Page MenuHomePhabricator

RhinosF1 (Samuel)
Volunteer Configurator

Today

  • No visible events.

Tomorrow

  • No visible events.

Monday

  • No visible events.

User Details

User Since
Dec 27 2018, 1:42 PM (381 w, 1 d)
Availability
Available
IRC Nick
RhinosF1
LDAP User
RhinosF1
MediaWiki User
RhinosF1 [ Global Accounts ]

See meta.wikimedia.org/wiki/User:RhinosF1

A list of valid alts is at https://meta.wikimedia.org/wiki/User:RhinosF1/Alts

Recent Activity

Wed, Apr 15

RhinosF1 added a project to T423519: userlogout-temp-moreinfo is unnecessarily scaring users: affects-Miraheze.
Wed, Apr 15, 7:48 PM · MW-1.46-release, MW-1.45-release, affects-Miraheze, Temporary accounts, Product Safety and Integrity, MediaWiki-User-login-and-signup

Sun, Apr 12

RhinosF1 updated the task description for T423035: Gerrit outage didn't page until 4.5 hours after the first alert.
Sun, Apr 12, 2:53 PM · Sustainability (Incident Followup), observability, collaboration-services
RhinosF1 renamed T423027: 2026-04-12 Gerrit Outage (was: DiskSpace) from DiskSpace to 2026-04-12 Gerrit Outage (was: DiskSpace).
Sun, Apr 12, 2:46 PM · Patch-For-Review, Wikimedia-Incident, Gerrit, collaboration-services
RhinosF1 created T423035: Gerrit outage didn't page until 4.5 hours after the first alert.
Sun, Apr 12, 2:45 PM · Sustainability (Incident Followup), observability, collaboration-services
RhinosF1 added a project to T423027: 2026-04-12 Gerrit Outage (was: DiskSpace): Wikimedia-Incident.
Sun, Apr 12, 2:40 PM · Patch-For-Review, Wikimedia-Incident, Gerrit, collaboration-services

Wed, Apr 8

RhinosF1 added a member for Wikinews-Developer-Group: RhinosF1.
Wed, Apr 8, 5:42 PM

Thu, Apr 2

RhinosF1 added a comment to T422130: Database servers in cluster(number) are overloaded.

Should I expect the coming backport window be cancelled or delayed due to this incident?

Thu, Apr 2, 11:01 AM · Wikimedia-Incident, SRE, DBA
RhinosF1 added a project to T422130: Database servers in cluster(number) are overloaded: Wikimedia-Incident.
Thu, Apr 2, 10:52 AM · Wikimedia-Incident, SRE, DBA

Mar 17 2026

RhinosF1 added a subtask for T419265: CSP adjustments related to the 2026 user javascript incident: T420291: iNaturalist2Commons user script can't load image thumbnails from iNaturalist any more due to Content Security Policy.
Mar 17 2026, 7:40 AM · Sustainability (Incident Followup), User-notice, 2026-user-javascript-incident, Product Safety and Integrity, ContentSecurityPolicy
RhinosF1 added a parent task for T420291: iNaturalist2Commons user script can't load image thumbnails from iNaturalist any more due to Content Security Policy: T419265: CSP adjustments related to the 2026 user javascript incident.
Mar 17 2026, 7:40 AM · SecTeam-Processed, Sustainability (Incident Followup), Security-Team, Product Safety and Integrity, Commons, 2026-user-javascript-incident, Security

Mar 15 2026

RhinosF1 added a project to T420146: Content Security Policy now breaks use of iNaturalist API on Commons: Product Safety and Integrity.
Mar 15 2026, 5:32 PM · Commons, Product Safety and Integrity, 2026-user-javascript-incident, Security
RhinosF1 added a subtask for T419265: CSP adjustments related to the 2026 user javascript incident: T420146: Content Security Policy now breaks use of iNaturalist API on Commons.
Mar 15 2026, 5:32 PM · Sustainability (Incident Followup), User-notice, 2026-user-javascript-incident, Product Safety and Integrity, ContentSecurityPolicy
RhinosF1 added a parent task for T420146: Content Security Policy now breaks use of iNaturalist API on Commons: T419265: CSP adjustments related to the 2026 user javascript incident.
Mar 15 2026, 5:32 PM · Commons, Product Safety and Integrity, 2026-user-javascript-incident, Security
RhinosF1 added a project to T420146: Content Security Policy now breaks use of iNaturalist API on Commons: 2026-user-javascript-incident.
Mar 15 2026, 5:30 PM · Commons, Product Safety and Integrity, 2026-user-javascript-incident, Security

Mar 13 2026

RhinosF1 updated subscribers of T419929: Information Disclosure of Sensitive Wiki Configurations via ApiQueryWikiConfig.

