Page MenuHomePhabricator

RhinosF1 (Samuel)
Volunteer Configurator

Today

  • No visible events.

Tomorrow

  • No visible events.

Tuesday

  • No visible events.

User Details

User Since
Dec 27 2018, 1:42 PM (398 w, 2 d)
Availability
Available
IRC Nick
RhinosF1
LDAP User
RhinosF1
MediaWiki User
RhinosF1 [ Global Accounts ]

See meta.wikimedia.org/wiki/User:RhinosF1

A list of valid alts is at https://meta.wikimedia.org/wiki/User:RhinosF1/Alts

Recent Activity

Jul 13 2026

RhinosF1 created T431967: Intermittent timeouts on Phab-ban tool.
Jul 13 2026, 7:22 AM · Tool-phab-ban, tools-platform-team, Toolforge

Jul 11 2026

RhinosF1 added a comment to T431934: Errorneous abusefilter permissions on dewiki.

Introduced in https://gerrit.wikimedia.org/r/c/operations/mediawiki-config/+/1247186/

Jul 11 2026, 8:49 PM · SecTeam-Processed, Wikimedia-Site-requests, AbuseFilter, Security, Security-Team

Jun 29 2026

RhinosF1 added a comment to T430563: Gitlab replica-b being indexed by Duck Duck Go.

Does it cause a problem?

It indexing the wrong site is a problem, yes. It means those visting from search engines will get the replica domain.

But what's the actual problem with that?

I mean, as long as it works, they can use it, they can clone from it. And it tells them clearly what it is and where the main instance is. We are not trying to hide that it exists, generally.

If there is a specific tag though that marks it as canonical, yea, totally, that should be the main one.

Jun 29 2026, 6:02 PM · Collaboration-Services, GitLab
RhinosF1 added a comment to T430563: Gitlab replica-b being indexed by Duck Duck Go.

I see a canonical tag on gitlab-replica-b, it should probably include gitlab.wikimedia.org instead of the replica domain

Jun 29 2026, 4:47 PM · Collaboration-Services, GitLab
RhinosF1 added a comment to T430563: Gitlab replica-b being indexed by Duck Duck Go.

Does it cause a problem?

Jun 29 2026, 4:46 PM · Collaboration-Services, GitLab

Jun 5 2026

RhinosF1 added a project to T422774: CVE-2026-14363: Cargo Extension: SQLi in Special:Drilldown: affects-Miraheze.
Jun 5 2026, 2:00 PM · affects-Miraheze, SecTeam-Processed, Vuln-Inject, MediaWiki-extensions-Cargo, Security

May 27 2026

RhinosF1 raised the priority of T427398: Unable to edit pages on Mediawiki namespace on 1.47.0-wmf.4, redirects to Verify your Identity page from High to Unbreak Now!.

Just to confirm: this does not appear to be affecting all wikis. When I try similar actions on enwiki, the reauth prompts work as expected for me.

That's because enwiki is still on 1.47.0-wmf.3. Once enwiki rolls to wmf.4, I believe it will break there too.

This feels like it should block the train from proceeding then

May 27 2026, 3:35 PM · MediaWiki-Core-Platform-Team (Kanban), MediaWiki-Core-AuthManager, MediaWiki-extensions-CentralAuth, Regression, Product Safety and Integrity, MediaWiki-User-login-and-signup
RhinosF1 added a parent task for T427398: Unable to edit pages on Mediawiki namespace on 1.47.0-wmf.4, redirects to Verify your Identity page: T423913: 1.47.0-wmf.4 deployment blockers.
May 27 2026, 3:35 PM · MediaWiki-Core-Platform-Team (Kanban), MediaWiki-Core-AuthManager, MediaWiki-extensions-CentralAuth, Regression, Product Safety and Integrity, MediaWiki-User-login-and-signup
RhinosF1 added a subtask for T423913: 1.47.0-wmf.4 deployment blockers: T427398: Unable to edit pages on Mediawiki namespace on 1.47.0-wmf.4, redirects to Verify your Identity page.
May 27 2026, 3:35 PM · Release-Engineering-Team (Priority Backlog 📥), Essential-Work, Release, Train Deployments

May 18 2026

RhinosF1 added a comment to T426631: CVE-2026-8857: Full RCE using EasyTimeline Extension.

