Last modified: 2009-08-06 22:28:39 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T22099, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 20099 - CSRF possible with Special:UsabilityInitiativeOptIn
CSRF possible with Special:UsabilityInitiativeOptIn
Status: RESOLVED FIXED
Product: MediaWiki extensions
Classification: Unclassified
UsabilityInitiative (Other open bugs)
unspecified
All All
: Normal minor (vote)
: ---
Assigned To: Trevor Parscal
http://en.wikipedia.org/wiki/User:Nak...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2009-08-06 21:57 UTC by Nakon
Modified: 2009-08-06 22:28 UTC (History)
2 users (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description Nakon 2009-08-06 21:57:35 UTC
It is possible to automatically opt a user in to the beta without their knowledge.  If the img tag in the link above is placed on a page and a logged-in user visits the page, they will automatically be opted-in to the beta
Comment 1 Brion Vibber 2009-08-06 22:23:39 UTC
Trevor's looking into this; we're currently looking at using session tokens similar to what's being done for rollback links from the history page. This lets us still use a GET req which is easy to forward to without forcing an extra <form> for a POST submission, while staying safe from predictable URLs.
Comment 2 Trevor Parscal 2009-08-06 22:28:39 UTC
Resolved in r54542 by adding edit token checking to the optin and optout procedures.

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links