Restoring subscribers

Mar 13 2026, 1:04 PM · affects-Miraheze, Security, Security-Team
RhinosF1 updated subscribers of T419928: Authorization Bypass in Special:ManageWiki via Dynamic Module Parameter manipulation.

Restoring subscribers

Mar 13 2026, 1:04 PM · affects-Miraheze, Security, Security-Team
RhinosF1 closed T419922: Unauthenticated Debug Mode Bypass Allows Cache Circumvention and Source Exposure in RenderBlocking Extension as Declined.

As per the other 3, AI slop that wasn't even reported to the correct place.

Mar 13 2026, 7:17 AM · affects-Miraheze, Security, Security-Team
RhinosF1 added a comment to T419928: Authorization Bypass in Special:ManageWiki via Dynamic Module Parameter manipulation.

Security issues with ManageWiki are not tracked on Wikimedia Phab. Please report this to https://issue-tracker.miraheze.org/maniphest/task/edit/form/2/

Mar 13 2026, 3:40 AM · affects-Miraheze, Security, Security-Team
RhinosF1 updated subscribers of T419928: Authorization Bypass in Special:ManageWiki via Dynamic Module Parameter manipulation.
Mar 13 2026, 3:31 AM · affects-Miraheze, Security, Security-Team
RhinosF1 updated subscribers of T419929: Information Disclosure of Sensitive Wiki Configurations via ApiQueryWikiConfig.
Mar 13 2026, 3:29 AM · affects-Miraheze, Security, Security-Team
RhinosF1 closed T419929: Information Disclosure of Sensitive Wiki Configurations via ApiQueryWikiConfig as Invalid.

Not only is this reported to the wrong place, this is not a security issue in the slightest.

Mar 13 2026, 3:29 AM · affects-Miraheze, Security, Security-Team
RhinosF1 closed T419928: Authorization Bypass in Special:ManageWiki via Dynamic Module Parameter manipulation as Declined.

Security issues with ManageWiki are not tracked on Wikimedia Phab. Please report this to https://issue-tracker.miraheze.org/maniphest/task/edit/form/2/

Mar 13 2026, 3:25 AM · affects-Miraheze, Security, Security-Team
RhinosF1 updated subscribers of T419928: Authorization Bypass in Special:ManageWiki via Dynamic Module Parameter manipulation.
Mar 13 2026, 3:23 AM · affects-Miraheze, Security, Security-Team

Mar 7 2026

RhinosF1 added a member for 2026-user-javascript-incident: RhinosF1.
Mar 7 2026, 8:14 AM

Mar 4 2026

RhinosF1 added a comment to T418201: wikimedia-l was signed up for a developer account.

Thank you :)

Mar 4 2026, 11:57 AM · SRE, Bitu, Infrastructure-Foundations
RhinosF1 added a comment to T418201: wikimedia-l was signed up for a developer account.

Thank you :)

Mar 4 2026, 11:57 AM · SRE, Bitu, Infrastructure-Foundations

Feb 24 2026

RhinosF1 created T418201: wikimedia-l was signed up for a developer account.
Feb 24 2026, 8:07 AM · SRE, Bitu, Infrastructure-Foundations

Feb 15 2026

RhinosF1 added a comment to T417498: OpenGraph meta tag lists site logo instead of uploaded image when linking to file page.

I think this is what the open graph metadata is documented to do but it also seems a bit of a questionable UX and whether someone would expect it

Feb 15 2026, 11:00 AM · WikiSEO, affects-Miraheze
RhinosF1 renamed T417498: OpenGraph meta tag lists site logo instead of uploaded image when linking to file page from OpenGraph meta tag lists site logo instead of a picture from the wiki page to OpenGraph meta tag lists site logo instead of uploaded image when linking to file page.
Feb 15 2026, 10:59 AM · WikiSEO, affects-Miraheze
RhinosF1 updated the task description for T417498: OpenGraph meta tag lists site logo instead of uploaded image when linking to file page.
Feb 15 2026, 10:55 AM · WikiSEO, affects-Miraheze

Jan 20 2026

RhinosF1 added a project to T414574: Magic word Parser cache expiry not applied when page uses main slot + additional slot: affects-Miraheze.
Jan 20 2026, 7:58 AM · affects-Miraheze, Multi-Content-Revisions, MediaWiki-Parser

Jan 12 2026

RhinosF1 added a project to T414386: <spam>: Trash.
Jan 12 2026, 10:09 PM · Trash

Dec 31 2025

RhinosF1 added a comment to T363726: ?action=info should have a Table of Contents.

