Page MenuHomePhabricator

mmartorana (manfredi martorana)
Application Security Engineer

Today

  • No visible events.

Tomorrow

  • No visible events.

Monday

  • No visible events.

User Details

User Since
Nov 5 2021, 2:54 PM (223 w, 20 h)
Availability
Available
LDAP User
Unknown
MediaWiki User
MMartorana (WMF) [ Global Accounts ]

Recent Activity

Yesterday

mmartorana moved T410091: Security review for Extension:WP25EasterEggs from In Progress to Our Part Is Done on the Security-Team board.
Fri, Feb 13, 6:42 PM · MW-1.46-notes (1.46.0-wmf.16; 2026-02-17), Patch-For-Review, SecTeam-Processed, Security-Team, secscrum, Application Security Reviews, MediaWiki-extensions-WP25EasterEggs, PES1.3.3 WP25 Easter Eggs

Tue, Feb 10

mmartorana updated the task description for T301992: Insert CheckUser row events during certain 2FA actions.
Tue, Feb 10, 7:04 PM · MW-1.46-notes (1.46.0-wmf.16; 2026-02-17), Security-Team, Trust and Safety Product Team, MW-1.43-notes (1.43.0-wmf.13; 2024-07-09), MediaWiki-extensions-OATHAuth, CheckUser

Fri, Feb 6

mmartorana added a comment to T415902: Instrument data for tracking email verifications.

Thanks for looking into this. I tried to get a hold of the totals on superset but realized they scrub gu_email(makes sense) so I can only get count and timestamp of confirmed emails but not the unconfirmed ones.

If you have access to the stat boxes, you can get it from there:

catrope@catrope-ThinkPad-T16-Gen-1$ ssh stat1008.eqiad.wmnet
catrope@stat1008:~$ analytics-mysql centralauth
mysql:research@dbstore1008.eqiad.wmnet [centralauth]> select if(gu_email is null or gu_email = '', 'no', 'yes') as hasemail, count(*) from globaluser group by hasemail;
+----------+----------+
| hasemail | count(*) |
+----------+----------+
| no       | 19885382 |
| yes      | 62393788 |
+----------+----------+
2 rows in set (24.526 sec)

This sounds fine to me. I'll update the task.

Great, thanks! @mmartorana will work on this next week.

Fri, Feb 6, 2:51 PM · FY2025-26 WE 4.6 - Account Security (WE 4.6.13 Encourage Email Verification)
mmartorana updated the task description for T301992: Insert CheckUser row events during certain 2FA actions.
Fri, Feb 6, 2:44 PM · MW-1.46-notes (1.46.0-wmf.16; 2026-02-17), Security-Team, Trust and Safety Product Team, MW-1.43-notes (1.43.0-wmf.13; 2024-07-09), MediaWiki-extensions-OATHAuth, CheckUser

Thu, Feb 5

mmartorana moved T301992: Insert CheckUser row events during certain 2FA actions from Incoming to In Progress on the Security-Team board.
Thu, Feb 5, 5:57 PM · MW-1.46-notes (1.46.0-wmf.16; 2026-02-17), Security-Team, Trust and Safety Product Team, MW-1.43-notes (1.43.0-wmf.13; 2024-07-09), MediaWiki-extensions-OATHAuth, CheckUser
mmartorana moved T415351: EmailAuth: Log success, failure, and account recovery requests as actions in CheckUser from Incoming to In Progress on the Security-Team board.
Thu, Feb 5, 5:57 PM · Security-Team, Product Safety and Integrity, MediaWiki-extensions-EmailAuth, CheckUser
mmartorana added a project to T415351: EmailAuth: Log success, failure, and account recovery requests as actions in CheckUser: Security-Team.
Thu, Feb 5, 5:56 PM · Security-Team, Product Safety and Integrity, MediaWiki-extensions-EmailAuth, CheckUser
mmartorana added a project to T301992: Insert CheckUser row events during certain 2FA actions: Security-Team.
Thu, Feb 5, 5:56 PM · MW-1.46-notes (1.46.0-wmf.16; 2026-02-17), Security-Team, Trust and Safety Product Team, MW-1.43-notes (1.43.0-wmf.13; 2024-07-09), MediaWiki-extensions-OATHAuth, CheckUser
mmartorana updated the task description for T301992: Insert CheckUser row events during certain 2FA actions.
Thu, Feb 5, 2:48 PM · MW-1.46-notes (1.46.0-wmf.16; 2026-02-17), Security-Team, Trust and Safety Product Team, MW-1.43-notes (1.43.0-wmf.13; 2024-07-09), MediaWiki-extensions-OATHAuth, CheckUser

Tue, Feb 3

mmartorana updated subscribers of T410091: Security review for Extension:WP25EasterEggs.

