Last modified: 2008-03-05 19:21:07 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T15255, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 13255 - Option to disallow special page transclusion
Option to disallow special page transclusion
Status: RESOLVED INVALID
Product: MediaWiki
Classification: Unclassified
General/Unknown (Other open bugs)
unspecified
All All
: Normal major with 1 vote (vote)
: ---
Assigned To: Nobody - You can work on this!
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2008-03-05 07:36 UTC by René Kijewski
Modified: 2008-03-05 19:21 UTC (History)
1 user (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description René Kijewski 2008-03-05 07:36:45 UTC
As yesterday an exploit in de.wp broke the Wikipedia for half an hour, I propose an option in the localsettings to disallow the transclusion of (some) special pages like newpages, recentchanges, etc.

This should be turned on the Wikimedia project, because if "some bad guy" or an admin running amok puts {{Special:Newpages}} and/or {{Special:Recentchanges}} into any often used template (e.g. {{!}}), it could brake the site again.
Comment 1 Alexandre Emsenhuber [IAlex] 2008-03-05 12:14:42 UTC
There is already $wgAllowSpecialInclusion <http://www.mediawiki.org/wiki/Manual:%24wgAllowSpecialInclusion> to allow special page transclusion (enabled by default).
Comment 2 Brion Vibber 2008-03-05 19:21:07 UTC
The correct fix is simply to have appropriate limit settings on these queries.

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links