Thanks for sharing the files here. Fandom engineering will apply this patch tomorrow.. Can you please hold off with applying the fix to the extension before that happens? Thanks1

@Gaperlinski @RhinosF1 et al - can you please confirm that when your teams deploy the ext:Timeline patches on this bug to your environments, that this will not be done publicly? We need to protect this security issue from disclosure until we are ready to make an official security release, which will not be in the near future.

I can confirm that the patches have been deployed through our private patches system and are not publicly accessible.

May 18 2026, 9:25 PM · MW-1.46-release, MW-1.45-release, MW-1.44-release, MW-1.43-release, affects-Miraheze, SecTeam-Processed, Vuln-RCE, EasyTimeline, Product Safety and Integrity, Security, Security-Team
RhinosF1 added a comment to T426631: CVE-2026-8857: Full RCE using EasyTimeline Extension.

How confident are we that this is the only issue of this type in the codebase?

follow up patch for additional hardening.

May 18 2026, 6:23 PM · MW-1.46-release, MW-1.45-release, MW-1.44-release, MW-1.43-release, affects-Miraheze, SecTeam-Processed, Vuln-RCE, EasyTimeline, Product Safety and Integrity, Security, Security-Team
RhinosF1 added a project to T426631: CVE-2026-8857: Full RCE using EasyTimeline Extension: affects-Miraheze.

cosmetic changes (filename, commit message) from previous version

May 18 2026, 5:40 PM · MW-1.46-release, MW-1.45-release, MW-1.44-release, MW-1.43-release, affects-Miraheze, SecTeam-Processed, Vuln-RCE, EasyTimeline, Product Safety and Integrity, Security, Security-Team
RhinosF1 updated subscribers of T426631: CVE-2026-8857: Full RCE using EasyTimeline Extension.

@sbassett, (or anyone else) this is also deployed on Miraheze. If you plan to deploy any mitigations to Wikimedia, can you give me a ping on IRC or on task as this sounds potentially serious and I'd like to replicate whatever is done and minimise the chance of this being exploited after WMF deploy any fix. I also don't want to deploy anything like disabling the extension first and expose the fact there's an issue.

May 18 2026, 3:25 PM · MW-1.46-release, MW-1.45-release, MW-1.44-release, MW-1.43-release, affects-Miraheze, SecTeam-Processed, Vuln-RCE, EasyTimeline, Product Safety and Integrity, Security, Security-Team
RhinosF1 added a project to T426631: CVE-2026-8857: Full RCE using EasyTimeline Extension: EasyTimeline.
May 18 2026, 3:19 PM · MW-1.46-release, MW-1.45-release, MW-1.44-release, MW-1.43-release, affects-Miraheze, SecTeam-Processed, Vuln-RCE, EasyTimeline, Product Safety and Integrity, Security, Security-Team

May 16 2026

RhinosF1 added a comment to T426511: De ce nu pot genera cont pagina de Wikipedia.

De ce nu pot genera cont pagina de Wikipedia

Are you receiving a specific error?

May 16 2026, 1:55 PM · Trash
RhinosF1 updated subscribers of T425850: Bing can't search images from Commons, is Wikimedia denying their requests?.

Have you tried to contact Bing why Bing behaves this way?

I don't think that should be the responsibility of random Wikimedia's when this is a wider issue. Traffic should be capable of checking their own logs and seeing if there are Microsoft IPs with a bing UA being blocked.

May 16 2026, 11:26 AM · SEO, Traffic

May 9 2026

RhinosF1 renamed T425852: Requesting GitLab account activation for dipanjansengupta from Requesting GitLab account activation for https://gitlab.wikimedia.org/dipanjansengupta , want to contribute to https://gitlab.wikimedia.org/cloudvps-repos/videocuttool/VideoCutTool to Requesting GitLab account activation for dipanjansengupta.
May 9 2026, 10:08 AM · GitLab (Account Approval), Release-Engineering-Team

Apr 15 2026

RhinosF1 added a project to T423519: userlogout-temp-moreinfo is unnecessarily scaring users: affects-Miraheze.
Apr 15 2026, 7:48 PM · Product Safety and Integrity (Sprint Sunflower (Aug 11 - Aug 28)), MW-1.47-notes (1.47.0-wmf.15; 2026-08-11), Essential-Work, Patch-For-Review, WikimediaMessages, MW-1.46-release, MW-1.45-release, affects-Miraheze, Temporary accounts, MediaWiki-User-login-and-signup