Thanks for the ping! We’re aware of the rollout timeline.

Tue, Feb 3, 6:57 PM · MW-1.46-notes (1.46.0-wmf.16; 2026-02-17), Patch-For-Review, SecTeam-Processed, Security-Team, secscrum, Application Security Reviews, MediaWiki-extensions-WP25EasterEggs, PES1.3.3 WP25 Easter Eggs
mmartorana updated the task description for T301992: Insert CheckUser row events during certain 2FA actions.
Tue, Feb 3, 4:33 PM · MW-1.46-notes (1.46.0-wmf.16; 2026-02-17), Security-Team, Trust and Safety Product Team, MW-1.43-notes (1.43.0-wmf.13; 2024-07-09), MediaWiki-extensions-OATHAuth, CheckUser
mmartorana updated the task description for T301992: Insert CheckUser row events during certain 2FA actions.
Tue, Feb 3, 4:24 PM · MW-1.46-notes (1.46.0-wmf.16; 2026-02-17), Security-Team, Trust and Safety Product Team, MW-1.43-notes (1.43.0-wmf.13; 2024-07-09), MediaWiki-extensions-OATHAuth, CheckUser

Tue, Jan 27

mmartorana changed the status of T301992: Insert CheckUser row events during certain 2FA actions from Open to In Progress.
Tue, Jan 27, 4:03 PM · MW-1.46-notes (1.46.0-wmf.16; 2026-02-17), Security-Team, Trust and Safety Product Team, MW-1.43-notes (1.43.0-wmf.13; 2024-07-09), MediaWiki-extensions-OATHAuth, CheckUser
mmartorana changed the status of T415351: EmailAuth: Log success, failure, and account recovery requests as actions in CheckUser from Open to In Progress.
Tue, Jan 27, 4:02 PM · Security-Team, Product Safety and Integrity, MediaWiki-extensions-EmailAuth, CheckUser

Fri, Jan 23

mmartorana moved T399459: Application Security Review Request: webonyx/graphql-php from In Progress to Our Part Is Done on the secscrum board.

Security Review Summary - T399459 - 2026-01-23

Fri, Jan 23, 5:08 PM · MW-1.46-notes (1.46.0-wmf.14; 2026-02-03), SecTeam-Processed, Wikibase Reuse Team, secscrum, Security, Application Security Reviews
mmartorana added a comment to T415087: itwiki: Special:AccountRecovery has incomplete/awkward Italian localisation (form + confirmation email).

@mmartorana Ciò è dovuto al fatto che non tutto dell'estensione Email Auth era stato tradotto su translatewiki (mentre i numeri e le scadenze sono spesso già tradotte). Sto risolvendo io su translatewiki e con il prossimo aggiornamento, da settimana prossima, dovrebbe essere tutto in italiano. Anzi, se vuoi dare una mano, questo è il link :)

Fri, Jan 23, 3:07 PM · MediaWiki-extensions-EmailAuth, FY2025-26 WE4.6.1 Support Desk Streamlining

Wed, Jan 21

mmartorana added a comment to T399459: Application Security Review Request: webonyx/graphql-php.

thanks so much! quick clarification question - what's the difference between it being completed vs. the results being posted? Would it take another month until we can officially use it on production?

Wed, Jan 21, 6:50 PM · MW-1.46-notes (1.46.0-wmf.14; 2026-02-03), SecTeam-Processed, Wikibase Reuse Team, secscrum, Security, Application Security Reviews
mmartorana added a comment to T399459: Application Security Review Request: webonyx/graphql-php.

Hi @Ifrahkhanyaree_WMDE - apologies on behalf of the Security-Team. We’ve reprioritized this review and expect it to be completed by the end of this week.