Thanks for the note!
I’ve added the Bug: T363726 line to the commit message and uploaded a new patch set.
Please let me know if anything else is needed.

You will need to address the CI failures. See the comment on your patch from Jenkins Bot.

Dec 31 2025, 3:30 PM · User-notice-archive, MW-1.46-notes (1.46.0-wmf.16; 2026-02-17), Patch-For-Review, good first task, Accessibility, MediaWiki-User-Interface (actions)
RhinosF1 added a comment to T363726: ?action=info should have a Table of Contents.

Update: I’ve implemented the Table of Contents for action=info pages and uploaded a patch to Gerrit.

The TOC is dynamically generated when multiple sections are present, inserted at the top of the page, and avoids duplication. This improves navigation and accessibility on longer Page information views.

Gerrit change:
https://gerrit.wikimedia.org/r/c/mediawiki/core/+/1221669/

The patch is now awaiting review. I’m happy to address any feedback or follow-up improvements if needed.

Dec 31 2025, 11:53 AM · User-notice-archive, MW-1.46-notes (1.46.0-wmf.16; 2026-02-17), Patch-For-Review, good first task, Accessibility, MediaWiki-User-Interface (actions)
RhinosF1 assigned T413619: Update UploadWizard's "1930" messages for so-old-they're-PD-in-the-US to 1931, now that it's 2026 to Talhasajid849.
Dec 31 2025, 11:51 AM · UploadWizard
RhinosF1 added a comment to T413619: Update UploadWizard's "1930" messages for so-old-they're-PD-in-the-US to 1931, now that it's 2026.

I submitted a Gerrit change updating the UploadWizard PD-US license year to 1931.

Patch: https://gerrit.wikimedia.org/r/1222270

Dec 31 2025, 11:47 AM · UploadWizard

Dec 29 2025

RhinosF1 added a project to T413568: Remove Comment_IP/Comment_Vote_IP from the Comments extension: affects-Miraheze.
Dec 29 2025, 1:13 PM · Social-Tools, affects-Miraheze, MediaWiki-extensions-Comments

Dec 14 2025

RhinosF1 closed T400449: Requesting GitLab account activation for Swayam_Agrahari as Resolved.

GitLab account pending approval

I created a GitLab account using my Wikimedia Developer Account,
but my account is still pending approval and blocked.

Username: Roger

Dec 14 2025, 12:59 PM · GitLab (Account Approval), Release-Engineering-Team
RhinosF1 reopened T400449: Requesting GitLab account activation for Swayam_Agrahari as "Open".
Dec 14 2025, 12:44 PM · GitLab (Account Approval), Release-Engineering-Team

Dec 9 2025

RhinosF1 added a comment to T412150: Allow Trusted-Contributors to change WIP/Active state of a patch.

Allowing patch author / owner to update WIP/Active is probably worth upstream task too. Note to future me: https://www.gerritcodereview.com/issues.html

Dec 9 2025, 7:48 PM · Gerrit
RhinosF1 created T412150: Allow Trusted-Contributors to change WIP/Active state of a patch.
Dec 9 2025, 7:47 PM · Gerrit

Nov 28 2025

RhinosF1 renamed T411235: Beta cluster scap using php8.1 container; php8.2 is now required from Beta cluster is running an unsupported version of PHP to Beta cluster CI is running an unsupported version of PHP.
Nov 28 2025, 6:50 AM · User-bd808, ci-test-error, Beta-Cluster-Infrastructure
RhinosF1 added a comment to T408275: 1.46.0-wmf.5 deployment blockers.

