Last modified: 2013-04-05 00:12:54 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T17489, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 15489 - Limit scripts to non-new users
Limit scripts to non-new users
Status: RESOLVED INVALID
Product: Wikimedia
Classification: Unclassified
Site requests (Other open bugs)
unspecified
All All
: Lowest normal with 1 vote (vote)
: ---
Assigned To: Nobody - You can work on this!
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2008-09-05 18:02 UTC by Mark Pellegrini
Modified: 2013-04-05 00:12 UTC (History)
7 users (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description Mark Pellegrini 2008-09-05 18:02:13 UTC
New users should not be able to run scripts. There's been a recent rash of vandalism where vandals register a new account, paste in a monobook script (like twinkle), and use it to vandalize (http://en.wikipedia.org/wiki/Special:Contributions/REDyellowGreenBLUE) 

Please limit running scripts to auto-approved users.
Comment 1 Dan Collins 2008-09-09 10:22:55 UTC
Is there consensus to do this on enwiki? It'd probably be fairly trivial to add a check before loading a user's monobook that they are autoconfirmed, but that doesn't stop them from using it with a tool like greasemonkey.
Comment 2 Aaron Schulz 2008-10-07 00:59:33 UTC
Needs consensus to implement.
Comment 3 Chad H. 2011-11-29 21:58:02 UTC
Would be easy enough to do in ResourceLoaderUserModule--add usercss & userjs rights to 'user' so no change in default config.

REOPENING.
Comment 4 Nemo 2013-04-04 21:09:14 UTC
No consensus found in 15 more months and if not by RateLimits they're surely doing it via AbuseFilter.

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links