Wed, Jan 21, 4:18 PM · MW-1.46-notes (1.46.0-wmf.14; 2026-02-03), SecTeam-Processed, Wikibase Reuse Team, secscrum, Security, Application Security Reviews

Tue, Jan 20

mmartorana created T415087: itwiki: Special:AccountRecovery has incomplete/awkward Italian localisation (form + confirmation email).
Tue, Jan 20, 4:27 PM · MediaWiki-extensions-EmailAuth, FY2025-26 WE4.6.1 Support Desk Streamlining
mmartorana updated the task description for T410336: Redesign passkey creation form.
Tue, Jan 20, 11:21 AM · FY2025-26 WE 4.6 - Account Security (WE 4.6.4 - 2FA improvements and passkey support), MediaWiki-extensions-OATHAuth
mmartorana updated the task description for T410938: Automatically generate passkey name based on AAGUID.
Tue, Jan 20, 11:19 AM · FY2025-26 WE 4.6 - Account Security (WE 4.6.4 - 2FA improvements and passkey support), MediaWiki-extensions-OATHAuth

Jan 9 2026

mmartorana changed the visibility for T410560: CVE-2026-0817: CampaignEvents API missing authorization exposes meeting and chat URLs.
Jan 9 2026, 6:13 PM · Patch-For-Review, SecTeam-Processed, Connection-Team (Connection-Current-Sprint), Vuln-Infoleak, CampaignEvents, Security, Security-Team
mmartorana closed T404620: Write and send supplementary release announcement for extensions and skins with security patches (1.39.16/1.43.6/1.44.3/1.45.1) as Resolved.

Email from T404620#11504513 has been sent to various mailing lists:

Jan 9 2026, 6:03 PM · user-sbassett, MediaWiki-Releasing, Security
mmartorana closed T404620: Write and send supplementary release announcement for extensions and skins with security patches (1.39.16/1.43.6/1.44.3/1.45.1), a subtask of T404610: Release MediaWiki 1.39.16/1.43.6/1.44.3/1.45.1, as Resolved.
Jan 9 2026, 6:03 PM · MediaWiki-Releasing, Security
mmartorana changed the visibility for T404620: Write and send supplementary release announcement for extensions and skins with security patches (1.39.16/1.43.6/1.44.3/1.45.1).
Jan 9 2026, 5:40 PM · user-sbassett, MediaWiki-Releasing, Security
mmartorana updated the task description for T404620: Write and send supplementary release announcement for extensions and skins with security patches (1.39.16/1.43.6/1.44.3/1.45.1).
Jan 9 2026, 3:52 PM · user-sbassett, MediaWiki-Releasing, Security
mmartorana renamed T410560: CVE-2026-0817: CampaignEvents API missing authorization exposes meeting and chat URLs from GET campaignevents/v0/event_registration/{id} leaks meeting and chat URL to everyone to CVE-2026-0817: CampaignEvents API missing authorization exposes meeting and chat URLs.
Jan 9 2026, 3:51 PM · Patch-For-Review, SecTeam-Processed, Connection-Team (Connection-Current-Sprint), Vuln-Infoleak, CampaignEvents, Security, Security-Team
mmartorana updated the task description for T404620: Write and send supplementary release announcement for extensions and skins with security patches (1.39.16/1.43.6/1.44.3/1.45.1).
Jan 9 2026, 3:39 PM · user-sbassett, MediaWiki-Releasing, Security
mmartorana updated the task description for T404620: Write and send supplementary release announcement for extensions and skins with security patches (1.39.16/1.43.6/1.44.3/1.45.1).
Jan 9 2026, 3:38 PM · user-sbassett, MediaWiki-Releasing, Security
mmartorana added a comment to T410560: CVE-2026-0817: CampaignEvents API missing authorization exposes meeting and chat URLs.

@Daimona I redid the production patch so that it would apply. If you have time to merge it then I'll go ahead and request a CVE and add it to the supplemental release.

Merged. I suppose this means I can put the new patch from T410560#11497430 on gerrit once the release is out right?

