Last modified: 2007-12-17 14:41:08 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T14321, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 12321 - API list=blocks reveals private data
API list=blocks reveals private data
Status: RESOLVED FIXED
Product: MediaWiki
Classification: Unclassified
API (Other open bugs)
1.12.x
All All
: Normal blocker (vote)
: ---
Assigned To: Nobody - You can work on this!
http://en.wikipedia.org/w/api.php?act...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2007-12-16 07:33 UTC by MER-C
Modified: 2007-12-17 14:41 UTC (History)
3 users (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description MER-C 2007-12-16 07:33:39 UTC
The current implementation of the IP block list reveals the IP address(es) of users who are autoblocked in breach of [[wikimedia:Privacy policy]]. See http://en.wikipedia.org/w/api.php?action=query&list=blocks&bklimit=500 for an example query where this problem occurs.

Expected behaviour: list the autoblock id only in the user attribute as in [[Special:Ipblocklist]] (#xxxxxx) for the entries that deal with autoblocks. Example: user="#123".

Actual behaviour: the IP of the autoblocked users is shown in the user attribute instead.
Comment 1 Tim Starling 2007-12-16 07:59:16 UTC
Disabled list=blocks on Wikimedia pending a fix.
Comment 2 Andrew Garrett 2007-12-16 09:44:38 UTC
Fixed by VasilievVV in r28533.

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links