[Bug 28840] Loader broken in IE because mediawiki thinks the periods in module names is a security leak (spoof extension)

2011-06-22 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28840 Mark A. Hershberger m...@everybody.org changed: What|Removed |Added CC|

[Bug 28840] Loader broken in IE because mediawiki thinks the periods in module names is a security leak (spoof extension)

2011-06-22 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28840 Mark A. Hershberger m...@everybody.org changed: What|Removed |Added Status|RESOLVED|REOPENED

[Bug 28840] Loader broken in IE because mediawiki thinks the periods in module names is a security leak (spoof extension)

2011-06-22 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28840 --- Comment #46 from p858snake p858sn...@gmail.com 2011-06-22 22:43:54 UTC --- Mark: Please explain why you reopened this bug. -- Configure bugmail: https://bugzilla.wikimedia.org/userprefs.cgi?tab=email --- You are receiving this mail

[Bug 28840] Loader broken in IE because mediawiki thinks the periods in module names is a security leak (spoof extension)

2011-06-22 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28840 Tim Starling tstarl...@wikimedia.org changed: What|Removed |Added Status|REOPENED|RESOLVED

[Bug 28840] Loader broken in IE because mediawiki thinks the periods in module names is a security leak (spoof extension)

2011-06-07 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28840 Roan Kattouw roan.katt...@gmail.com changed: What|Removed |Added Status|REOPENED|RESOLVED

[Bug 28840] Loader broken in IE because mediawiki thinks the periods in module names is a security leak (spoof extension)

2011-06-06 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28840 Krinkle krinklem...@gmail.com changed: What|Removed |Added CC||krinklem...@gmail.com

[Bug 28840] Loader broken in IE because mediawiki thinks the periods in module names is a security leak (spoof extension)

2011-06-06 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28840 --- Comment #41 from Paul Oranje p.ora...@xs4all.nl 2011-06-06 17:16:25 UTC --- Shouldn't r89397 be tagged with 1.17, 1.17wmf1? OT: When do (ports of) these revisions land on the 1.17 branch? -- Configure bugmail:

[Bug 28840] Loader broken in IE because mediawiki thinks the periods in module names is a security leak (spoof extension)

2011-06-06 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28840 --- Comment #42 from Roan Kattouw roan.katt...@gmail.com 2011-06-06 17:42:50 UTC --- (In reply to comment #41) Shouldn't r89397 be tagged with 1.17, 1.17wmf1? It will be once I review it. OT: When do (ports of) these revisions land on the

[Bug 28840] Loader broken in IE because mediawiki thinks the periods in module names is a security leak (spoof extension)

2011-06-06 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28840 --- Comment #43 from Mark A. Hershberger m...@everybody.org 2011-06-07 02:11:41 UTC --- (In reply to comment #40) Can this ticket be closed now or is there still something pending ? Roan can close it once he has reviewed the patch. This is

[Bug 28840] Loader broken in IE because mediawiki thinks the periods in module names is a security leak (spoof extension)

2011-06-02 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28840 Rob Lanphier ro...@wikimedia.org changed: What|Removed |Added CC||ro...@wikimedia.org

[Bug 28840] Loader broken in IE because mediawiki thinks the periods in module names is a security leak (spoof extension)

2011-06-02 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28840 --- Comment #39 from Tim Starling tstarl...@wikimedia.org 2011-06-03 05:49:19 UTC --- (In reply to comment #37) One possible way to make it break less things would be to have it redirect to a safe equivalent of the same URL, instead of

[Bug 28840] Loader broken in IE because mediawiki thinks the periods in module names is a security leak (spoof extension)

2011-05-31 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28840 --- Comment #34 from Derk-Jan Hartman hart...@videolan.org 2011-05-31 12:35:20 UTC --- Well brion and I myself experienced issues after r3 it seems. At least I had my trunk up to date, and I doubt that brion wasn't using up to date trunk.

[Bug 28840] Loader broken in IE because mediawiki thinks the periods in module names is a security leak (spoof extension)

2011-05-31 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28840 --- Comment #35 from Derk-Jan Hartman hart...@videolan.org 2011-05-31 12:36:09 UTC --- (In reply to comment #34) Well brion and I myself experienced issues after r3 it seems. At least I had my trunk up to date, and I doubt that brion

[Bug 28840] Loader broken in IE because mediawiki thinks the periods in module names is a security leak (spoof extension)

2011-05-31 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28840 --- Comment #36 from Tim Starling tstarl...@wikimedia.org 2011-05-31 23:56:34 UTC --- We can fix a few more special cases, but there's not going to be a solution for this that can allow any arbitrary api.php or action=raw request. --

[Bug 28840] Loader broken in IE because mediawiki thinks the periods in module names is a security leak (spoof extension)

2011-05-31 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28840 Krinkle krinklem...@gmail.com changed: What|Removed |Added CC||tpars...@wikimedia.org

[Bug 28840] Loader broken in IE because mediawiki thinks the periods in module names is a security leak (spoof extension)