Jan 9 2026, 2:51 PM · Patch-For-Review, SecTeam-Processed, Connection-Team (Connection-Current-Sprint), Vuln-Infoleak, CampaignEvents, Security, Security-Team
mmartorana changed the visibility for T409423: CVE-2026-0670: Stored XSS through a system message and a user-provided parameter in ProofreadPage.
Jan 9 2026, 2:50 PM · SecTeam-Processed, affects-Miraheze, Vuln-XSS, ProofreadPage, Security, Security-Team
mmartorana changed the visibility for T407157: CVE-2026-0671: Multiple stored i18n/message-key XSSes in UploadWizard.
Jan 9 2026, 2:50 PM · Patch-For-Review, affects-Miraheze, SecTeam-Processed, Vuln-XSS, UploadWizard, Security, Security-Team
mmartorana changed the visibility for T401526: CVE-2026-0669: Path Traversal vulnerability in CSS extension on certain web servers.
Jan 9 2026, 2:49 PM · Vuln-DirectoryTraversal, SecTeam-Processed, MediaWiki-extensions-CSS, Security
mmartorana changed the visibility for T387008: CVE-2026-0668: VisualData extension: Regular Expression Denial of Service (ReDoS) via crafted user input.
Jan 9 2026, 2:48 PM · SecTeam-Processed, MediaWiki-extensions-Other, Vuln-DoS, affects-Miraheze, Security
mmartorana renamed T407157: CVE-2026-0671: Multiple stored i18n/message-key XSSes in UploadWizard from Multiple stored i18n/message-key XSSes in UploadWizard to CVE-2026-0671: Multiple stored i18n/message-key XSSes in UploadWizard.
Jan 9 2026, 2:47 PM · Patch-For-Review, affects-Miraheze, SecTeam-Processed, Vuln-XSS, UploadWizard, Security, Security-Team
mmartorana updated the task description for T404620: Write and send supplementary release announcement for extensions and skins with security patches (1.39.16/1.43.6/1.44.3/1.45.1).
Jan 9 2026, 2:46 PM · user-sbassett, MediaWiki-Releasing, Security

Jan 8 2026

mmartorana updated the task description for T404620: Write and send supplementary release announcement for extensions and skins with security patches (1.39.16/1.43.6/1.44.3/1.45.1).
Jan 8 2026, 6:55 PM · user-sbassett, MediaWiki-Releasing, Security
mmartorana updated the task description for T404620: Write and send supplementary release announcement for extensions and skins with security patches (1.39.16/1.43.6/1.44.3/1.45.1).
Jan 8 2026, 6:33 PM · user-sbassett, MediaWiki-Releasing, Security
mmartorana closed T342468: Craft more mediawiki-specific and php semgrep rule sets, a subtask of T371814: [EPIC] Universal Security Dashboard, as Declined.
Jan 8 2026, 6:18 PM · SecTeam-Processed, Universal Security Dashboard, user-sbassett, Epic, Security, Security-Team
mmartorana closed T342468: Craft more mediawiki-specific and php semgrep rule sets as Declined.
Jan 8 2026, 6:18 PM · Security-Team, GitLab-Application-Security-Pipeline
mmartorana closed T412077: Add API endpoint for creating a passkey as Resolved.
Jan 8 2026, 5:45 PM · FY2025-26 WE 4.6 - Account Security (WE 4.6.4 - 2FA improvements and passkey support), MediaWiki-extensions-OATHAuth
mmartorana closed T412077: Add API endpoint for creating a passkey, a subtask of T410336: Redesign passkey creation form, as Resolved.
Jan 8 2026, 5:45 PM · FY2025-26 WE 4.6 - Account Security (WE 4.6.4 - 2FA improvements and passkey support), MediaWiki-extensions-OATHAuth
mmartorana closed T410938: Automatically generate passkey name based on AAGUID as Resolved.
Jan 8 2026, 5:45 PM · FY2025-26 WE 4.6 - Account Security (WE 4.6.4 - 2FA improvements and passkey support), MediaWiki-extensions-OATHAuth
mmartorana added a comment to T410091: Security review for Extension:WP25EasterEggs.

Hi @Jdrewniak - to help us scope this review, could you clarify the expected deployment window more precisely ?