FYI - Beta scap is broken due to T411235: Beta cluster scap using php8.1 container; php8.2 is now required

Nov 28 2025, 6:46 AM · Release-Engineering-Team (Priority Backlog 📥), Essential-Work, Release, Train Deployments
RhinosF1 created T411235: Beta cluster scap using php8.1 container; php8.2 is now required.
Nov 28 2025, 6:44 AM · User-bd808, ci-test-error, Beta-Cluster-Infrastructure

Nov 2 2025

RhinosF1 added a project to T409014: Add English Gyaanipedia to Wikistats: VPS-project-Wikistats.
Nov 2 2025, 8:39 PM · VPS-project-Wikistats

Oct 17 2025

RhinosF1 added a member for Trusted-Contributors: TMWYK.
Oct 17 2025, 7:13 PM

Oct 9 2025

RhinosF1 added a project to T406895: WikiSEO cannot set an external URL as the image if $wgAllowExternalImages is set to true: affects-Miraheze.
Oct 9 2025, 4:06 PM · Patch-For-Review, affects-Miraheze, WikiSEO

Aug 27 2025

RhinosF1 closed T403052: Newly-added member of deployment-prep is not in bastion project, a subtask of T379550: openstack: keystone may be failing to add users to the bastion project in Keystone and/or LDAP, as Resolved.
Aug 27 2025, 3:35 PM · Cloud-VPS, User-aborrero, cloud-services-team
RhinosF1 closed T403052: Newly-added member of deployment-prep is not in bastion project as Resolved.
Aug 27 2025, 3:35 PM · Cloud-VPS, cloud-services-team

Aug 18 2025

RhinosF1 added a project to T402226: User email was not updated in phab after updating on-wiki: Release-Engineering-Team.
Aug 18 2025, 8:21 PM · Release-Engineering-Team, Phabricator
RhinosF1 added a project to T402226: User email was not updated in phab after updating on-wiki: Phabricator.
Aug 18 2025, 8:21 PM · Release-Engineering-Team, Phabricator
RhinosF1 added a comment to T402226: User email was not updated in phab after updating on-wiki.

Phabricator is a completely separate system with a separate authentication system.

Aug 18 2025, 8:20 PM · Release-Engineering-Team, Phabricator

Aug 7 2025

RhinosF1 added a comment to T397900: Warning: User::loadFromSession called before the end of Setup.php.

The second fix (the MediaWiki core one) seems to reduce many more logs than the other one (though both are still needed).

For example https://logstash.wikimedia.org/goto/1204feae3a5687f4dc1e81bc7fd37a3b shows all such warnings fixed by the second patch (2 million in the last week).

Therefore, we should probably also backport the fix to MediaWiki core as well to fix the logs for affects-Miraheze.

Aug 7 2025, 2:55 PM · MW-1.44-notes, MW-1.43-notes, Trust and Safety Product Sprint (Sprint Princess Tarta (August 18 - September 5)), Essential-Work, MW-1.45-notes (1.45.0-wmf.14; 2025-08-12), MediaWiki-Platform-Team (Radar), affects-Miraheze, Trust and Safety Product Team, MediaWiki-extensions-CentralAuth, GlobalBlocking
RhinosF1 added a comment to T397900: Warning: User::loadFromSession called before the end of Setup.php.

There are also a million other such warnings in the last week, but these do not appear to be caused by us (instead the Vector (legacy skin) skin).

I guess that should be split off into another task then

Aug 7 2025, 2:54 PM · MW-1.44-notes, MW-1.43-notes, Trust and Safety Product Sprint (Sprint Princess Tarta (August 18 - September 5)), Essential-Work, MW-1.45-notes (1.45.0-wmf.14; 2025-08-12), MediaWiki-Platform-Team (Radar), affects-Miraheze, Trust and Safety Product Team, MediaWiki-extensions-CentralAuth, GlobalBlocking

Aug 4 2025

RhinosF1 updated subscribers of T401099: CVE-2025-61638: Sanitizer::validateAttributes data-XSS.
Aug 4 2025, 11:10 AM · MW-1.44-release, MW-1.43-release, MW-1.39-release, Content-Transform-Team (Work In Progress), SecTeam-Processed, Vuln-XSS, MediaWiki-Parser, Security, Security-Team

Jul 10 2025

RhinosF1 updated the task description for T397776: Write and send supplementary release announcement for extensions and skins with security patches (1.39.14/1.43.4/1.44.1).
Jul 10 2025, 7:50 AM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security

Jul 9 2025

RhinosF1 updated the task description for T399132: Add security reports from 1.39.13/1.42.7/1.43.2/1.44.0 (+ extension supplement) to security hall of fame.
Jul 9 2025, 8:57 PM · SecTeam-Processed, affects-Miraheze, Security-Team
RhinosF1 updated the task description for T399132: Add security reports from 1.39.13/1.42.7/1.43.2/1.44.0 (+ extension supplement) to security hall of fame.
Jul 9 2025, 8:55 PM · SecTeam-Processed, affects-Miraheze, Security-Team
RhinosF1 updated the task description for T397776: Write and send supplementary release announcement for extensions and skins with security patches (1.39.14/1.43.4/1.44.1).
Jul 9 2025, 8:48 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 created T399132: Add security reports from 1.39.13/1.42.7/1.43.2/1.44.0 (+ extension supplement) to security hall of fame.
Jul 9 2025, 8:43 PM · SecTeam-Processed, affects-Miraheze, Security-Team

