Page MenuHomePhabricator

Vuln-MisconfigurationBugs
ActivePublic

Members

  • This project does not have any members.
  • View All

Watchers

  • This project does not have any watchers.
  • View All

Details

Description

This tag is used to group security bugs by their general classification, in this case Security misconfigurations. See OWASP Top 10 2017 - A6

Parent project: Security-Team

Recent Activity

Sep 2 2025

matmarex removed a subtask for T40848: Security: CSS positioning can be used to break out of the content area: T37704: Drop support in wikitext for inline styles.
Sep 2 2025, 11:12 PM · SecTeam-Processed, Vuln-Misconfiguration, Security, User-Tgr, TemplateStyles, MediaWiki-User-Interface

Aug 20 2025

sbassett changed the visibility for T397891: User without checkuser-temporary-account-auto-reveal permission can auto-reveal IPs.
Aug 20 2025, 3:45 PM · OKR-Work, Temporary accounts (Global wiki rollout), Trust and Safety Product Sprint (Sprint Rum baba (July 28 - August 15)), CheckUser, Vuln-Misconfiguration, Vuln-Infoleak, SecTeam-Processed, Trust and Safety Product Team, Security, Security-Team
sbassett moved T397891: User without checkuser-temporary-account-auto-reveal permission can auto-reveal IPs from Watching to Our Part Is Done on the Security-Team board.
Aug 20 2025, 3:44 PM · OKR-Work, Temporary accounts (Global wiki rollout), Trust and Safety Product Sprint (Sprint Rum baba (July 28 - August 15)), CheckUser, Vuln-Misconfiguration, Vuln-Infoleak, SecTeam-Processed, Trust and Safety Product Team, Security, Security-Team
Dreamy_Jazz closed T397891: User without checkuser-temporary-account-auto-reveal permission can auto-reveal IPs as Resolved.

I think we can call this resolved:

Aug 20 2025, 10:15 AM · OKR-Work, Temporary accounts (Global wiki rollout), Trust and Safety Product Sprint (Sprint Rum baba (July 28 - August 15)), CheckUser, Vuln-Misconfiguration, Vuln-Infoleak, SecTeam-Processed, Trust and Safety Product Team, Security, Security-Team

Aug 15 2025

taavi triaged T401190: Toolforge loki allows unauthenticated access to logs across namespaces as High priority.
Aug 15 2025, 1:04 PM · SecTeam-Processed, Vuln-Misconfiguration, cloud-services-team, Toolforge, Security
taavi closed T401190: Toolforge loki allows unauthenticated access to logs across namespaces as Resolved.

This is resolved with the live hack being committed as https://gitlab.wikimedia.org/repos/cloud/toolforge/toolforge-deploy/-/merge_requests/927. Thanks again for the report.

Aug 15 2025, 1:03 PM · SecTeam-Processed, Vuln-Misconfiguration, cloud-services-team, Toolforge, Security

Aug 14 2025

Dreamy_Jazz added a project to T397891: User without checkuser-temporary-account-auto-reveal permission can auto-reveal IPs: OKR-Work.
Aug 14 2025, 10:33 AM · OKR-Work, Temporary accounts (Global wiki rollout), Trust and Safety Product Sprint (Sprint Rum baba (July 28 - August 15)), CheckUser, Vuln-Misconfiguration, Vuln-Infoleak, SecTeam-Processed, Trust and Safety Product Team, Security, Security-Team

Aug 13 2025

STran moved T397891: User without checkuser-temporary-account-auto-reveal permission can auto-reveal IPs from Needs Review to Done on the Trust and Safety Product Sprint (Sprint Rum baba (July 28 - August 15)) board.
Aug 13 2025, 6:06 PM · OKR-Work, Temporary accounts (Global wiki rollout), Trust and Safety Product Sprint (Sprint Rum baba (July 28 - August 15)), CheckUser, Vuln-Misconfiguration, Vuln-Infoleak, SecTeam-Processed, Trust and Safety Product Team, Security, Security-Team

Aug 12 2025

Dreamy_Jazz added a comment to T397891: User without checkuser-temporary-account-auto-reveal permission can auto-reveal IPs.

Created patch https://gerrit.wikimedia.org/r/c/mediawiki/extensions/CheckUser/+/1177991 which is ready for review.