Apr 12 2026

RhinosF1 updated the task description for T423035: Enable paging for Gerrit (was: Gerrit outage didn't page until 4.5 hours after the first alert).
Apr 12 2026, 2:53 PM · Sustainability (Incident Followup), observability, Collaboration-Services
RhinosF1 renamed T423027: 2026-04-12 Gerrit Outage (was: DiskSpace) from DiskSpace to 2026-04-12 Gerrit Outage (was: DiskSpace).
Apr 12 2026, 2:46 PM · Incident Severity 3, Wikimedia-Incident, Gerrit, Collaboration-Services
RhinosF1 created T423035: Enable paging for Gerrit (was: Gerrit outage didn't page until 4.5 hours after the first alert).
Apr 12 2026, 2:45 PM · Sustainability (Incident Followup), observability, Collaboration-Services
RhinosF1 added a project to T423027: 2026-04-12 Gerrit Outage (was: DiskSpace): Wikimedia-Incident.
Apr 12 2026, 2:40 PM · Incident Severity 3, Wikimedia-Incident, Gerrit, Collaboration-Services

Apr 8 2026

RhinosF1 added a member for Wikinews-Developer-Group: RhinosF1.
Apr 8 2026, 5:42 PM

Apr 2 2026

RhinosF1 added a comment to T422130: External store unreachable: "Database servers in clusterXX are overloaded".

Should I expect the coming backport window be cancelled or delayed due to this incident?

Apr 2 2026, 11:01 AM · Incident Severity 3, Wikimedia-Incident, SRE, DBA
RhinosF1 added a project to T422130: External store unreachable: "Database servers in clusterXX are overloaded": Wikimedia-Incident.
Apr 2 2026, 10:52 AM · Incident Severity 3, Wikimedia-Incident, SRE, DBA

Mar 17 2026

RhinosF1 added a subtask for T419265: CSP adjustments related to the 2026 user javascript incident: T420291: iNaturalist2Commons user script can't load image thumbnails from iNaturalist any more due to Content Security Policy.
Mar 17 2026, 7:40 AM · Sustainability (Incident Followup), User-notice, 2026-user-javascript-incident, Product Safety and Integrity, ContentSecurityPolicy
RhinosF1 added a parent task for T420291: iNaturalist2Commons user script can't load image thumbnails from iNaturalist any more due to Content Security Policy: T419265: CSP adjustments related to the 2026 user javascript incident.
Mar 17 2026, 7:40 AM · SecTeam-Processed, Sustainability (Incident Followup), Security-Team, Product Safety and Integrity, Commons, 2026-user-javascript-incident, Security

Mar 15 2026

RhinosF1 added a project to T420146: Content Security Policy now breaks use of iNaturalist API on Commons: Product Safety and Integrity.
Mar 15 2026, 5:32 PM · Commons, Product Safety and Integrity, 2026-user-javascript-incident, Security
RhinosF1 added a subtask for T419265: CSP adjustments related to the 2026 user javascript incident: T420146: Content Security Policy now breaks use of iNaturalist API on Commons.
Mar 15 2026, 5:32 PM · Sustainability (Incident Followup), User-notice, 2026-user-javascript-incident, Product Safety and Integrity, ContentSecurityPolicy
RhinosF1 added a parent task for T420146: Content Security Policy now breaks use of iNaturalist API on Commons: T419265: CSP adjustments related to the 2026 user javascript incident.
Mar 15 2026, 5:32 PM · Commons, Product Safety and Integrity, 2026-user-javascript-incident, Security
RhinosF1 added a project to T420146: Content Security Policy now breaks use of iNaturalist API on Commons: 2026-user-javascript-incident.
Mar 15 2026, 5:30 PM · Commons, Product Safety and Integrity, 2026-user-javascript-incident, Security

Mar 13 2026

RhinosF1 updated subscribers of T419929: Information Disclosure of Sensitive Wiki Configurations via ApiQueryWikiConfig.

Restoring subscribers

Mar 13 2026, 1:04 PM · affects-Miraheze, Security, Security-Team
RhinosF1 updated subscribers of T419928: Authorization Bypass in Special:ManageWiki via Dynamic Module Parameter manipulation.