Jul 7 2025

RhinosF1 updated subscribers of T392341: CVE-2025-53483, CVE-2025-53484, CVE-2025-53485: SecurePoll is vulnerable to XSS, CSRF, and lack of authorisation.
Jul 7 2025, 8:01 PM · Trust and Safety Product Sprint (Sprint Princess Tarta (August 18 - September 5)), Essential-Work, Patch-For-Review, Trust and Safety Product Team, Vuln-BrokenAccessControl, affects-Miraheze, Vuln-CSRF, Vuln-XSS, MediaWiki-extensions-SecurePoll, Security, Security-Team

Jul 5 2025

RhinosF1 added a comment to T398753: Too Many Requests Error on certain useragents (QtWebEngine, outdated chromium based browsers, Safari 605).

I suspect it's similar to https://lists.wikimedia.org/hyperkitty/list/wikitech-l@lists.wikimedia.org/message/3DNR7FALKHAU4L5ZUBRNP4Q4YWXLGABB/

Jul 5 2025, 2:47 PM · Traffic

Jul 3 2025

RhinosF1 added a comment to T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).

I'm extremely late adding them so if I'm too late then apologies but I added the 2 other ManageWiki CVEs that I forgot to add here

Since they are tracked outside of Phab/Gerrit and have CVEs assigned and merged patches already, it should be fairly trivial to include them for this release.

Thanks, I added the 5 CVEs from the last citizen release too. I'll try and think of a good way of tracking the ones we find that are from non-Wikimedia maintained extensions. It shouldn't be too difficult now both me and @Paladox have security access to create a Miraheze equivalent we can sync up to here close to the release for the next one. Obviously not sharing anything from here the other way around, just us sharing up to you.

Jul 3 2025, 6:11 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 updated the task description for T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).
Jul 3 2025, 6:02 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 updated the task description for T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).
Jul 3 2025, 5:55 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 updated the task description for T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).
Jul 3 2025, 5:53 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 updated the task description for T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).
Jul 3 2025, 5:51 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 updated the task description for T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).
Jul 3 2025, 5:51 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 added a comment to T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).

T394869: CVE-2025-7056: Stored XSS through a system message in UrlShortener and T394612: CVE-2025-7057: Stored XSS through a system message in Extension:Quiz are WMF tracked and missing off the list too

Jul 3 2025, 12:22 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 updated the task description for T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).
Jul 3 2025, 12:21 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 updated subscribers of T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).

I'm extremely late adding them so if I'm too late then apologies but I added the 2 other ManageWiki CVEs that I forgot to add here

Since they are tracked outside of Phab/Gerrit and have CVEs assigned and merged patches already, it should be fairly trivial to include them for this release.

Jul 3 2025, 12:17 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 updated the task description for T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).
Jul 3 2025, 12:12 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security

Jul 2 2025

RhinosF1 added a comment to T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).

I'm extremely late adding them so if I'm too late then apologies but I added the 2 other ManageWiki CVEs that I forgot to add here

Jul 2 2025, 4:34 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 updated the task description for T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).
Jul 2 2025, 4:33 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 added a comment to T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).

Subject: MediaWiki Extensions and Skins Security Release Supplement (1.39.13/1.42.7/1.43.2)

Greetings-

With the security/maintenance release of MediaWiki 1.39.13/1.42.7/1.43.2, we would also like to provide this supplementary announcement of MediaWiki extensions and skins with now-public Phabricator tasks, security patches and backports [1]:

ManageWiki
+ (https://github.com/miraheze/ManageWiki/security/advisories/GHSA-gg42-cv66-f5x7, CVE-2025-32956) - SQL injection vulnerability in NamespaceMigrationJob
https://github.com/miraheze/ManageWiki/commit/f504ed8eeb59b57ebb90f93cd44f23da4c5bc4c9

The Wikimedia Security Team recommends updating these extensions and/or skins to the current master branch or relevant, supported release branch [2] as soon as possible. Some of the referenced Phabricator tasks above _may_ still be private. Unfortunately, when security issues are reported, sometimes sensitive information is exposed and since Phabricator is historical, we cannot make these tasks public without exposing this sensitive information. If you have any additional questions or concerns regarding this update, please feel free to contact security@wikimedia.org or file a security task within Phabricator [3].