Jan 8 2026, 5:15 PM · MW-1.46-notes (1.46.0-wmf.16; 2026-02-17), Patch-For-Review, SecTeam-Processed, Security-Team, secscrum, Application Security Reviews, MediaWiki-extensions-WP25EasterEggs, PES1.3.3 WP25 Easter Eggs
mmartorana added a comment to T404620: Write and send supplementary release announcement for extensions and skins with security patches (1.39.16/1.43.6/1.44.3/1.45.1).
Draft Email For Release - Please comment with any questions/concerns - otherwise this will be sent to the relevant mailing lists on 01/09/2026
Jan 8 2026, 4:34 PM · user-sbassett, MediaWiki-Releasing, Security
mmartorana updated the task description for T404620: Write and send supplementary release announcement for extensions and skins with security patches (1.39.16/1.43.6/1.44.3/1.45.1).
Jan 8 2026, 4:22 PM · user-sbassett, MediaWiki-Releasing, Security
mmartorana updated the task description for T404620: Write and send supplementary release announcement for extensions and skins with security patches (1.39.16/1.43.6/1.44.3/1.45.1).
Jan 8 2026, 3:44 PM · user-sbassett, MediaWiki-Releasing, Security
mmartorana updated the task description for T404620: Write and send supplementary release announcement for extensions and skins with security patches (1.39.16/1.43.6/1.44.3/1.45.1).
Jan 8 2026, 3:38 PM · user-sbassett, MediaWiki-Releasing, Security

Jan 7 2026

mmartorana updated the task description for T404620: Write and send supplementary release announcement for extensions and skins with security patches (1.39.16/1.43.6/1.44.3/1.45.1).
Jan 7 2026, 6:56 PM · user-sbassett, MediaWiki-Releasing, Security
mmartorana renamed T401526: CVE-2026-0669: Path Traversal vulnerability in CSS extension on certain web servers from Path Traversal vulnerability in CSS extension on certain web servers to CVE-2026-0669: Path Traversal vulnerability in CSS extension on certain web servers.
Jan 7 2026, 5:48 PM · Vuln-DirectoryTraversal, SecTeam-Processed, MediaWiki-extensions-CSS, Security
mmartorana updated the task description for T404620: Write and send supplementary release announcement for extensions and skins with security patches (1.39.16/1.43.6/1.44.3/1.45.1).
Jan 7 2026, 5:47 PM · user-sbassett, MediaWiki-Releasing, Security
mmartorana renamed T387008: CVE-2026-0668: VisualData extension: Regular Expression Denial of Service (ReDoS) via crafted user input from Evil regexes are used to process user-provided input in VisualData to CVE-2026-0668: VisualData extension: Regular Expression Denial of Service (ReDoS) via crafted user input.
Jan 7 2026, 5:38 PM · SecTeam-Processed, MediaWiki-extensions-Other, Vuln-DoS, affects-Miraheze, Security
mmartorana updated the task description for T404620: Write and send supplementary release announcement for extensions and skins with security patches (1.39.16/1.43.6/1.44.3/1.45.1).
Jan 7 2026, 5:37 PM · user-sbassett, MediaWiki-Releasing, Security
mmartorana updated the task description for T404620: Write and send supplementary release announcement for extensions and skins with security patches (1.39.16/1.43.6/1.44.3/1.45.1).
Jan 7 2026, 5:17 PM · user-sbassett, MediaWiki-Releasing, Security

Dec 16 2025

mmartorana added a comment to T408876: https://wm-bot.wmcloud.org/github/index.php seems vulnerable to SQL injection.

Hey cloud-services-team and @dcaro - this service has a known vulnerability. Since there are currently no mitigation steps and no identified code owner, the Security-Team strongly recommends shutting the service down.

Dec 16 2025, 6:14 PM · Vuln-Inject, SecTeam-Processed, WM-Bot, Security, Security-Team

Dec 15 2025

mmartorana closed T404751: Application Security Review Request : ReaderExperiments as Resolved.

Security Review Summary - T404751 - 2025-12-15
Last commit reviewed: d77fc0e

Dec 15 2025, 6:05 PM · ReaderExperiments-ImageBrowsing, FY2025-26 WE3.1 Engaging New Audiences, Reader Growth Team, ReaderExperiments, secscrum, Security, Application Security Reviews

Dec 8 2025

mmartorana added a comment to T410938: Automatically generate passkey name based on AAGUID.

