Last modified: 2008-05-26 02:39:47 UTC

Wikimedia Bugzilla is closed!

Wikimedia has migrated from Bugzilla to Phabricator. Bug reports should be created and updated in Wikimedia Phabricator instead. Please create an account in Phabricator and add your Bugzilla email address to it.
Wikimedia Bugzilla is read-only. If you try to edit or create any bug report in Bugzilla you will be shown an intentional error message.
In order to access the Phabricator task corresponding to a Bugzilla report, just remove "static-" from its URL.
You could still run searches in Bugzilla or access your list of votes but bug reports will obviously not be up-to-date in Bugzilla.
Bug 14248 - Still able to create accounts on projects with a SUL-account-name
Still able to create accounts on projects with a SUL-account-name
Product: MediaWiki extensions
Classification: Unclassified
CentralAuth (Other open bugs)
All All
: High major with 2 votes (vote)
: ---
Assigned To: Nobody - You can work on this!
Depends on:
  Show dependency treegraph
Reported: 2008-05-24 12:06 UTC by Willemo
Modified: 2008-05-26 02:39 UTC (History)
6 users (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Description Willemo 2008-05-24 12:06:23 UTC
I was a bit playing with SUL functionality and tried to register my account on projects which I never registered before. I could login instantly, but I tried to create an account the old-fashioned way. I did use different passwords etc.

If I quote

The greatest advantages are single sign-up (...) consistent identity (your username now always means you; no one else can take your name on another project).

As far I can see for now, this isn't the case. I am still able to create accounts (though I didn't try this with other usernames) I don't know whether this is done intentionally (I couldn't find any statement about this), some IP-check is performed, or this is really a bug.
Comment 1 spacebirdy 2008-05-24 16:51:10 UTC
Today this bug was brought to my attention by Pill.

We did some tests on

Pills SUL was not complete (1 wiki was left open) but his SUL was activated
he was able to create an account with the name Pill (he used another password another (or no) mail)

We wanted to test with someone whoses SUL was completet too.

The SUL of Baisemain was complete (I checked before with CentralAuth),
she too was able to create a totally new account with the name Baisemain on!

This looks quite serious to me.

Many thanks for Your help,
Elisabeth Anderl [[:wikt:is:Notandi:Spacebirdy]]
Comment 2 Church of emacs 2008-05-25 09:43:09 UTC
Looks quite serious to me, too; therefor I changed Priority from normal to high and Severity from normal to major (feel free to revert this though, I am no expert).
Comment 3 Thomas Goldammer 2008-05-25 15:10:37 UTC
Please make sure that this bug gets fixed *before* enabling SUL for all. Otherwise we will get tons of complains by community members facing new fake accounts. (And, seeing the recent cross-wiki activity, fake-accounting seems to be a major issue these days...)

BR, Th.
Comment 4 Platonides 2008-05-25 20:18:38 UTC
Just checked out
This should be blocking further SUL expansion.
Comment 5 Korg 2008-05-25 20:22:34 UTC
This bug was also reported on Meta: see
Comment 6 Tim Starling 2008-05-26 02:39:47 UTC
Regression due to r34124, fixed in r35340.

Note You need to log in before you can comment on or make changes to this bug.