Restoring subscribers

Mar 13 2026, 1:04 PM · affects-Miraheze, Security, Security-Team
RhinosF1 closed T419922: Unauthenticated Debug Mode Bypass Allows Cache Circumvention and Source Exposure in RenderBlocking Extension as Declined.

As per the other 3, AI slop that wasn't even reported to the correct place.

Mar 13 2026, 7:17 AM · affects-Miraheze, Security, Security-Team
RhinosF1 added a comment to T419928: Authorization Bypass in Special:ManageWiki via Dynamic Module Parameter manipulation.

Security issues with ManageWiki are not tracked on Wikimedia Phab. Please report this to https://issue-tracker.miraheze.org/maniphest/task/edit/form/2/

Mar 13 2026, 3:40 AM · affects-Miraheze, Security, Security-Team
RhinosF1 updated subscribers of T419928: Authorization Bypass in Special:ManageWiki via Dynamic Module Parameter manipulation.
Mar 13 2026, 3:31 AM · affects-Miraheze, Security, Security-Team
RhinosF1 updated subscribers of T419929: Information Disclosure of Sensitive Wiki Configurations via ApiQueryWikiConfig.
Mar 13 2026, 3:29 AM · affects-Miraheze, Security, Security-Team
RhinosF1 closed T419929: Information Disclosure of Sensitive Wiki Configurations via ApiQueryWikiConfig as Invalid.

Not only is this reported to the wrong place, this is not a security issue in the slightest.

Mar 13 2026, 3:29 AM · affects-Miraheze, Security, Security-Team
RhinosF1 closed T419928: Authorization Bypass in Special:ManageWiki via Dynamic Module Parameter manipulation as Declined.

Security issues with ManageWiki are not tracked on Wikimedia Phab. Please report this to https://issue-tracker.miraheze.org/maniphest/task/edit/form/2/

Mar 13 2026, 3:25 AM · affects-Miraheze, Security, Security-Team
RhinosF1 updated subscribers of T419928: Authorization Bypass in Special:ManageWiki via Dynamic Module Parameter manipulation.
Mar 13 2026, 3:23 AM · affects-Miraheze, Security, Security-Team

Mar 7 2026

RhinosF1 added a member for 2026-user-javascript-incident: RhinosF1.
Mar 7 2026, 8:14 AM

Mar 4 2026

RhinosF1 added a comment to T418201: wikimedia-l was signed up for a developer account.

Thank you :)

Mar 4 2026, 11:57 AM · SRE, Bitu, Infrastructure-Foundations
RhinosF1 added a comment to T418201: wikimedia-l was signed up for a developer account.

Thank you :)

Mar 4 2026, 11:57 AM · SRE, Bitu, Infrastructure-Foundations

Feb 24 2026

RhinosF1 created T418201: wikimedia-l was signed up for a developer account.
Feb 24 2026, 8:07 AM · SRE, Bitu, Infrastructure-Foundations

Feb 15 2026

RhinosF1 added a comment to T417498: OpenGraph meta tag lists site logo instead of uploaded image when linking to file page.

I think this is what the open graph metadata is documented to do but it also seems a bit of a questionable UX and whether someone would expect it

Feb 15 2026, 11:00 AM · WikiSEO, affects-Miraheze
RhinosF1 renamed T417498: OpenGraph meta tag lists site logo instead of uploaded image when linking to file page from OpenGraph meta tag lists site logo instead of a picture from the wiki page to OpenGraph meta tag lists site logo instead of uploaded image when linking to file page.
Feb 15 2026, 10:59 AM · WikiSEO, affects-Miraheze
RhinosF1 updated the task description for T417498: OpenGraph meta tag lists site logo instead of uploaded image when linking to file page.
Feb 15 2026, 10:55 AM · WikiSEO, affects-Miraheze

Jan 20 2026

RhinosF1 added a project to T414574: Magic word Parser cache expiry not applied when page uses main slot + additional slot: affects-Miraheze.
Jan 20 2026, 7:58 AM · affects-Miraheze, Multi-Content-Revisions, MediaWiki-Parser

Jan 12 2026

RhinosF1 added a project to T414386: <spam>: Trash.
Jan 12 2026, 10:09 PM · Trash

Dec 31 2025

RhinosF1 added a comment to T363726: ?action=info should have a Table of Contents.

Thanks for the note!
I’ve added the Bug: T363726 line to the commit message and uploaded a new patch set.
Please let me know if anything else is needed.

You will need to address the CI failures. See the comment on your patch from Jenkins Bot.