Given the scope, I think it seems reasonable to start with a simple lookup table that maps known AAGUIDs to readable device names (e.g. Google Password Manager, iCloud Keychain, YubiKey 5 Series, etc...). This can be either hardcoded at first, or stored in a small static file. I think that is a good starting point rather than some more complex approach for now.

Dec 8 2025, 6:54 PM · FY2025-26 WE 4.6 - Account Security (WE 4.6.4 - 2FA improvements and passkey support), MediaWiki-extensions-OATHAuth

Dec 2 2025

mmartorana closed T409986: Convert 2FA deletion warning to HTMLForm as Resolved.
Dec 2 2025, 4:13 PM · MW-1.46-notes (1.46.0-wmf.5; 2025-12-02), FY2025-26 WE 4.6 - Account Security (WE 4.6.4 - 2FA improvements and passkey support), MediaWiki-extensions-OATHAuth

Dec 1 2025

mmartorana added a comment to T408876: https://wm-bot.wmcloud.org/github/index.php seems vulnerable to SQL injection.

Hey @Petrb - based on the codepath above this still looks like a plausible SQL injection vector. Could you confirm whether you plan to patch this upstream, or if there’s anything needed from our side to help move it forward?

Dec 1 2025, 3:34 PM · Vuln-Inject, SecTeam-Processed, WM-Bot, Security, Security-Team

Nov 25 2025

mmartorana changed the status of T409986: Convert 2FA deletion warning to HTMLForm from Open to In Progress.
Nov 25 2025, 6:38 PM · MW-1.46-notes (1.46.0-wmf.5; 2025-12-02), FY2025-26 WE 4.6 - Account Security (WE 4.6.4 - 2FA improvements and passkey support), MediaWiki-extensions-OATHAuth

Nov 17 2025

mmartorana moved T399742: Integrated on-page form for EmailAuth recovery requests from In Progress to Done on the FY2025-26 WE4.6.1 Support Desk Streamlining board.
Nov 17 2025, 5:40 PM · MW-1.46-notes (1.46.0-wmf.2; 2025-11-12), MediaWiki-extensions-EmailAuth, FY2025-26 WE4.6.1 Support Desk Streamlining

Nov 12 2025

mmartorana closed T404996: Offboard Jimmy Ly from the Security Team as Resolved.
Nov 12 2025, 5:15 PM · SecTeam-Processed, Security-Team
mmartorana updated the task description for T404996: Offboard Jimmy Ly from the Security Team.
Nov 12 2025, 5:15 PM · SecTeam-Processed, Security-Team

Nov 11 2025

mmartorana added a comment to T408876: https://wm-bot.wmcloud.org/github/index.php seems vulnerable to SQL injection.

Hey cloud-services-team - this looks like a potential vulnerability. What mitigation approach do you want to take?

Nov 11 2025, 7:00 PM · Vuln-Inject, SecTeam-Processed, WM-Bot, Security, Security-Team
mmartorana updated the task description for T404996: Offboard Jimmy Ly from the Security Team.
Nov 11 2025, 5:25 PM · SecTeam-Processed, Security-Team

Nov 10 2025

mmartorana claimed T399742: Integrated on-page form for EmailAuth recovery requests.
Nov 10 2025, 4:04 PM · MW-1.46-notes (1.46.0-wmf.2; 2025-11-12), MediaWiki-extensions-EmailAuth, FY2025-26 WE4.6.1 Support Desk Streamlining
mmartorana moved T399743: Zendesk Spreadsheets Automation from In Progress to Done on the FY2025-26 WE4.6.1 Support Desk Streamlining board.
Nov 10 2025, 4:03 PM · FY2025-26 WE4.6.1 Support Desk Streamlining
mmartorana moved T399749: Link to Zendesk form from EmailAuth failure message from In Progress to Done on the FY2025-26 WE4.6.1 Support Desk Streamlining board.
Nov 10 2025, 4:01 PM · MW-1.46-notes (1.46.0-wmf.1; 2025-11-05), MW-1.45-notes (1.45.0-wmf.19; 2025-09-16), WikimediaMessages, MediaWiki-extensions-EmailAuth, FY2025-26 WE4.6.1 Support Desk Streamlining
mmartorana closed T399749: Link to Zendesk form from EmailAuth failure message as Resolved.
Nov 10 2025, 4:01 PM · MW-1.46-notes (1.46.0-wmf.1; 2025-11-05), MW-1.45-notes (1.45.0-wmf.19; 2025-09-16), WikimediaMessages, MediaWiki-extensions-EmailAuth, FY2025-26 WE4.6.1 Support Desk Streamlining

Nov 7 2025

mmartorana closed T397076: Re-enable WMF-NDA access for Miriam and Snwachukwu as Resolved.