2011-05-31 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28840 --- Comment #37 from Tim Starling tstarl...@wikimedia.org 2011-06-01 02:56:16 UTC --- It should be somewhat better as of r89249. It should mostly only block requests that have dots in the last parameter of the query string now. One possible

[Bug 28840] Loader broken in IE because mediawiki thinks the periods in module names is a security leak (spoof extension)

2011-05-31 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28840 Michael Dale d...@ucsc.edu changed: What|Removed |Added CC||d...@ucsc.edu --- Comment

[Bug 28840] Loader broken in IE because mediawiki thinks the periods in module names is a security leak (spoof extension)

2011-05-30 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28840 --- Comment #33 from Tim Starling tstarl...@wikimedia.org 2011-05-31 00:37:44 UTC --- It should be fixed as of r3, to be released soon. -- Configure bugmail: https://bugzilla.wikimedia.org/userprefs.cgi?tab=email --- You are

[Bug 28840] Loader broken in IE because mediawiki thinks the periods in module names is a security leak (spoof extension)

2011-05-29 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28840 Derk-Jan Hartman hart...@videolan.org changed: What|Removed |Added CC|

[Bug 28840] Loader broken in IE because mediawiki thinks the periods in module names is a security leak (spoof extension)

2011-05-27 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28840 Mark A. Hershberger m...@everybody.org changed: What|Removed |Added Keywords|need-review |reviewed --

[Bug 28840] Loader broken in IE because mediawiki thinks the periods in module names is a security leak (spoof extension)

2011-05-27 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28840 Brion Vibber br...@wikimedia.org changed: What|Removed |Added Status|RESOLVED|REOPENED

[Bug 28840] Loader broken in IE because mediawiki thinks the periods in module names is a security leak (spoof extension)

2011-05-27 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28840 --- Comment #29 from Brion Vibber br...@wikimedia.org 2011-05-27 21:29:38 UTC --- I also see this for some things still using legacy action=raw to load site css pages, such as [[MediaWiki:Filepage.css]] being loaded by ImagePage:

[Bug 28840] Loader broken in IE because mediawiki thinks the periods in module names is a security leak (spoof extension)

2011-05-27 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28840 --- Comment #30 from Brion Vibber br...@wikimedia.org 2011-05-27 21:32:13 UTC --- And... also for perfectly legit API hits!

[Bug 28840] Loader broken in IE because mediawiki thinks the periods in module names is a security leak (spoof extension)

2011-05-27 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28840 Brion Vibber br...@wikimedia.org changed: What|Removed |Added Blocks||21587 -- Configure

[Bug 28840] Loader broken in IE because mediawiki thinks the periods in module names is a security leak (spoof extension)

2011-05-27 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28840 Brion Vibber br...@wikimedia.org changed: What|Removed |Added Blocks|21587 | -- Configure

[Bug 28840] Loader broken in IE because mediawiki thinks the periods in module names is a security leak (spoof extension)

2011-05-27 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28840 Brion Vibber br...@wikimedia.org changed: What|Removed |Added Blocks||29177 -- Configure

[Bug 28840] Loader broken in IE because mediawiki thinks the periods in module names is a security leak (spoof extension)

2011-05-27 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28840 Brion Vibber br...@wikimedia.org changed: What|Removed |Added Blocks|29177 |27699 --- Comment

[Bug 28840] Loader broken in IE because mediawiki thinks the periods in module names is a security leak (spoof extension)

2011-05-26 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28840 Roan Kattouw roan.katt...@gmail.com changed: What|Removed |Added Status|NEW |RESOLVED

[Bug 28840] Loader broken in IE because mediawiki thinks the periods in module names is a security leak (spoof extension)

2011-05-26 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28840 --- Comment #25 from Mark A. Hershberger m...@everybody.org 2011-05-26 18:54:42 UTC --- *** Bug 28962 has been marked as a duplicate of this bug. *** -- Configure bugmail: https://bugzilla.wikimedia.org/userprefs.cgi?tab=email --- You

[Bug 28840] Loader broken in IE because mediawiki thinks the periods in module names is a security leak (spoof extension)

2011-05-26 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28840 Roan Kattouw roan.katt...@gmail.com changed: What|Removed |Added CC|

[Bug 28840] Loader broken in IE because mediawiki thinks the periods in module names is a security leak (spoof extension)

2011-05-26 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28840 --- Comment #27 from Paul Oranje p.ora...@xs4all.nl 2011-05-26 21:52:36 UTC --- Will the patch be applied onto branches/REL1_17 (and when) so that the fix can be got with svn update? -- Configure bugmail:

[Bug 28840] Loader broken in IE because mediawiki thinks the periods in module names is a security leak (spoof extension)

2011-05-21 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28840 Krinkle krinklem...@gmail.com changed: What|Removed |Added Summary|Diffs not displaying|Loader broken in IE

[Bug 28840] Loader broken in IE because mediawiki thinks the periods in module names is a security leak (spoof extension)

2011-05-21 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28840 Bawolff bawolff...@gmail.com changed: What|Removed |Added Blocks||28962 -- Configure