Last modified: 2013-04-08 17:25:50 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T27622, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 25622 - If a user does not have cookies enabled, they need to be told to have cookies enabled to use the credit card form
If a user does not have cookies enabled, they need to be told to have cookies...
Status: NEW
Product: MediaWiki extensions
Classification: Unclassified
DonationInterface (Other open bugs)
unspecified
All All
: Normal enhancement (vote)
: ---
Assigned To: Arthur Richards
: fundraising
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2010-10-23 13:56 UTC by Arthur Richards
Modified: 2013-04-08 17:25 UTC (History)
4 users (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description Arthur Richards 2010-10-23 13:56:11 UTC
Users need cookies enabled for session handling on the credit card form to prevent CSRF.  At the moment, depending on the particular form the user sees, they can either be entered into an infinite loop of the credit card form refreshing -or- they can still transparently go through the process, although it is a security vulnerability
Comment 1 Andre Klapper 2013-04-08 12:32:16 UTC
What was the trick again (apart from deleting cookies) to get the donation banners displayed again? Adding some parameter to the URL, I assume? Or is that documented somewhere for testers?
Would love to check if this is still a problem nowadays.
Comment 2 Matt Walker 2013-04-08 17:25:50 UTC
There's two 'tricks' if you will. One is adding &reset=1 (and possibly &banner= a banner name from CN if there's no banners currently being run). The other is to delete the 'centralnotice_fundraising' cookie if it exists (this sets the hide flag which will stop CN from even requesting a banner).

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links