Aug 12 2025, 8:00 PM · OKR-Work, Temporary accounts (Global wiki rollout), Trust and Safety Product Sprint (Sprint Rum baba (July 28 - August 15)), CheckUser, Vuln-Misconfiguration, Vuln-Infoleak, SecTeam-Processed, Trust and Safety Product Team, Security, Security-Team
Dreamy_Jazz added a comment to T397891: User without checkuser-temporary-account-auto-reveal permission can auto-reveal IPs.

Thanks for the comments! I'll create a backport of the patch I mentioned to REL1.44. It will likely need review because it merge conflicts as it stands quite heavily.

Aug 12 2025, 4:02 PM · OKR-Work, Temporary accounts (Global wiki rollout), Trust and Safety Product Sprint (Sprint Rum baba (July 28 - August 15)), CheckUser, Vuln-Misconfiguration, Vuln-Infoleak, SecTeam-Processed, Trust and Safety Product Team, Security, Security-Team
STran added a comment to T397891: User without checkuser-temporary-account-auto-reveal permission can auto-reveal IPs.

Moving to 'Needs Review' to see if others agree with my proposed direction on this task.

Aug 12 2025, 1:11 PM · OKR-Work, Temporary accounts (Global wiki rollout), Trust and Safety Product Sprint (Sprint Rum baba (July 28 - August 15)), CheckUser, Vuln-Misconfiguration, Vuln-Infoleak, SecTeam-Processed, Trust and Safety Product Team, Security, Security-Team
Niharika moved T397891: User without checkuser-temporary-account-auto-reveal permission can auto-reveal IPs from Q2 FY25-26 candidates to Global wiki rollout on the Temporary accounts board.
Aug 12 2025, 12:09 PM · OKR-Work, Temporary accounts (Global wiki rollout), Trust and Safety Product Sprint (Sprint Rum baba (July 28 - August 15)), CheckUser, Vuln-Misconfiguration, Vuln-Infoleak, SecTeam-Processed, Trust and Safety Product Team, Security, Security-Team

Aug 11 2025

sbassett edited projects for T401190: Toolforge loki allows unauthenticated access to logs across namespaces, added: Vuln-Misconfiguration, SecTeam-Processed; removed Security-Team.
Aug 11 2025, 4:46 PM · SecTeam-Processed, Vuln-Misconfiguration, cloud-services-team, Toolforge, Security
sbassett added a comment to T397891: User without checkuser-temporary-account-auto-reveal permission can auto-reveal IPs.

@sbassett / @Reedy

Given that the fix for this is in the public master branch (fixed through addressing other issues), could we consider publicly backporting the fix to REL1_44 without mentioning it as a security issue? I think this is okay because this is only security issue if:

  • Temporary accounts are enabled (marked as an unstable config)
  • CheckUser is installed
  • The user has the checkuser-temporary-account right (which means by default only users in the checkuser and temporary-account-viewer groups)
Aug 11 2025, 3:49 PM · OKR-Work, Temporary accounts (Global wiki rollout), Trust and Safety Product Sprint (Sprint Rum baba (July 28 - August 15)), CheckUser, Vuln-Misconfiguration, Vuln-Infoleak, SecTeam-Processed, Trust and Safety Product Team, Security, Security-Team
JTweed-WMF moved T100556: Password reset function should not send the email to blocked accounts if $wgBlockDisablesLogin from Inbox, needs triage to Backlog on the MediaWiki-Platform-Team board.
Aug 11 2025, 2:44 PM · MediaWiki-Platform-Team, Vuln-Misconfiguration, SecTeam-Processed, Trust and Safety Product Team, MediaWiki-Blocks, MediaWiki-Core-AuthManager

Aug 6 2025

Dreamy_Jazz moved T397891: User without checkuser-temporary-account-auto-reveal permission can auto-reveal IPs from Ready to Needs Review on the Trust and Safety Product Sprint (Sprint Rum baba (July 28 - August 15)) board.

We could update the front-end if we think there is a legitimate case that a user could have auto-reveal mode considered on in the front-end but off in the back-end.

In any case, addressing this would not be fixing a security issue so I would prefer to do this publicly without backporting.

Aug 6 2025, 9:02 PM · OKR-Work, Temporary accounts (Global wiki rollout), Trust and Safety Product Sprint (Sprint Rum baba (July 28 - August 15)), CheckUser, Vuln-Misconfiguration, Vuln-Infoleak, SecTeam-Processed, Trust and Safety Product Team, Security, Security-Team
Dreamy_Jazz claimed T397891: User without checkuser-temporary-account-auto-reveal permission can auto-reveal IPs.
Aug 6 2025, 8:59 PM · OKR-Work, Temporary accounts (Global wiki rollout), Trust and Safety Product Sprint (Sprint Rum baba (July 28 - August 15)), CheckUser, Vuln-Misconfiguration, Vuln-Infoleak, SecTeam-Processed, Trust and Safety Product Team, Security, Security-Team
Dreamy_Jazz updated subscribers of T397891: User without checkuser-temporary-account-auto-reveal permission can auto-reveal IPs.