Dec 31 2025, 3:30 PM · User-notice-archive, MW-1.46-notes (1.46.0-wmf.16; 2026-02-17), Patch-For-Review, good first task, Accessibility, MediaWiki-User-Interface (actions)
RhinosF1 added a comment to T363726: ?action=info should have a Table of Contents.

Update: I’ve implemented the Table of Contents for action=info pages and uploaded a patch to Gerrit.

The TOC is dynamically generated when multiple sections are present, inserted at the top of the page, and avoids duplication. This improves navigation and accessibility on longer Page information views.

Gerrit change:
https://gerrit.wikimedia.org/r/c/mediawiki/core/+/1221669/

The patch is now awaiting review. I’m happy to address any feedback or follow-up improvements if needed.

Dec 31 2025, 11:53 AM · User-notice-archive, MW-1.46-notes (1.46.0-wmf.16; 2026-02-17), Patch-For-Review, good first task, Accessibility, MediaWiki-User-Interface (actions)
RhinosF1 assigned T413619: Update UploadWizard's "1930" messages for so-old-they're-PD-in-the-US to 1931, now that it's 2026 to Talhasajid849.
Dec 31 2025, 11:51 AM · UploadWizard
RhinosF1 added a comment to T413619: Update UploadWizard's "1930" messages for so-old-they're-PD-in-the-US to 1931, now that it's 2026.

I submitted a Gerrit change updating the UploadWizard PD-US license year to 1931.

Patch: https://gerrit.wikimedia.org/r/1222270

Dec 31 2025, 11:47 AM · UploadWizard

Dec 29 2025

RhinosF1 added a project to T413568: Remove Comment_IP/Comment_Vote_IP from the Comments extension: affects-Miraheze.
Dec 29 2025, 1:13 PM · Social-Tools, affects-Miraheze, MediaWiki-extensions-Comments

Dec 14 2025

RhinosF1 closed T400449: Requesting GitLab account activation for Swayam_Agrahari as Resolved.

GitLab account pending approval

I created a GitLab account using my Wikimedia Developer Account,
but my account is still pending approval and blocked.

Username: Roger

Dec 14 2025, 12:59 PM · GitLab (Account Approval), Release-Engineering-Team
RhinosF1 reopened T400449: Requesting GitLab account activation for Swayam_Agrahari as "Open".
Dec 14 2025, 12:44 PM · GitLab (Account Approval), Release-Engineering-Team

Dec 9 2025

RhinosF1 added a comment to T412150: Allow Trusted-Contributors to change WIP/Active state of a patch.

Allowing patch author / owner to update WIP/Active is probably worth upstream task too. Note to future me: https://www.gerritcodereview.com/issues.html

Dec 9 2025, 7:48 PM · Gerrit
RhinosF1 created T412150: Allow Trusted-Contributors to change WIP/Active state of a patch.
Dec 9 2025, 7:47 PM · Gerrit

Nov 28 2025

RhinosF1 renamed T411235: Beta cluster scap using php8.1 container; php8.2 is now required from Beta cluster is running an unsupported version of PHP to Beta cluster CI is running an unsupported version of PHP.
Nov 28 2025, 6:50 AM · User-bd808, ci-test-error, Beta-Cluster-Infrastructure
RhinosF1 added a comment to T408275: 1.46.0-wmf.5 deployment blockers.

FYI - Beta scap is broken due to T411235: Beta cluster scap using php8.1 container; php8.2 is now required

Nov 28 2025, 6:46 AM · Release-Engineering-Team (Priority Backlog 📥), Essential-Work, Release, Train Deployments
RhinosF1 created T411235: Beta cluster scap using php8.1 container; php8.2 is now required.
Nov 28 2025, 6:44 AM · User-bd808, ci-test-error, Beta-Cluster-Infrastructure

Nov 2 2025

RhinosF1 added a project to T409014: Add English Gyaanipedia to Wikistats: VPS-project-Wikistats.
Nov 2 2025, 8:39 PM · VPS-project-Wikistats

Oct 17 2025

RhinosF1 added a member for Trusted-Contributors: TMWYK.
Oct 17 2025, 7:13 PM

Oct 9 2025

RhinosF1 added a project to T406895: WikiSEO cannot set an external URL as the image if $wgAllowExternalImages is set to true: affects-Miraheze.
Oct 9 2025, 4:06 PM · User-SomeRandomDeveloper, Patch-For-Review, affects-Miraheze, WikiSEO

