[Bug 28962] ajax calls with '.' not working in IE

2011-06-22 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28962

Bug 28962 depends on bug 28840, which changed state.

Bug 28840 Summary: Loader broken in IE because mediawiki thinks the periods in 
module names is a security leak (spoof extension)
https://bugzilla.wikimedia.org/show_bug.cgi?id=28840

   What|Old Value   |New Value

 Status|RESOLVED|REOPENED
 Resolution|FIXED   |

-- 
Configure bugmail: https://bugzilla.wikimedia.org/userprefs.cgi?tab=email
--- You are receiving this mail because: ---
You are on the CC list for the bug.

___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l


[Bug 28962] ajax calls with '.' not working in IE

2011-06-22 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28962

Bug 28962 depends on bug 28840, which changed state.

Bug 28840 Summary: Loader broken in IE because mediawiki thinks the periods in 
module names is a security leak (spoof extension)
https://bugzilla.wikimedia.org/show_bug.cgi?id=28840

   What|Old Value   |New Value

 Status|REOPENED|RESOLVED
 Resolution||FIXED

-- 
Configure bugmail: https://bugzilla.wikimedia.org/userprefs.cgi?tab=email
--- You are receiving this mail because: ---
You are on the CC list for the bug.

___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l


[Bug 28962] ajax calls with '.' not working in IE

2011-06-07 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28962

Bug 28962 depends on bug 28840, which changed state.

Bug 28840 Summary: Loader broken in IE because mediawiki thinks the periods in 
module names is a security leak (spoof extension)
https://bugzilla.wikimedia.org/show_bug.cgi?id=28840

   What|Old Value   |New Value

 Status|REOPENED|RESOLVED
 Resolution||FIXED

-- 
Configure bugmail: https://bugzilla.wikimedia.org/userprefs.cgi?tab=email
--- You are receiving this mail because: ---
You are on the CC list for the bug.

___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l


[Bug 28962] ajax calls with '.' not working in IE

2011-05-27 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28962

Mark A. Hershberger m...@everybody.org changed:

   What|Removed |Added

   Keywords|triage  |

-- 
Configure bugmail: https://bugzilla.wikimedia.org/userprefs.cgi?tab=email
--- You are receiving this mail because: ---
You are on the CC list for the bug.

___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l


[Bug 28962] ajax calls with '.' not working in IE

2011-05-27 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28962

Bug 28962 depends on bug 28840, which changed state.

Bug 28840 Summary: Loader broken in IE because mediawiki thinks the periods in 
module names is a security leak (spoof extension)
https://bugzilla.wikimedia.org/show_bug.cgi?id=28840

   What|Old Value   |New Value

 Status|RESOLVED|REOPENED
 Resolution|FIXED   |

-- 
Configure bugmail: https://bugzilla.wikimedia.org/userprefs.cgi?tab=email
--- You are receiving this mail because: ---
You are on the CC list for the bug.

___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l


[Bug 28962] ajax calls with '.' not working in IE

2011-05-26 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28962

Bug 28962 depends on bug 28840, which changed state.

Bug 28840 Summary: Loader broken in IE because mediawiki thinks the periods in 
module names is a security leak (spoof extension)
https://bugzilla.wikimedia.org/show_bug.cgi?id=28840

   What|Old Value   |New Value

 Status|NEW |RESOLVED
 Resolution||FIXED

-- 
Configure bugmail: https://bugzilla.wikimedia.org/userprefs.cgi?tab=email
--- You are receiving this mail because: ---
You are on the CC list for the bug.

___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l


[Bug 28962] ajax calls with '.' not working in IE

2011-05-26 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28962

Mark A. Hershberger m...@everybody.org changed:

   What|Removed |Added

 Status|NEW |RESOLVED
 Resolution||DUPLICATE

--- Comment #7 from Mark A. Hershberger m...@everybody.org 2011-05-26 
18:54:42 UTC ---


*** This bug has been marked as a duplicate of bug 28840 ***

-- 
Configure bugmail: https://bugzilla.wikimedia.org/userprefs.cgi?tab=email
--- You are receiving this mail because: ---
You are on the CC list for the bug.

