HomePhabricator

Isolate wikidata.org cookies and CORS policies

Description

Isolate wikidata.org cookies and CORS policies

query.wikidata.org is a new service that should not have access to
MediaWiki/CentralAuth cookies, nor be allowed to send CORS requests.

The login cookie is now only set for "www.wikidata.org". Users of
test.wikidata.org will need to manually visit the wiki to be logged in.

CORS requests are now only accepted from "www.wikidata.org" and
"test.wikidata.org".

Bug: T108101
Change-Id: I67dba772a239e3dec50809c4252419cfdb90ee36

Details

Provenance
LegoktmAuthored on
Parents
rOMWC672c37987a60: group1 wikis to 1.26wmf18
Branches
Unknown
Tags
Unknown
ChangeId
I67dba772a239e3dec50809c4252419cfdb90ee36