Given that the fix for this is in the public master branch (fixed through addressing other issues), could we consider publicly backporting the fix to REL1_44 without mentioning it as a security issue? I think this is okay because this is only security issue if:

  • Temporary accounts are enabled (marked as an unstable config)
  • CheckUser is installed
  • The user has the checkuser-temporary-account right (which means by default only users in the checkuser and temporary-account-viewer groups)
Aug 6 2025, 8:59 PM · OKR-Work, Temporary accounts (Global wiki rollout), Trust and Safety Product Sprint (Sprint Rum baba (July 28 - August 15)), CheckUser, Vuln-Misconfiguration, Vuln-Infoleak, SecTeam-Processed, Trust and Safety Product Team, Security, Security-Team
Dreamy_Jazz added a comment to T397891: User without checkuser-temporary-account-auto-reveal permission can auto-reveal IPs.

One additional point. Because this is a security task, we will need to create security backports of the fix in 1abae1d48f75f8b0d53a5a1ff18c549b8a9da68c. We will need to backport it to only REL1_44. In REL1_43 and earlier the feature did not exist (so no backport is needed).

Aug 6 2025, 8:56 PM · OKR-Work, Temporary accounts (Global wiki rollout), Trust and Safety Product Sprint (Sprint Rum baba (July 28 - August 15)), CheckUser, Vuln-Misconfiguration, Vuln-Infoleak, SecTeam-Processed, Trust and Safety Product Team, Security, Security-Team
Dreamy_Jazz moved T100556: Password reset function should not send the email to blocked accounts if $wgBlockDisablesLogin from Inbox to Tracking work by others on the Trust and Safety Product Team board.
Aug 6 2025, 10:22 AM · MediaWiki-Platform-Team, Vuln-Misconfiguration, SecTeam-Processed, Trust and Safety Product Team, MediaWiki-Blocks, MediaWiki-Core-AuthManager
Dreamy_Jazz moved T397891: User without checkuser-temporary-account-auto-reveal permission can auto-reveal IPs from Inbox to Engineering on the Trust and Safety Product Team board.
Aug 6 2025, 9:28 AM · OKR-Work, Temporary accounts (Global wiki rollout), Trust and Safety Product Sprint (Sprint Rum baba (July 28 - August 15)), CheckUser, Vuln-Misconfiguration, Vuln-Infoleak, SecTeam-Processed, Trust and Safety Product Team, Security, Security-Team

Aug 5 2025

Dreamy_Jazz added a comment to T397891: User without checkuser-temporary-account-auto-reveal permission can auto-reveal IPs.

Given that T399747: Limit the number of IPs that can be revealed per day seems to be controversial, we should address this task via the Permission checking approaches mentioned in T397891#10954244.

Whoever picks up this task should take some time to decide which approach is best (whether it's one mentioned in that comment or something else).

I already did this AFAICS in 1abae1d48f75f8b0d53a5a1ff18c549b8a9da68c

Aug 5 2025, 4:01 PM · OKR-Work, Temporary accounts (Global wiki rollout), Trust and Safety Product Sprint (Sprint Rum baba (July 28 - August 15)), CheckUser, Vuln-Misconfiguration, Vuln-Infoleak, SecTeam-Processed, Trust and Safety Product Team, Security, Security-Team
Tchanders updated subscribers of T397891: User without checkuser-temporary-account-auto-reveal permission can auto-reveal IPs.
Aug 5 2025, 3:58 PM · OKR-Work, Temporary accounts (Global wiki rollout), Trust and Safety Product Sprint (Sprint Rum baba (July 28 - August 15)), CheckUser, Vuln-Misconfiguration, Vuln-Infoleak, SecTeam-Processed, Trust and Safety Product Team, Security, Security-Team
Tchanders added a comment to T397891: User without checkuser-temporary-account-auto-reveal permission can auto-reveal IPs.

Given that T399747: Limit the number of IPs that can be revealed per day seems to be controversial, we should address this task via the Permission checking approaches mentioned in T397891#10954244.