Aug 27 2025

RhinosF1 closed T403052: Newly-added member of deployment-prep is not in bastion project, a subtask of T379550: openstack: keystone may be failing to add users to the bastion project in Keystone and/or LDAP, as Resolved.
Aug 27 2025, 3:35 PM · Patch-For-Review, Cloud-VPS, User-aborrero, cloud-services-team
RhinosF1 closed T403052: Newly-added member of deployment-prep is not in bastion project as Resolved.
Aug 27 2025, 3:35 PM · Cloud-VPS, cloud-services-team

Aug 18 2025

RhinosF1 added a project to T402226: User email was not updated in phab after updating on-wiki: Release-Engineering-Team.
Aug 18 2025, 8:21 PM · Release-Engineering-Team, Phabricator
RhinosF1 added a project to T402226: User email was not updated in phab after updating on-wiki: Phabricator.
Aug 18 2025, 8:21 PM · Release-Engineering-Team, Phabricator
RhinosF1 added a comment to T402226: User email was not updated in phab after updating on-wiki.

Phabricator is a completely separate system with a separate authentication system.

Aug 18 2025, 8:20 PM · Release-Engineering-Team, Phabricator

Aug 7 2025

RhinosF1 added a comment to T397900: Warning: User::loadFromSession called before the end of Setup.php.

The second fix (the MediaWiki core one) seems to reduce many more logs than the other one (though both are still needed).

For example https://logstash.wikimedia.org/goto/1204feae3a5687f4dc1e81bc7fd37a3b shows all such warnings fixed by the second patch (2 million in the last week).

Therefore, we should probably also backport the fix to MediaWiki core as well to fix the logs for affects-Miraheze.

Aug 7 2025, 2:55 PM · MW-1.44-notes, MW-1.43-notes, Trust and Safety Product Sprint (Sprint Princess Tarta (August 18 - September 5)), Essential-Work, MW-1.45-notes (1.45.0-wmf.14; 2025-08-12), MediaWiki-Core-Platform-Team (Radar), affects-Miraheze, Trust and Safety Product Team, MediaWiki-extensions-CentralAuth, GlobalBlocking
RhinosF1 added a comment to T397900: Warning: User::loadFromSession called before the end of Setup.php.

There are also a million other such warnings in the last week, but these do not appear to be caused by us (instead the Vector (legacy skin) skin).

I guess that should be split off into another task then

Aug 7 2025, 2:54 PM · MW-1.44-notes, MW-1.43-notes, Trust and Safety Product Sprint (Sprint Princess Tarta (August 18 - September 5)), Essential-Work, MW-1.45-notes (1.45.0-wmf.14; 2025-08-12), MediaWiki-Core-Platform-Team (Radar), affects-Miraheze, Trust and Safety Product Team, MediaWiki-extensions-CentralAuth, GlobalBlocking

Aug 4 2025

RhinosF1 updated subscribers of T401099: CVE-2025-61638: Sanitizer::validateAttributes data-XSS.
Aug 4 2025, 11:10 AM · MW-1.44-release, MW-1.43-release, MW-1.39-release, SecTeam-Processed, Vuln-XSS, MediaWiki-Parser, Security, Security-Team

Jul 10 2025

RhinosF1 updated the task description for T397776: Write and send supplementary release announcement for extensions and skins with security patches (1.39.14/1.43.4/1.44.1).
Jul 10 2025, 7:50 AM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security

Jul 9 2025

RhinosF1 updated the task description for T399132: Add security reports from 1.39.13/1.42.7/1.43.2/1.44.0 (+ extension supplement) to security hall of fame.
Jul 9 2025, 8:57 PM · SecTeam-Processed, affects-Miraheze, Security-Team
RhinosF1 updated the task description for T399132: Add security reports from 1.39.13/1.42.7/1.43.2/1.44.0 (+ extension supplement) to security hall of fame.
Jul 9 2025, 8:55 PM · SecTeam-Processed, affects-Miraheze, Security-Team
RhinosF1 updated the task description for T397776: Write and send supplementary release announcement for extensions and skins with security patches (1.39.14/1.43.4/1.44.1).
Jul 9 2025, 8:48 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 created T399132: Add security reports from 1.39.13/1.42.7/1.43.2/1.44.0 (+ extension supplement) to security hall of fame.
Jul 9 2025, 8:43 PM · SecTeam-Processed, affects-Miraheze, Security-Team