[1] https://phabricator.wikimedia.org/T389312
[2] https://www.mediawiki.org/wiki/Version_lifecycle
[3] https://www.mediawiki.org/wiki/Reporting_security_bugs

Jul 2 2025, 4:29 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security

Jun 29 2025

RhinosF1 updated subscribers of T394614: New upstream release for Pywikibot.

@rook used to be, I created https://github.com/toolforge/paws/pull/488

Jun 29 2025, 4:58 PM · User-RhinosF1, PAWS

Jun 26 2025

RhinosF1 updated the task description for T397900: Warning: User::loadFromSession called before the end of Setup.php.
Jun 26 2025, 7:02 AM · MW-1.44-notes, MW-1.43-notes, Trust and Safety Product Sprint (Sprint Princess Tarta (August 18 - September 5)), Essential-Work, MW-1.45-notes (1.45.0-wmf.14; 2025-08-12), MediaWiki-Platform-Team (Radar), affects-Miraheze, Trust and Safety Product Team, MediaWiki-extensions-CentralAuth, GlobalBlocking
RhinosF1 updated the task description for T397900: Warning: User::loadFromSession called before the end of Setup.php.
Jun 26 2025, 6:54 AM · MW-1.44-notes, MW-1.43-notes, Trust and Safety Product Sprint (Sprint Princess Tarta (August 18 - September 5)), Essential-Work, MW-1.45-notes (1.45.0-wmf.14; 2025-08-12), MediaWiki-Platform-Team (Radar), affects-Miraheze, Trust and Safety Product Team, MediaWiki-extensions-CentralAuth, GlobalBlocking
RhinosF1 removed a project from T397900: Warning: User::loadFromSession called before the end of Setup.php: Wikimedia-production-error.
Jun 26 2025, 6:50 AM · MW-1.44-notes, MW-1.43-notes, Trust and Safety Product Sprint (Sprint Princess Tarta (August 18 - September 5)), Essential-Work, MW-1.45-notes (1.45.0-wmf.14; 2025-08-12), MediaWiki-Platform-Team (Radar), affects-Miraheze, Trust and Safety Product Team, MediaWiki-extensions-CentralAuth, GlobalBlocking
RhinosF1 created T397900: Warning: User::loadFromSession called before the end of Setup.php.
Jun 26 2025, 6:50 AM · MW-1.44-notes, MW-1.43-notes, Trust and Safety Product Sprint (Sprint Princess Tarta (August 18 - September 5)), Essential-Work, MW-1.45-notes (1.45.0-wmf.14; 2025-08-12), MediaWiki-Platform-Team (Radar), affects-Miraheze, Trust and Safety Product Team, MediaWiki-extensions-CentralAuth, GlobalBlocking

Jun 24 2025

RhinosF1 added a comment to T385811: Vector should not direct third-party wikis to report dark mode issues to MW.o.

It's saddening to see this antipattern again after years of MediaViewer third-party misconfiguration issues (mis)filed in Wikimedia Phabricator due to hardcoding a Wikimedia URI in an extension that can also be used outside of Wikimedia.

Jun 24 2025, 10:59 AM · Verified, MW-1.45-notes (1.45.0-wmf.17; 2025-09-02), Reader Experience Team, Readers Essential Work, MW-1.44-release, Patch-For-Review, affects-Miraheze, good first task, patch-welcome, WikimediaMessages, MW-1.43-release, Vector 2022
RhinosF1 added a comment to T397679: Non Wikimedia wikis users report dark mode issues on mediawiki.org and causing IP leaks..

There is already a task for this. I don't think it's a security issue or there's need to suppress IPs.

Jun 24 2025, 7:22 AM · SecTeam-Processed, affects-Miraheze
RhinosF1 merged T397679: Non Wikimedia wikis users report dark mode issues on mediawiki.org and causing IP leaks. into T385811: Vector should not direct third-party wikis to report dark mode issues to MW.o.
Jun 24 2025, 7:20 AM · Verified, MW-1.45-notes (1.45.0-wmf.17; 2025-09-02), Reader Experience Team, Readers Essential Work, MW-1.44-release, Patch-For-Review, affects-Miraheze, good first task, patch-welcome, WikimediaMessages, MW-1.43-release, Vector 2022
RhinosF1 merged task T397679: Non Wikimedia wikis users report dark mode issues on mediawiki.org and causing IP leaks. into T385811: Vector should not direct third-party wikis to report dark mode issues to MW.o.
Jun 24 2025, 7:20 AM · SecTeam-Processed, affects-Miraheze

