bengali-Sites, Community-Tech (CommTech-Sprint-2), Wikimedia OCR

Jul 11 2021

R4356th committed rEREP06ef77d33b24: Add missing i18n for Special:HandleReports (authored by R4356th).
Add missing i18n for Special:HandleReports
Jul 11 2021, 3:00 PM
R4356th committed rEREP4363b15444d2: Define $out to fix fatal exception (authored by R4356th).
Define $out to fix fatal exception
Jul 11 2021, 2:57 PM

Jul 10 2021

R4356th claimed T286152: Disable search engine indexing in specific namespaces of Bangla Wikipedia.
Jul 10 2021, 12:00 PM · Bengali-Sites, Wikimedia-Site-requests

Jul 9 2021

R4356th removed projects from T286379: Dark mode glitch (colour switching): Community-Tech, DarkMode.

This seems like the Dark Mode gadget, not the MediaWiki extension.

Jul 9 2021, 4:56 PM

Jul 4 2021

R4356th moved T286152: Disable search engine indexing in specific namespaces of Bangla Wikipedia from Backlog to Config - to process on the Wikimedia-Site-requests board.
Jul 4 2021, 3:18 PM · Bengali-Sites, Wikimedia-Site-requests
R4356th moved T286152: Disable search engine indexing in specific namespaces of Bangla Wikipedia from Backlog to Site configuration on the Bengali-Sites board.
Jul 4 2021, 3:18 PM · Bengali-Sites, Wikimedia-Site-requests

Jun 24 2021

R4356th added a watcher for MediaWiki-Core-Skin-Architecture: R4356th.
Jun 24 2021, 8:50 AM

Jun 12 2021

R4356th added a watcher for Design-Systems-team: R4356th.
Jun 12 2021, 11:13 AM

Jun 8 2021

R4356th added a comment to T221897: Allow users to switch Dark Mode on/off.

Since MediaWiki can be installed on a domain where other applications or JavaScript scripts may be installed it would be good to put the LocalStorage key in a namespace by prefixing the key with mw or mediawiki or something, followed by a dot (the . character)...

Jun 8 2021, 4:50 AM · DarkMode

Jun 1 2021

R4356th committed rEDKM4dac88371439: DarkMode: Apply the "darkmode-link" id (authored by R4356th).
DarkMode: Apply the "darkmode-link" id
Jun 1 2021, 8:10 PM
R4356th committed rEDKM6d05bd4ab857: DarkMode: Apply the "darkmode-link" id (authored by R4356th).
DarkMode: Apply the "darkmode-link" id
Jun 1 2021, 8:10 PM

May 30 2021

R4356th added a comment to T283406: GoogleDocs4MW Uses Wrong URL for Embedding Spreadsheets.

@R4356th : Why?

May 30 2021, 12:51 PM · Patch-For-Review, User-RhinosF1, MediaWiki-extensions-Other

May 28 2021

R4356th committed rEDKM561a743eafda: DarkMode: Apply the "darkmode-link" id (authored by R4356th).
DarkMode: Apply the "darkmode-link" id
May 28 2021, 6:18 PM
R4356th closed T283406: GoogleDocs4MW Uses Wrong URL for Embedding Spreadsheets as Declined.
May 28 2021, 2:31 PM · Patch-For-Review, User-RhinosF1, MediaWiki-extensions-Other

May 23 2021

R4356th awarded T52864: Upgrade GNU Mailman from 2.1 to Mailman3 a Barnstar token.
May 23 2021, 2:12 PM · Security-Team, SRE, Wikimedia-Mailing-lists

May 22 2021

R4356th claimed T283406: GoogleDocs4MW Uses Wrong URL for Embedding Spreadsheets.
May 22 2021, 11:01 AM · Patch-For-Review, User-RhinosF1, MediaWiki-extensions-Other
R4356th created T283406: GoogleDocs4MW Uses Wrong URL for Embedding Spreadsheets.
May 22 2021, 10:57 AM · Patch-For-Review, User-RhinosF1, MediaWiki-extensions-Other

May 13 2021

R4356th added a comment to T281193: Security release of AbuseFilter 1.35 throws TypeError.

Please read https://www.mediawiki.org/wiki/Phabricator/Project_management#Priority_levels "Unbreak Now! – Something is broken and needs to be fixed immediately, setting anything else aside". - I don't know if the /test interface being broken meets that criteria, but "Unbreak Now!" does not have to impact WMF production, I have no idea why you'd say that..