Aug 5 2025, 3:56 PM · OKR-Work, Temporary accounts (Global wiki rollout), Trust and Safety Product Sprint (Sprint Rum baba (July 28 - August 15)), CheckUser, Vuln-Misconfiguration, Vuln-Infoleak, SecTeam-Processed, Trust and Safety Product Team, Security, Security-Team

Aug 1 2025

OKryva-WMF moved T397891: User without checkuser-temporary-account-auto-reveal permission can auto-reveal IPs from Priority Backlog to Ready on the Trust and Safety Product Sprint (Sprint Rum baba (July 28 - August 15)) board.
Aug 1 2025, 1:41 PM · OKR-Work, Temporary accounts (Global wiki rollout), Trust and Safety Product Sprint (Sprint Rum baba (July 28 - August 15)), CheckUser, Vuln-Misconfiguration, Vuln-Infoleak, SecTeam-Processed, Trust and Safety Product Team, Security, Security-Team
OKryva-WMF added a project to T397891: User without checkuser-temporary-account-auto-reveal permission can auto-reveal IPs: Trust and Safety Product Sprint (Sprint Rum baba (July 28 - August 15)).
Aug 1 2025, 1:40 PM · OKR-Work, Temporary accounts (Global wiki rollout), Trust and Safety Product Sprint (Sprint Rum baba (July 28 - August 15)), CheckUser, Vuln-Misconfiguration, Vuln-Infoleak, SecTeam-Processed, Trust and Safety Product Team, Security, Security-Team
Tchanders updated subscribers of T397891: User without checkuser-temporary-account-auto-reveal permission can auto-reveal IPs.
Aug 1 2025, 1:08 PM · OKR-Work, Temporary accounts (Global wiki rollout), Trust and Safety Product Sprint (Sprint Rum baba (July 28 - August 15)), CheckUser, Vuln-Misconfiguration, Vuln-Infoleak, SecTeam-Processed, Trust and Safety Product Team, Security, Security-Team
Dreamy_Jazz moved T397891: User without checkuser-temporary-account-auto-reveal permission can auto-reveal IPs from Inbox to Temporary account IP reveal on the CheckUser board.
Aug 1 2025, 12:27 PM · OKR-Work, Temporary accounts (Global wiki rollout), Trust and Safety Product Sprint (Sprint Rum baba (July 28 - August 15)), CheckUser, Vuln-Misconfiguration, Vuln-Infoleak, SecTeam-Processed, Trust and Safety Product Team, Security, Security-Team
Dreamy_Jazz added a project to T397891: User without checkuser-temporary-account-auto-reveal permission can auto-reveal IPs: CheckUser.
Aug 1 2025, 12:19 PM · OKR-Work, Temporary accounts (Global wiki rollout), Trust and Safety Product Sprint (Sprint Rum baba (July 28 - August 15)), CheckUser, Vuln-Misconfiguration, Vuln-Infoleak, SecTeam-Processed, Trust and Safety Product Team, Security, Security-Team
Tchanders set the point value for T397891: User without checkuser-temporary-account-auto-reveal permission can auto-reveal IPs to 1.
Aug 1 2025, 10:16 AM · OKR-Work, Temporary accounts (Global wiki rollout), Trust and Safety Product Sprint (Sprint Rum baba (July 28 - August 15)), CheckUser, Vuln-Misconfiguration, Vuln-Infoleak, SecTeam-Processed, Trust and Safety Product Team, Security, Security-Team

Jul 22 2025

Niharika moved T397891: User without checkuser-temporary-account-auto-reveal permission can auto-reveal IPs from In progress to Q2 FY25-26 candidates on the Temporary accounts board.
Jul 22 2025, 11:06 AM · OKR-Work, Temporary accounts (Global wiki rollout), Trust and Safety Product Sprint (Sprint Rum baba (July 28 - August 15)), CheckUser, Vuln-Misconfiguration, Vuln-Infoleak, SecTeam-Processed, Trust and Safety Product Team, Security, Security-Team

Jul 16 2025

Tchanders added a comment to T397891: User without checkuser-temporary-account-auto-reveal permission can auto-reveal IPs.

The main issue here is that a user with the IP reveal right could reveal many IPs without having to click many times. They could achieve the same effect as auto-reveal by clicking a lot. This in itself is a problem, so we should introduce rate limiting, irrespective of this task. Once we have rate limiting, this won't be as much of a problem any more.

