MediaWiki r115677 - Code Review

Jump to: navigation, search
Repository:MediaWiki
Revision:r115676‎ | r115677 (on ViewVC)‎ | r115678 >
Date:18:34, 20 August 2012
Author:bawolff
Status:new (Comments)
Tags:
Comment:

Update extension from the author's website.

Author claims this resolves several security issues.

This update does weird things to the i18n files.
I'm choosing to just commit it anyhow, some newer
translations may be lost.

I did a very quick test, and it appears to work
(Although i noticed issues with how it handles Namespaces)

Theaitetos has said he is going to take over maintaining this
extension at some point, and eventually request it be moved to
git.
Modified paths:

Diff [purge]

The diff is too large to display.

Follow-up revisions

Rev.Commit summaryAuthorDate
r115681follow-up r115677 - rv changes just to the message file...bawolff20:31, 21 August 2012
r115684follow up r115677 - Upgrade to author's version 2.01...bawolff19:10, 23 August 2012

Comments

#Comment by Siebrand (talk | contribs)   19:10, 20 August 2012

Please revert. This has been a fork for a while. Use of constants in i18n files is not being used in this repo.

#Comment by Bawolff (talk | contribs)   19:29, 20 August 2012

The old version has gigantic security risks. I would consider it better to just totally drop i18n support for this extension than to continue to have the extension with the XSS issues in the repo.

#Comment by Bawolff (talk | contribs)   20:22, 20 August 2012

user:Algorithmix has indicated he would be willing to fix up the i18n issues

#Comment by Bawolff (talk | contribs)   20:31, 21 August 2012

I've done a partial revert of just the i18n file.

#Comment by Bawolff (talk | contribs)   19:25, 23 August 2012

The author made an updated version to try and address concerns raised. I've committed it, and am resetting this to new.

Status & tagging log

  • 19:25, 23 August 2012 Bawolff (talk | contribs) changed the status of r115677 [removed: fixme added: new]
  • 19:10, 20 August 2012 Siebrand (talk | contribs) changed the status of r115677 [removed: new added: fixme]