May 13 2021, 2:21 PM · AbuseFilter

May 12 2021

R4356th lowered the priority of T281193: Security release of AbuseFilter 1.35 throws TypeError from Unbreak Now! to Needs Triage.

This does not impact WMF production and does not appear to have anyone actively working on this.

May 12 2021, 7:35 PM · AbuseFilter

May 10 2021

R4356th added a project to T282470: Use Foreign Keys in CreatedPageList extension: MediaWiki-extensions-Other.
May 10 2021, 4:50 PM · MediaWiki-extensions-Other

May 9 2021

R4356th moved T282366: Monitor mailman3 runner processes from Backlog to Mailman v3 on the Wikimedia-Mailing-lists board.
May 9 2021, 10:01 AM · SRE, observability, Wikimedia-Mailing-lists

May 4 2021

R4356th added a member for Bengali-Sites: R4356th.
May 4 2021, 9:13 AM

Apr 26 2021

R4356th committed rEDKM0224fa679de8: Make DarkMode usable by anons and add user pref (authored by R4356th).
Make DarkMode usable by anons and add user pref
Apr 26 2021, 10:34 PM

Apr 25 2021

R4356th moved T281070: hyperkitty didn't import all wikitech-l messages from Backlog to Mailman v3 on the Wikimedia-Mailing-lists board.
Apr 25 2021, 10:22 PM · SRE, Wikimedia-Mailing-lists

Apr 24 2021

R4356th updated the task description for T268230: Roll out the new logo of MediaWiki.
Apr 24 2021, 8:43 PM · User-Ladsgroup, MW-1.36-notes, MW-1.37-notes (1.37.0-wmf.1; 2021-04-13), MW-1.31-release-notes, MW-1.35-notes, Patch-For-Review, Logos, MW-1.36-release, Design, MediaWiki-General

Apr 23 2021

R4356th claimed T241925: Dark mode does not persist between pages.
Apr 23 2021, 2:25 PM · MW-1.35-notes (1.35.0-wmf.31; 2020-05-05), Community-Tech, DarkMode, User-RhinosF1

Apr 21 2021

R4356th moved T274793: Turn on Impact module for Bengali Wikipedia after conclusion of another impact stats experiment from Backlog to Closed on the Bengali-Sites board.
Apr 21 2021, 3:40 PM · User-Urbanecm_WMF (Engineering), Growth-Team (Current Sprint), GrowthExperiments-Homepage, GrowthExperiments-ImpactModule, Bengali-Sites
R4356th added a comment to T274040: In Special:Translate, insertables hide text in longer messages in Firefox 87–88.

this is making translating big strings using the translation interface impossible.

I think adding a blank line at the end should work this bug around. When saving the Translations-namespace page, this blank line is dropped, and I hope it’s dropped in the actual translatable page as well. However, I couldn’t test this, because…

Apr 21 2021, 3:06 PM · Browser-Support-Firefox, MediaWiki-extensions-Translate

Apr 20 2021

R4356th added a comment to T274040: In Special:Translate, insertables hide text in longer messages in Firefox 87–88.

Could you post a direct link to an example message for testing?

Link:
https://meta.wikimedia.org/w/index.php?title=Special:Translate&group=page-User%3ATimur+Vorkul+%28WMDE%29%2FSuggested+values+announcement&language=bn&action=page&filter=
Snip:

image.png (468×874 px, 88 KB)

I am using Firefox version 88.0 and this is making translating big strings using the translation interface impossible.

Apr 20 2021, 1:30 PM · Browser-Support-Firefox, MediaWiki-extensions-Translate

Apr 14 2021

R4356th added a comment to T276688: HTTP 403 rest-write-denied error - Caught exception of type Flow\Exception\NoParserException.

It was due to a downstream configuration issue with permissions, not an issue with the extension itself.

