Last modified: 2008-08-08 11:30:53 UTC

Wikimedia Bugzilla is closed!

Wikimedia has migrated from Bugzilla to Phabricator. Bug reports should be created and updated in Wikimedia Phabricator instead. Please create an account in Phabricator and add your Bugzilla email address to it.
Wikimedia Bugzilla is read-only. If you try to edit or create any bug report in Bugzilla you will be shown an intentional error message.
In order to access the Phabricator task corresponding to a Bugzilla report, just remove "static-" from its URL.
You could still run searches in Bugzilla or access your list of votes but bug reports will obviously not be up-to-date in Bugzilla.
Bug 12579 - Arbitrary user's e-mail address sent when blocking another user
Arbitrary user's e-mail address sent when blocking another user
Product: MediaWiki
Classification: Unclassified
Email (Other open bugs)
All All
: Normal critical (vote)
: ---
Assigned To: Nobody - You can work on this!
Depends on:
  Show dependency treegraph
Reported: 2008-01-10 16:47 UTC by Xosé
Modified: 2008-08-08 11:30 UTC (History)
2 users (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Description Xosé 2008-01-10 16:47:53 UTC
I'm reporting something weird that happened on the Galician wikipedia on behalf of the affected user.

User DOA was blocked by sysop Albert galiza for including self-promotional content (18:36, 15 dec 2007).

On logging back into the system, user DOA got a message stating that he had been blocked and asking him to contact user Alma, who is not a sysop, along with a list of syops. Alma's name was in red and when user DOA clicked on her name he could see Alma's e-mail address. User DOA wrote to Alma and to the first sysop on the list (Albert galiza); eventually, Alma and DOA cleared out the situation on the phone, Alma asked Albert galiza and another sysop and finally asked me to look into this.

In order to test the message announcing the block I blocked my own bot account and couldn't see anything strange when logging back. The only guess we could make about why Alma's name would be sent is that she was the first user to greet DOA.

We're concerned that a private e-mail address can be shown to another user and wonder whether this is a known bug.
Comment 1 AGK 2008-01-11 19:59:46 UTC
I'd be interested in whether this is a one-off complaint of this nature, or whether there are more users of MW out there who have experienced this.


Comment 2 Brion Vibber 2008-01-11 20:40:40 UTC
Well, there's no way the block message can get at an email address; the code's just not there.

Most likely scenario off the top of my head: DOA followed Alma's signature from his talk page, then clicked the 'email this user' link on the sidebar.

The only time you should ever see an e-mail address on a link will be if someone explicitly added a mailto: link to a page with that address. Can you confirm that such an address was actually shown, or was it just the in-wiki form?
Comment 3 Andrew Garrett 2008-08-08 11:30:53 UTC
No further information, closing as WORKSFORME.

Note You need to log in before you can comment on or make changes to this bug.