Jul 7 2025

RhinosF1 updated subscribers of T392341: CVE-2025-53483, CVE-2025-53484, CVE-2025-53485: SecurePoll is vulnerable to XSS, CSRF, and lack of authorisation.
Jul 7 2025, 8:01 PM · Trust and Safety Product Sprint (Sprint Princess Tarta (August 18 - September 5)), Essential-Work, Patch-For-Review, Trust and Safety Product Team, Vuln-BrokenAccessControl, affects-Miraheze, Vuln-CSRF, Vuln-XSS, MediaWiki-extensions-SecurePoll, Security, Security-Team

Jul 5 2025

RhinosF1 added a comment to T398753: Too Many Requests Error on certain useragents (QtWebEngine, outdated chromium based browsers, Safari 605).

I suspect it's similar to https://lists.wikimedia.org/hyperkitty/list/wikitech-l@lists.wikimedia.org/message/3DNR7FALKHAU4L5ZUBRNP4Q4YWXLGABB/

Jul 5 2025, 2:47 PM · Traffic

Jul 3 2025

RhinosF1 added a comment to T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).

I'm extremely late adding them so if I'm too late then apologies but I added the 2 other ManageWiki CVEs that I forgot to add here

Since they are tracked outside of Phab/Gerrit and have CVEs assigned and merged patches already, it should be fairly trivial to include them for this release.

Thanks, I added the 5 CVEs from the last citizen release too. I'll try and think of a good way of tracking the ones we find that are from non-Wikimedia maintained extensions. It shouldn't be too difficult now both me and @Paladox have security access to create a Miraheze equivalent we can sync up to here close to the release for the next one. Obviously not sharing anything from here the other way around, just us sharing up to you.

Jul 3 2025, 6:11 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 updated the task description for T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).
Jul 3 2025, 6:02 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 updated the task description for T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).
Jul 3 2025, 5:55 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 updated the task description for T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).
Jul 3 2025, 5:53 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 updated the task description for T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).
Jul 3 2025, 5:51 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 updated the task description for T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).
Jul 3 2025, 5:51 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 added a comment to T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).

T394869: CVE-2025-7056: Stored XSS through a system message in UrlShortener and T394612: CVE-2025-7057: Stored XSS through a system message in Extension:Quiz are WMF tracked and missing off the list too

Jul 3 2025, 12:22 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 updated the task description for T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).
Jul 3 2025, 12:21 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 updated subscribers of T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).

I'm extremely late adding them so if I'm too late then apologies but I added the 2 other ManageWiki CVEs that I forgot to add here

Since they are tracked outside of Phab/Gerrit and have CVEs assigned and merged patches already, it should be fairly trivial to include them for this release.

Jul 3 2025, 12:17 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 updated the task description for T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).
Jul 3 2025, 12:12 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security

Jul 2 2025

RhinosF1 added a comment to T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).

I'm extremely late adding them so if I'm too late then apologies but I added the 2 other ManageWiki CVEs that I forgot to add here

Jul 2 2025, 4:34 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 updated the task description for T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).
Jul 2 2025, 4:33 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 added a comment to T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).

Subject: MediaWiki Extensions and Skins Security Release Supplement (1.39.13/1.42.7/1.43.2)

Greetings-

With the security/maintenance release of MediaWiki 1.39.13/1.42.7/1.43.2, we would also like to provide this supplementary announcement of MediaWiki extensions and skins with now-public Phabricator tasks, security patches and backports [1]:

ManageWiki
+ (https://github.com/miraheze/ManageWiki/security/advisories/GHSA-gg42-cv66-f5x7, CVE-2025-32956) - SQL injection vulnerability in NamespaceMigrationJob
https://github.com/miraheze/ManageWiki/commit/f504ed8eeb59b57ebb90f93cd44f23da4c5bc4c9

The Wikimedia Security Team recommends updating these extensions and/or skins to the current master branch or relevant, supported release branch [2] as soon as possible. Some of the referenced Phabricator tasks above _may_ still be private. Unfortunately, when security issues are reported, sometimes sensitive information is exposed and since Phabricator is historical, we cannot make these tasks public without exposing this sensitive information. If you have any additional questions or concerns regarding this update, please feel free to contact security@wikimedia.org or file a security task within Phabricator [3].