Apr 14 2021, 9:04 PM · StructuredDiscussions, Growth-Team, User-RhinosF1
R4356th added a watcher for DarkMode: R4356th.
Apr 14 2021, 8:48 PM
R4356th changed the status of T276688: HTTP 403 rest-write-denied error - Caught exception of type Flow\Exception\NoParserException from Resolved to Invalid.
Apr 14 2021, 8:47 PM · StructuredDiscussions, Growth-Team, User-RhinosF1

Mar 29 2021

R4356th moved T273090: Deploy modern Vector and new Vue.js search experience to new pilot wikis from Backlog to Closed on the Bengali-Sites board.
Mar 29 2021, 7:38 AM · Bengali-Sites, Serbian-Sites, Turkish-Sites, Readers-Web-Backlog (Kanbanana-FY-2020-21), Design-Systems-team (Vue.js Search Experience (Vector modern)), Desktop Improvements

Mar 28 2021

R4356th moved T6554: Set up mailing list for Bengali Wikipedia from Backlog to Closed on the Bengali-Sites board.
Mar 28 2021, 4:29 PM · SRE, Bengali-Sites, Wikimedia-Mailing-lists

Mar 13 2021

R4356th moved T273477: Update Wikivoyage logos (Vector modern & mobile) from Backlog to Closed on the Bengali-Sites board.
Mar 13 2021, 4:16 PM · Bengali-Sites, Turkish-Sites, Logos, Readers-Web-Backlog (Kanbanana-FY-2020-21), Desktop Improvements

Mar 12 2021

R4356th moved T274784: CDN cache revalidation on several wikis for desktop improvements deployment pt 2 from Backlog to Closed on the Bengali-Sites board.
Mar 12 2021, 4:01 PM · Readers-Web-Backlog (Kanbanana-FY-2020-21), Bengali-Sites, Serbian-Sites, Turkish-Sites, Performance-Team (Radar), SRE, Traffic, Desktop Improvements

Mar 10 2021

R4356th added a watcher for User-notice: R4356th.
Mar 10 2021, 4:19 PM

Mar 9 2021

R4356th added a project to T276954: "(next page)" link on Categories ignores the `pagefrom` parameter when the Video extension is installed: MediaWiki-Categories.
Mar 9 2021, 4:42 PM · Social-Tools, Video (non-WMF), MediaWiki-Categories, User-RhinosF1

Mar 8 2021

R4356th moved T163428: Port CopyPatrol to the Bengali Wikipedia from Backlog to Closed on the Bengali-Sites board.
Mar 8 2021, 5:16 PM · Community-Tech, Bengali-Sites, CopyPatrol
R4356th moved T276739: Get Wikimedia added to disconnect.me entity list from To Triage to Not ready to announce on the User-notice board.
Mar 8 2021, 4:50 AM · Platform Team Workboards (Clinic Duty Team), Browser-Support-Firefox, MediaWiki-extensions-CentralAuth

Feb 22 2021

R4356th set IRC Nick to R4356th on R4356th.
Feb 22 2021, 5:42 AM

Feb 20 2021

R4356th moved T259896: Integrate MediaSearch backend into Visual Editor from To Triage to In current Tech/News draft on the User-notice board.
Feb 20 2021, 4:37 PM · User-notice, MW-1.36-notes (1.36.0-wmf.31; 2021-02-16), Structured-Data-Backlog (Current Work), SDAW-MediaSearch (MediaSearch-ReleaseCandidate)
R4356th added a project to T259896: Integrate MediaSearch backend into Visual Editor: User-notice.

Adding User-notice as this is included in the upcoming publication of Tech News.

Feb 20 2021, 4:37 PM · User-notice, MW-1.36-notes (1.36.0-wmf.31; 2021-02-16), Structured-Data-Backlog (Current Work), SDAW-MediaSearch (MediaSearch-ReleaseCandidate)
R4356th moved T274741: Update Pygments to latest 2.8.0 from To Triage to In current Tech/News draft on the User-notice board.
Feb 20 2021, 3:01 PM · User-notice, MW-1.36-notes (1.36.0-wmf.32; 2021-02-23), SyntaxHighlight

Feb 16 2021

R4356th moved T273758: Restart x1 database master (db1103) from In current Tech/News draft to Already announced/Archive on the User-notice board.

This was announced in Tech News yesterday.

Feb 16 2021, 7:54 AM · User-notice, SRE, Product-Infrastructure-Team-Backlog, WikimediaEditorTasks, Reading List Service, ContentTranslation, MediaWiki-extensions-BounceHandler, StructuredDiscussions, MediaWiki-extensions-UrlShortener, Cognate, Language-Team, Growth-Team, Orchestrator, DBA

Feb 10 2021

R4356th added a watcher for Tech-Ambassadors: R4356th.
Feb 10 2021, 1:02 PM

Jan 7 2021

R4356th awarded T270767: Wg variables aren't validated by CommentBox - possible raw html insertion risk (CVE-2021-31550) a Like token.
Jan 7 2021, 8:57 AM · Vuln-XSS, MediaWiki-extensions-Commentbox, User-RhinosF1