I’ve restored access for @Snwachukwu to WMF-NDA

Nov 7 2025, 6:22 PM · SecTeam-Processed, Security, Security-Team
mmartorana added a member for WMF-NDA: Snwachukwu.
Nov 7 2025, 6:19 PM
mmartorana moved T399749: Link to Zendesk form from EmailAuth failure message from Done to In Progress on the FY2025-26 WE4.6.1 Support Desk Streamlining board.
Nov 7 2025, 5:59 PM · MW-1.46-notes (1.46.0-wmf.1; 2025-11-05), MW-1.45-notes (1.45.0-wmf.19; 2025-09-16), WikimediaMessages, MediaWiki-extensions-EmailAuth, FY2025-26 WE4.6.1 Support Desk Streamlining
mmartorana reopened T399749: Link to Zendesk form from EmailAuth failure message as "In Progress".
Nov 7 2025, 5:58 PM · MW-1.46-notes (1.46.0-wmf.1; 2025-11-05), MW-1.45-notes (1.45.0-wmf.19; 2025-09-16), WikimediaMessages, MediaWiki-extensions-EmailAuth, FY2025-26 WE4.6.1 Support Desk Streamlining

Nov 3 2025

mmartorana added a comment to T397076: Re-enable WMF-NDA access for Miriam and Snwachukwu.

Since there hasn’t been any recent activity on this task, the Security-Team plans to close it soon due to inactivity.

Nov 3 2025, 4:06 PM · SecTeam-Processed, Security, Security-Team

Oct 27 2025

mmartorana closed T407256: Security Issue Access Request for SLopes-WMF as Resolved.

I have added @SLopes-WMF to acl*security_management .

Oct 27 2025, 2:33 PM · SecTeam-Processed, Security-Team, Security
mmartorana added a member for acl*security_management: SLopes-WMF.
Oct 27 2025, 2:32 PM

Oct 14 2025

mmartorana created T407256: Security Issue Access Request for SLopes-WMF.
Oct 14 2025, 3:47 PM · SecTeam-Processed, Security-Team, Security
mmartorana added a comment to T397076: Re-enable WMF-NDA access for Miriam and Snwachukwu.

Hey @Miriam and @Snwachukwu - how are you?

Oct 14 2025, 3:40 PM · SecTeam-Processed, Security, Security-Team

Oct 7 2025

mmartorana updated the task description for T404996: Offboard Jimmy Ly from the Security Team.
Oct 7 2025, 3:15 PM · SecTeam-Processed, Security-Team
mmartorana added a comment to T405926: Security Issue Access Request for Jsn.sherman.

Hi @jsn.sherman - I have granted access to acl*security_developer .

Oct 7 2025, 3:13 PM · SecTeam-Processed, Security-Team, Security
mmartorana added a member for acl*security_developer: jsn.sherman.
Oct 7 2025, 3:11 PM

Sep 18 2025

mmartorana created T404996: Offboard Jimmy Ly from the Security Team.
Sep 18 2025, 3:51 PM · SecTeam-Processed, Security-Team

Sep 12 2025

mmartorana moved T399749: Link to Zendesk form from EmailAuth failure message from Backlog to In Progress on the FY2025-26 WE4.6.1 Support Desk Streamlining board.
Sep 12 2025, 4:01 PM · MW-1.46-notes (1.46.0-wmf.1; 2025-11-05), MW-1.45-notes (1.45.0-wmf.19; 2025-09-16), WikimediaMessages, MediaWiki-extensions-EmailAuth, FY2025-26 WE4.6.1 Support Desk Streamlining
mmartorana moved T399742: Integrated on-page form for EmailAuth recovery requests from Backlog to In Progress on the FY2025-26 WE4.6.1 Support Desk Streamlining board.
Sep 12 2025, 4:00 PM · MW-1.46-notes (1.46.0-wmf.2; 2025-11-12), MediaWiki-extensions-EmailAuth, FY2025-26 WE4.6.1 Support Desk Streamlining

Sep 9 2025

mmartorana closed T355161: Application Security Review Request : PlaceNewSection extension, a subtask of T344501: Add Extension:PlaceNewSection to Russian Wikipedia, as Resolved.
Sep 9 2025, 6:04 PM · MediaWiki-extensions-PlaceNewSection, Wikimedia-extension-review-queue, Release-Engineering-Team, Wikimedia-Extension-setup, Russian-Sites
mmartorana closed T355161: Application Security Review Request : PlaceNewSection extension as Resolved.

