Last modified: 2014-08-16 10:26:30 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T70776, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 68776 - Merge ViewFiles extension to the core
Merge ViewFiles extension to the core
Status: UNCONFIRMED
Product: MediaWiki
Classification: Unclassified
Special pages (Other open bugs)
1.24rc
All All
: Lowest enhancement (vote)
: ---
Assigned To: Nobody - You can work on this!
:
Depends on:
Blocks: 26751
  Show dependency treegraph
 
Reported: 2014-07-29 00:04 UTC by Nathan Larson
Modified: 2014-08-16 10:26 UTC (History)
1 user (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description Nathan Larson 2014-07-29 00:04:58 UTC
[[mw:Extension:ViewFiles]] implements the Special:ViewFiles page, important for allowing users to view LocalSettings.php.
Comment 1 MZMcBride 2014-07-29 00:16:00 UTC
(In reply to Nathan Larson from comment #0)
> [[mw:Extension:ViewFiles]] implements the Special:ViewFiles page, important
> for allowing users to view LocalSettings.php.

It looks like you wrote [[mw:Extension:ViewFiles]]. If merged into core, this feature would need to be permanently disabled with a very explicit warning attached to it due to the security implications, as I understand it.

Broadly, I imagine we want a better long-term solution for viewing and managing MediaWiki configuration.

In order for this ticket to move forward, I'd like to first see evidence that the ViewFiles MediaWiki extension is widely installed or that there's a great demand from MediaWiki system administrators and users to have this "view [configuration] files" feature almost always available (at the flick of a switch). I think it will be difficult to meet this burden, so I'm marking this bug as unconfirmed for now.
Comment 2 Nathan Larson 2014-07-29 00:20:22 UTC
I think UNCONFIRMED would be for if we weren't certain whether it's unmerged. In other words, a question of fact rather than an opinion as to the likelihood that it should be WONTFIXed. This was discussed (briefly) at [[mw:Talk:Bug management/Bug report life cycle]]; feel free to weigh in there on the more general question of how UNCONFIRMED should be used.
Comment 3 Nathan Larson 2014-07-29 00:24:25 UTC
Perhaps ViewFiles could be made smart enough to tell whether sensitive configuration settings, e.g. $wgDBpassword, are exposed in the config file. It could look for, e.g., the string $wgDBpassword = "

If that string is present, then it could, by default, not allow the file to be viewed. Alternatively, there could be a config setting, $wgViewFilesEnabled, that would by default be set to false.

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links