Jul 16 2025, 5:47 PM · OKR-Work, Temporary accounts (Global wiki rollout), Trust and Safety Product Sprint (Sprint Rum baba (July 28 - August 15)), CheckUser, Vuln-Misconfiguration, Vuln-Infoleak, SecTeam-Processed, Trust and Safety Product Team, Security, Security-Team

Jul 15 2025

Tchanders placed T397891: User without checkuser-temporary-account-auto-reveal permission can auto-reveal IPs up for grabs.
Jul 15 2025, 5:41 PM · OKR-Work, Temporary accounts (Global wiki rollout), Trust and Safety Product Sprint (Sprint Rum baba (July 28 - August 15)), CheckUser, Vuln-Misconfiguration, Vuln-Infoleak, SecTeam-Processed, Trust and Safety Product Team, Security, Security-Team

Jul 11 2025

Dzahn updated the task description for T239061: Adopt CSP policy for microsites.
Jul 11 2025, 6:07 PM · Vuln-Misconfiguration, Security-Team, collaboration-services, ContentSecurityPolicy
mmartorana added a comment to T239061: Adopt CSP policy for microsites.

From a security perspective, we support moving forward with adopting CSP policies for these microsites.

Jul 11 2025, 2:28 PM · Vuln-Misconfiguration, Security-Team, collaboration-services, ContentSecurityPolicy
mmartorana changed the status of T239061: Adopt CSP policy for microsites from Open to In Progress.
Jul 11 2025, 1:52 PM · Vuln-Misconfiguration, Security-Team, collaboration-services, ContentSecurityPolicy

Jul 8 2025

Niharika moved T397891: User without checkuser-temporary-account-auto-reveal permission can auto-reveal IPs from Inbox to In progress on the Temporary accounts board.
Jul 8 2025, 9:36 AM · OKR-Work, Temporary accounts (Global wiki rollout), Trust and Safety Product Sprint (Sprint Rum baba (July 28 - August 15)), CheckUser, Vuln-Misconfiguration, Vuln-Infoleak, SecTeam-Processed, Trust and Safety Product Team, Security, Security-Team

Jul 7 2025

sbassett triaged T385403: Wrong E-Mail address composition for usernames with a comma in it "Doe, John" (observed today in MW 1.41.0) as Low priority.
Jul 7 2025, 5:04 PM · MediaWiki-Engineering, Vuln-Misconfiguration, MediaWiki-Email, Security, Security-Team
Mstyles moved T385403: Wrong E-Mail address composition for usernames with a comma in it "Doe, John" (observed today in MW 1.41.0) from In Progress to Our Part Is Done on the Security-Team board.
Jul 7 2025, 4:17 PM · MediaWiki-Engineering, Vuln-Misconfiguration, MediaWiki-Email, Security, Security-Team
Mstyles closed T385403: Wrong E-Mail address composition for usernames with a comma in it "Doe, John" (observed today in MW 1.41.0) as Invalid.

Marking as invalid since we were not able to reproduce this issue on our side. Feel free to reopen @Wikinaut if you still see any issues.

Jul 7 2025, 4:17 PM · MediaWiki-Engineering, Vuln-Misconfiguration, MediaWiki-Email, Security, Security-Team
kostajh edited projects for T397891: User without checkuser-temporary-account-auto-reveal permission can auto-reveal IPs, added: Trust and Safety Product Sprint (Sprint Cannoli (July 7 - July 25)); removed Trust and Safety Product Sprint (Sprint Baklava (June 16 - July 4)).
Jul 7 2025, 9:45 AM · OKR-Work, Temporary accounts (Global wiki rollout), Trust and Safety Product Sprint (Sprint Rum baba (July 28 - August 15)), CheckUser, Vuln-Misconfiguration, Vuln-Infoleak, SecTeam-Processed, Trust and Safety Product Team, Security, Security-Team

Jul 2 2025

kostajh moved T397891: User without checkuser-temporary-account-auto-reveal permission can auto-reveal IPs from Priority Backlog to In Progress on the Trust and Safety Product Sprint (Sprint Baklava (June 16 - July 4)) board.
Jul 2 2025, 10:29 AM · OKR-Work, Temporary accounts (Global wiki rollout), Trust and Safety Product Sprint (Sprint Rum baba (July 28 - August 15)), CheckUser, Vuln-Misconfiguration, Vuln-Infoleak, SecTeam-Processed, Trust and Safety Product Team, Security, Security-Team

Jun 30 2025

sbassett moved T397891: User without checkuser-temporary-account-auto-reveal permission can auto-reveal IPs from Incoming to Watching on the Security-Team board.
Jun 30 2025, 4:23 PM · OKR-Work, Temporary accounts (Global wiki rollout), Trust and Safety Product Sprint (Sprint Rum baba (July 28 - August 15)), CheckUser, Vuln-Misconfiguration, Vuln-Infoleak, SecTeam-Processed, Trust and Safety Product Team, Security, Security-Team

Jun 23 2025

Mstyles added a comment to T385403: Wrong E-Mail address composition for usernames with a comma in it "Doe, John" (observed today in MW 1.41.0).