Jun 11 2025

RhinosF1 updated subscribers of T396413: CVE-2025-53497: Stored XSS in RelatedArticles.
Jun 11 2025, 3:34 PM · Web-Team, RelatedArticles, affects-Miraheze, Vuln-XSS, Security, Security-Team
RhinosF1 updated subscribers of T396413: CVE-2025-53497: Stored XSS in RelatedArticles.
Jun 11 2025, 3:34 PM · Web-Team, RelatedArticles, affects-Miraheze, Vuln-XSS, Security, Security-Team
RhinosF1 added a comment to T396413: CVE-2025-53497: Stored XSS in RelatedArticles.
Jun 11 2025, 3:33 PM · Web-Team, RelatedArticles, affects-Miraheze, Vuln-XSS, Security, Security-Team
RhinosF1 added a comment to T396413: CVE-2025-53497: Stored XSS in RelatedArticles.

...I would recommend quickly assessing whether there is any impact outside RelatedArticles before applying the fix and making this public.

We'd plan to deploy this as a security patch to Wikimedia production. We'd want to hold off on making it public in gerrit until the next supplemental security release.

Jun 11 2025, 1:26 PM · Web-Team, RelatedArticles, affects-Miraheze, Vuln-XSS, Security, Security-Team

Jun 9 2025

RhinosF1 added a comment to T394708: Security issue access for Paladox.

Thanks all!

Jun 9 2025, 4:19 PM · SecTeam-Processed, Security, Security-Team, affects-Miraheze

Jun 5 2025

RhinosF1 added a comment to T395934: NEW BUG REPORT: Investigate rise in May 2025 Reader metrics.

Slightly note of an interest, I saw a very similar pattern recently for Miraheze in our Cloudflare data so possible this affects for than the WMF. I can pull actual data later.

Jun 5 2025, 6:14 AM · Movement-Insights (FY25-26 H1), Data-Engineering (Q1 FY25/26 July 1st - September 30th), Traffic

May 29 2025

RhinosF1 updated subscribers of T394708: Security issue access for Paladox.

@KFrancis: can you start that?

May 29 2025, 4:07 PM · SecTeam-Processed, Security, Security-Team, affects-Miraheze

May 27 2025

RhinosF1 added a comment to T394938: CVE-2025-53494: Stored XSS through a system message in TwoColConflict.

I removed it because it needed to be brought to security team's attention again because somehow the report in _security & via email was completely missed.

It's not for you to remove. Please do not do it again. There are other ways of contacting the Security-Team, as you've mentioned above. Both of which did receive replies as you have incorrectly noted here. Two on-call WMF staff members both correctly described this issue as low risk and not an immediate worry in #mediawiki_security, responding to @Urbanecm's message. That answer should absolutely have sufficed. I also replied to your email this morning and noted that the security team would be getting to these issues today during our clinic, which was delayed due to a Monday US holiday and an ongoing Wikimedia production incident. The Security-Team does not have unlimited resources nor do we guarantee 24/7 on-call services for every possible security-related issue.

There is still a process to follow though that security team are supposed to manage for WMF Deployed code. If this was a third party extension, we'd normally wait on task for your triage and for you to determine whether it's safe to be made public via a gerrit patch (and normally ensure that patch gets a speedy review). For a WMF Deployed Security issue, you guys are supposed to help us manage the private patch and deployment process to ensure WMF wikis are patched before the issue is exposed and normally would then release yourselves at security release time. This task has gone against the norm for reasons I'm not certain of but the lack of engagement is again embarrassing.

Processes are great when they are followed. That wasn't the case here and not due to the actions of anyone on the Security-Team. When incidents like this happen, people have to take out-of-process actions to correct the matter, which doesn't always happen perfectly and instantly.

As far as I can tell, _security was ignored. My email wasn't read. The patch was +2'd despite already being merged. This isn't an effective security release and someone needs to explain why again we're chasing the basics.

Most of this is incorrect as I mentioned above. I gave a quick +2 because from the comments on this task, it seemed like the patch hadn't been merged yet, nor cut for 1.45.0-wmf.3, both of which were incorrect. You're free to form your own opinions but I would advise not doing so on false assumptions and misinformation.