Security Review Summary - T355161 - 2025-09-09
Last commit reviewed: 1a70f4d

Sep 9 2025, 6:03 PM · MediaWiki-extensions-PlaceNewSection, secscrum, Security, Application Security Reviews

Aug 25 2025

mmartorana added a comment to T402095: CVE-2025-62663: Stored XSS through a system message in UploadWizard.

From a security perspective, this is safe to deploy.

Aug 25 2025, 3:09 PM · SecTeam-Processed, Vuln-XSS, affects-Miraheze, UploadWizard, Security, Security-Team

Aug 20 2025

mmartorana added a comment to T400960: Get Manfredi access to T&S Zendesk instance.

Hey - I got access to zendesk yesterday, so this can be resolved.

Aug 20 2025, 1:14 PM · Trust-and-Safety, FY2025-26 WE4.6.1 Support Desk Streamlining

Aug 4 2025

mmartorana closed T398852: Onboard Sérgio Lopes to the Security Team as Resolved.
Aug 4 2025, 3:22 PM · SecTeam-Processed, Security-Team
mmartorana updated the task description for T398852: Onboard Sérgio Lopes to the Security Team.
Aug 4 2025, 3:22 PM · SecTeam-Processed, Security-Team

Jul 30 2025

mmartorana moved T399743: Zendesk Spreadsheets Automation from Backlog to In Progress on the FY2025-26 WE4.6.1 Support Desk Streamlining board.
Jul 30 2025, 3:01 PM · FY2025-26 WE4.6.1 Support Desk Streamlining

Jul 18 2025

mmartorana added a comment to T397924: Publish the public key for OAuth 2 access tokens.

From a security perspective, this seems reasonable as long as it’s paired with the usual safeguards: short-lived tokens, proper key rotation, minimal claims, and good client validation guidance. It’s a common pattern across the industry.

Jul 18 2025, 5:12 PM · SecTeam-Processed, MediaWiki-Platform-Team, MW-Interfaces-Team, Security-Team, Security, MediaWiki-extensions-OAuth

Jul 11 2025

mmartorana changed the status of T398840: Modify security-related Phabricator projects related to incidents and audits from Open to In Progress.
Jul 11 2025, 2:33 PM · SecTeam-Processed, Project-Admins, Security, Security-Team
mmartorana added a comment to T398840: Modify security-related Phabricator projects related to incidents and audits.

They all look good to me!

Jul 11 2025, 2:32 PM · SecTeam-Processed, Project-Admins, Security, Security-Team
mmartorana added a comment to T239061: Adopt CSP policy for microsites.

From a security perspective, we support moving forward with adopting CSP policies for these microsites.

Jul 11 2025, 2:28 PM · Vuln-Misconfiguration, Security-Team, collaboration-services, ContentSecurityPolicy
mmartorana changed the status of T239061: Adopt CSP policy for microsites, a subtask of T28508: Content Security Policy (CSP), from Open to In Progress.
Jul 11 2025, 1:52 PM · SecTeam-Processed, Epic, Security, ContentSecurityPolicy, Front-end-Standards-Group, Security-Team, OKR-Work, MediaWiki-General
mmartorana changed the status of T239061: Adopt CSP policy for microsites from Open to In Progress.
Jul 11 2025, 1:52 PM · Vuln-Misconfiguration, Security-Team, collaboration-services, ContentSecurityPolicy

Jul 9 2025

mmartorana added a comment to T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).

Supplemental announcement is out!

Jul 9 2025, 5:03 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security

Jul 8 2025

mmartorana updated the task description for T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).
Jul 8 2025, 5:47 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
mmartorana updated the task description for T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).
Jul 8 2025, 5:46 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security