Last modified: 2008-03-05 19:21:07 UTC

Wikimedia Bugzilla is closed!

Wikimedia has migrated from Bugzilla to Phabricator. Bug reports should be created and updated in Wikimedia Phabricator instead. Please create an account in Phabricator and add your Bugzilla email address to it.
Wikimedia Bugzilla is read-only. If you try to edit or create any bug report in Bugzilla you will be shown an intentional error message.
In order to access the Phabricator task corresponding to a Bugzilla report, just remove "static-" from its URL.
You could still run searches in Bugzilla or access your list of votes but bug reports will obviously not be up-to-date in Bugzilla.
Bug 13255 - Option to disallow special page transclusion
Option to disallow special page transclusion
Product: MediaWiki
Classification: Unclassified
General/Unknown (Other open bugs)
All All
: Normal major with 1 vote (vote)
: ---
Assigned To: Nobody - You can work on this!
Depends on:
  Show dependency treegraph
Reported: 2008-03-05 07:36 UTC by René Kijewski
Modified: 2008-03-05 19:21 UTC (History)
1 user (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Description René Kijewski 2008-03-05 07:36:45 UTC
As yesterday an exploit in de.wp broke the Wikipedia for half an hour, I propose an option in the localsettings to disallow the transclusion of (some) special pages like newpages, recentchanges, etc.

This should be turned on the Wikimedia project, because if "some bad guy" or an admin running amok puts {{Special:Newpages}} and/or {{Special:Recentchanges}} into any often used template (e.g. {{!}}), it could brake the site again.
Comment 1 Alexandre Emsenhuber [IAlex] 2008-03-05 12:14:42 UTC
There is already $wgAllowSpecialInclusion <> to allow special page transclusion (enabled by default).
Comment 2 Brion Vibber 2008-03-05 19:21:07 UTC
The correct fix is simply to have appropriate limit settings on these queries.

Note You need to log in before you can comment on or make changes to this bug.