___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l


[Bug 28962] ajax calls with '.' not working in IE

2011-05-21 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28962

Krinkle krinklem...@gmail.com changed:

   What|Removed |Added

 CC||krinklem...@gmail.com,
   ||roan.katt...@gmail.com

--- Comment #4 from Krinkle krinklem...@gmail.com 2011-05-21 16:13:23 UTC ---
I think this was fixed by r87711 which was a fix for bug 28840.

CC-ing Roan/Catrope to confirm.

-- 
Configure bugmail: https://bugzilla.wikimedia.org/userprefs.cgi?tab=email
--- You are receiving this mail because: ---
You are on the CC list for the bug.

___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l


[Bug 28962] ajax calls with '.' not working in IE

2011-05-21 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28962

Bawolff bawolff...@gmail.com changed:

   What|Removed |Added

 Depends on||28840

--- Comment #5 from Bawolff bawolff...@gmail.com 2011-05-21 17:50:43 UTC ---
(In reply to comment #4)
 I think this was fixed by r87711 which was a fix for bug 28840.
 
 CC-ing Roan/Catrope to confirm.

No, it doesn't fix this.


I don't suppose there's some magic way to change how jQuery urlencodes ajax
parameters to force dots to be urlencoded (per comment 0)? In my testing, that
would fix much of these issues.

(btw, for reference the original security bug is bug 28235. I'm just writing
that here because bugzilla search is a pain and I always have trouble finding
it).

I'm also marking this depends on bug 28840, not sure if that's right, but the
two issues are highly related.

-- 
Configure bugmail: https://bugzilla.wikimedia.org/userprefs.cgi?tab=email
--- You are receiving this mail because: ---
You are on the CC list for the bug.

___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l


[Bug 28962] ajax calls with '.' not working in IE

2011-05-21 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28962

--- Comment #6 from Roan Kattouw roan.katt...@gmail.com 2011-05-21 19:17:06 
UTC ---
I have written a patch that will provide an easy workaround for these requests
and sent it to Tim (by private e-mail, because it's about a security issue) for
review.

-- 
Configure bugmail: https://bugzilla.wikimedia.org/userprefs.cgi?tab=email
--- You are receiving this mail because: ---
You are on the CC list for the bug.

___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l


[Bug 28962] ajax calls with '.' not working in IE

2011-05-20 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28962

duplicate...@googlemail.com changed:

   What|Removed |Added

   Severity|normal  |major

--- Comment #3 from duplicate...@googlemail.com 2011-05-20 20:46:43 UTC ---
Increase severity after one week.

-- 
Configure bugmail: https://bugzilla.wikimedia.org/userprefs.cgi?tab=email
--- You are receiving this mail because: ---
You are on the CC list for the bug.

___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l


[Bug 28962] ajax calls with '.' not working in IE

2011-05-13 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28962

Mark A. Hershberger m...@everybody.org changed:

   What|Removed |Added

   Keywords||triage
   Priority|Unprioritized   |Highest
 CC||m...@everybody.org
 Blocks||26676
 AssignedTo|wikibugs-l@lists.wikimedia. |tstarl...@wikimedia.org
   |org |

--- Comment #1 from Mark A. Hershberger m...@everybody.org 2011-05-13 
22:20:30 UTC ---
Assigning this to Tim, making it 1.17 blocker, and adding to triage so I can
make sure I am not insane.

-- 
Configure bugmail: https://bugzilla.wikimedia.org/userprefs.cgi?tab=email
--- You are receiving this mail because: ---
You are the assignee for the bug.
You are on the CC list for the bug.

___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l


[Bug 28962] ajax calls with '.' not working in IE

2011-05-13 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28962

Bawolff bawolff...@gmail.com changed:

   What|Removed |Added

 CC||bawolff...@gmail.com

--- Comment #2 from Bawolff bawolff...@gmail.com 2011-05-14 03:19:50 UTC ---
Perhaps someone with access to the logs could check to see how many 403
requests are returned due to the dot thing, just to see how widespread the
problem is.

-- 
Configure bugmail: https://bugzilla.wikimedia.org/userprefs.cgi?tab=email
--- You are receiving this mail because: ---
You are on the CC list for the bug.

___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l