[1] https://phabricator.wikimedia.org/T389312
[2] https://www.mediawiki.org/wiki/Version_lifecycle
[3] https://www.mediawiki.org/wiki/Reporting_security_bugs

Jul 2 2025, 4:29 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security

Jun 29 2025

RhinosF1 updated subscribers of T394614: New upstream release for Pywikibot.

@rook used to be, I created https://github.com/toolforge/paws/pull/488

Jun 29 2025, 4:58 PM · User-RhinosF1, PAWS

Jun 26 2025

RhinosF1 updated the task description for T397900: Warning: User::loadFromSession called before the end of Setup.php.
Jun 26 2025, 7:02 AM · MW-1.44-notes, MW-1.43-notes, Trust and Safety Product Sprint (Sprint Princess Tarta (August 18 - September 5)), Essential-Work, MW-1.45-notes (1.45.0-wmf.14; 2025-08-12), MediaWiki-Core-Platform-Team (Radar), affects-Miraheze, Trust and Safety Product Team, MediaWiki-extensions-CentralAuth, GlobalBlocking
RhinosF1 updated the task description for T397900: Warning: User::loadFromSession called before the end of Setup.php.
Jun 26 2025, 6:54 AM · MW-1.44-notes, MW-1.43-notes, Trust and Safety Product Sprint (Sprint Princess Tarta (August 18 - September 5)), Essential-Work, MW-1.45-notes (1.45.0-wmf.14; 2025-08-12), MediaWiki-Core-Platform-Team (Radar), affects-Miraheze, Trust and Safety Product Team, MediaWiki-extensions-CentralAuth, GlobalBlocking
RhinosF1 removed a project from T397900: Warning: User::loadFromSession called before the end of Setup.php: Wikimedia-production-error.
Jun 26 2025, 6:50 AM · MW-1.44-notes, MW-1.43-notes, Trust and Safety Product Sprint (Sprint Princess Tarta (August 18 - September 5)), Essential-Work, MW-1.45-notes (1.45.0-wmf.14; 2025-08-12), MediaWiki-Core-Platform-Team (Radar), affects-Miraheze, Trust and Safety Product Team, MediaWiki-extensions-CentralAuth, GlobalBlocking
RhinosF1 created T397900: Warning: User::loadFromSession called before the end of Setup.php.
Jun 26 2025, 6:50 AM · MW-1.44-notes, MW-1.43-notes, Trust and Safety Product Sprint (Sprint Princess Tarta (August 18 - September 5)), Essential-Work, MW-1.45-notes (1.45.0-wmf.14; 2025-08-12), MediaWiki-Core-Platform-Team (Radar), affects-Miraheze, Trust and Safety Product Team, MediaWiki-extensions-CentralAuth, GlobalBlocking

Jun 24 2025

RhinosF1 added a comment to T385811: Vector should not direct third-party wikis to report dark mode issues to MW.o.

It's saddening to see this antipattern again after years of MediaViewer third-party misconfiguration issues (mis)filed in Wikimedia Phabricator due to hardcoding a Wikimedia URI in an extension that can also be used outside of Wikimedia.

Jun 24 2025, 10:59 AM · Verified, MW-1.45-notes (1.45.0-wmf.17; 2025-09-02), Reader Experience Team, Readers Essential Work, MW-1.44-release, Patch-For-Review, affects-Miraheze, good first task, patch-welcome, WikimediaMessages, MW-1.43-release, Vector 2022
RhinosF1 added a comment to T397679: Non Wikimedia wikis users report dark mode issues on mediawiki.org and causing IP leaks..

There is already a task for this. I don't think it's a security issue or there's need to suppress IPs.

Jun 24 2025, 7:22 AM · SecTeam-Processed, affects-Miraheze
RhinosF1 merged T397679: Non Wikimedia wikis users report dark mode issues on mediawiki.org and causing IP leaks. into T385811: Vector should not direct third-party wikis to report dark mode issues to MW.o.
Jun 24 2025, 7:20 AM · Verified, MW-1.45-notes (1.45.0-wmf.17; 2025-09-02), Reader Experience Team, Readers Essential Work, MW-1.44-release, Patch-For-Review, affects-Miraheze, good first task, patch-welcome, WikimediaMessages, MW-1.43-release, Vector 2022