@Wikinaut can you verify the reproduction steps that @Jly posted?

Jun 23 2025, 4:18 PM · MediaWiki-Engineering, Vuln-Misconfiguration, MediaWiki-Email, Security, Security-Team

Jun 21 2025

Aklapper changed the status of T385403: Wrong E-Mail address composition for usernames with a comma in it "Doe, John" (observed today in MW 1.41.0) from Open to Stalled.
Jun 21 2025, 7:33 AM · MediaWiki-Engineering, Vuln-Misconfiguration, MediaWiki-Email, Security, Security-Team

Jun 19 2025

Jly added a comment to T385403: Wrong E-Mail address composition for usernames with a comma in it "Doe, John" (observed today in MW 1.41.0).

I wasn't able to reproduce this. I tested this on a local development of MediaWiki 1.41.0 (8ce0ec5) with an SMTP server. I've captured the raw email logs, and they are being sent correctly to the user. Can you validate the steps below to reproduce the bug, or please share the correct steps:

Jun 19 2025, 12:12 PM · MediaWiki-Engineering, Vuln-Misconfiguration, MediaWiki-Email, Security, Security-Team

Jun 16 2025

Mstyles added a comment to T385403: Wrong E-Mail address composition for usernames with a comma in it "Doe, John" (observed today in MW 1.41.0).

@Wikinaut We did not try to reproduce in the version that you reported it in, just in 1.44.0. I'll find out if we can reproduce in 1.41.0

Jun 16 2025, 4:10 PM · MediaWiki-Engineering, Vuln-Misconfiguration, MediaWiki-Email, Security, Security-Team

Jun 11 2025

sbassett added a comment to T394828: People who are banned from clicking on forgot password can do so by visiting Urdu Wikipedia.

@Syed_Azmat_Husain - You could propose a new, public task requesting this functionality. I would probably title it something like "Locally blocked Wikimedia users should not be allowed to reset their passwords on any SUL project" or something like that. Again, whether you agree with it or not, there are reasons for why this is currently allowed and an escalation path for abuse via global block requests. So I do not personally consider this an urgent security issue. There has also been some previous discussion about a related matter in T109909, for additional context.

Jun 11 2025, 3:46 PM · MediaWiki-Platform-Team, MediaWiki-Core-AuthManager, SecTeam-Processed, Security-Team
Syed_Azmat_Husain added a comment to T394828: People who are banned from clicking on forgot password can do so by visiting Urdu Wikipedia.

Thanks for the response. Just to clarify, this isn’t about override logs. The concern is that if a user or IP is *locally blocked* from using "Forgot Password" on English Wikipedia, they can simply go to another project like Urdu Wikipedia and use the same feature. Since Wikimedia accounts are global, the password reset still goes through, bypassing the original block's intent. This seems to be a functional loophole. Should this not be handled?

Jun 11 2025, 4:02 AM · MediaWiki-Platform-Team, MediaWiki-Core-AuthManager, SecTeam-Processed, Security-Team

Jun 10 2025

sbassett added a comment to T394828: People who are banned from clicking on forgot password can do so by visiting Urdu Wikipedia.

@Syed_Azmat_Husain - So the way MediaWiki blocks currently work - with local and global IP blocks possible - is very much intentional and by design. I've verified with the global stewards that it does not look like Urdu Wikipiedia has ever overriden any global blocks, according to its logs: https://ur.wikipedia.org/wiki/%D8%AE%D8%A7%D8%B5:%D9%86%D9%88%D8%B4%D8%AA%DB%81?type=gblblock&user=&page=&wpdate=&tagfilter=&wpfilters%5B%5D=newusers&wpFormIdentifier=logeventslist. If traffic from an IP address or range starts to become an issue on other projects, and a local block or a few local blocks are not enough to stop the abuser, then a global block can and should be requested: https://meta.wikimedia.org/wiki/Global_blocks.

Jun 10 2025, 7:15 PM · MediaWiki-Platform-Team, MediaWiki-Core-AuthManager, SecTeam-Processed, Security-Team