May 27 2025, 5:14 PM · SecTeam-Processed, WMDE-TechWish-Sprint-2025-05-14, Two-Column-Edit-Conflict-Merge, affects-Miraheze, Vuln-XSS, Security, Security-Team
RhinosF1 added a comment to T394938: CVE-2025-53494: Stored XSS through a system message in TwoColConflict.

Please don't remove SecTeam-Processed. That's an internal tag for the Security-Team's tracking.

I removed it because it needed to be brought to security team's attention again because somehow the report in _security & via email was completely missed.

This is already on 1.45.0-wmf.3, so at this point it just needs to ride the train the rest of the week to land in Wikimedia production. For most of these message XSS issues, we've traditionally considered them low risk since you'd need to compromise the MediaWiki message as well, which is non-trivial for unprivileged users.

Once a patch is up in gerrit, it can be backported by pretty much anyone. I can get those started now for supported release versions.

There is still a process to follow though that security team are supposed to manage for WMF Deployed code. If this was a third party extension, we'd normally wait on task for your triage and for you to determine whether it's safe to be made public via a gerrit patch (and normally ensure that patch gets a speedy review). For a WMF Deployed Security issue, you guys are supposed to help us manage the private patch and deployment process to ensure WMF wikis are patched before the issue is exposed and normally would then release yourselves at security release time. This task has gone against the norm for reasons I'm not certain of but the lack of engagement is again embarrassing.

May 27 2025, 4:36 PM · SecTeam-Processed, WMDE-TechWish-Sprint-2025-05-14, Two-Column-Edit-Conflict-Merge, affects-Miraheze, Vuln-XSS, Security, Security-Team
RhinosF1 removed a project from T394938: CVE-2025-53494: Stored XSS through a system message in TwoColConflict: SecTeam-Processed.
May 27 2025, 4:03 PM · SecTeam-Processed, WMDE-TechWish-Sprint-2025-05-14, Two-Column-Edit-Conflict-Merge, affects-Miraheze, Vuln-XSS, Security, Security-Team
RhinosF1 updated subscribers of T394938: CVE-2025-53494: Stored XSS through a system message in TwoColConflict.

Untagging Security-Team as it looks like WMDE plans to review this? Since this extension is Wikimedia-production-deployed, please code-review on this task and do not push the patch to gerrit. Once reviewed, the Security-Team can assist with a Wikimedia production deployment.

A bit late for that one. As per my email to security-help and flag by @Urbanecm in _security on IRC, this has been public for 48 hours on gerrit and afaik not deployed to production.

May 27 2025, 4:02 PM · SecTeam-Processed, WMDE-TechWish-Sprint-2025-05-14, Two-Column-Edit-Conflict-Merge, affects-Miraheze, Vuln-XSS, Security, Security-Team

May 25 2025

RhinosF1 added a comment to T395201: Quarry down - web service unreachable.

04:32:28 <wmcs-alerts> FIRING: [2x] TargetDown: Job app is unreachable in project quarry instance quarry.wmcloud.org:443  - https://prometheus-alerts.wmcloud.org/?q=alertname%3DTargetDown
04:32:39 <wmcs-alerts> FIRING: QuarryDown: Quarry application is unreachable  - https://prometheus-alerts.wmcloud.org/?q=alertname%3DQuarryDown

May 25 2025, 7:11 AM · Quarry
RhinosF1 renamed T395201: Quarry down - web service unreachable from Is Quarry down? to Quarry down - web service unreachable.
May 25 2025, 7:09 AM · Quarry

May 22 2025

RhinosF1 updated subscribers of T394721: CVE-2025-7363: XSS in TitleIcon.

Please also do a version bump to 6.2.1 in extension.json in all patched branches that did not get a MW version bump and a version bump to 6.3.0 in all branches that got a MW version bump from 1.39.0 to 1.40.0. Thank you!

Hi Cindy, I don't think that's a normal part of the security patching process. If you want to follow up with a version bump, you're more than welcome to.

May 22 2025, 7:47 PM · SecTeam-Processed, Vuln-XSS, MediaWiki-extensions-Title-Icon, affects-Miraheze, Security, Security-Team

May 19 2025

RhinosF1 added a comment to T394708: Security issue access for Paladox.

I followed https://wikitech.wikimedia.org/wiki/Volunteer_NDA because you need an NDA as part of getting security issue access

May 19 2025, 6:25 PM · SecTeam-Processed, Security, Security-Team, affects-Miraheze
RhinosF1 created T394708: Security issue access for Paladox.
May 19 2025, 5:14 PM · SecTeam-Processed, Security, Security-Team, affects-Miraheze