[Bug 61115] Drop URL parameter setlang

2014-03-22 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=61115

Nemo federicol...@tiscali.it changed:

   What|Removed |Added

 Status|REOPENED|RESOLVED
 Resolution|--- |WONTFIX

--- Comment #5 from Nemo federicol...@tiscali.it ---
(In reply to Fomafix from comment #4)
 setlang is a security risk. Here is a demonstrator for this risk:
 https://bugzilla.wikimedia.org/attachment.cgi?id=14788

Your attachment only proves that the security risk you claim is actually
standard behaviour: you have two inclusions there, one of a setlang call and
one of userlogout; if userlogout is acceptable, setlang is too.

-- 
You are receiving this mail because:
You are the assignee for the bug.
You are on the CC list for the bug.
___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l


[Bug 61115] Drop URL parameter setlang

2014-03-21 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=61115

Amir E. Aharoni amir.ahar...@mail.huji.ac.il changed:

   What|Removed |Added

 Status|UNCONFIRMED |RESOLVED
 Resolution|--- |WONTFIX

--- Comment #3 from Amir E. Aharoni amir.ahar...@mail.huji.ac.il ---
I find the setlang parameter useful and I don't see any convincing reason to
remove it. I don't consider its availability a problem. It is useful to force a
language using a parameter.

Replacing its use in some places, such as mw.uls.changeLanguage() can be
considered, but it should not be removed entirely.

-- 
You are receiving this mail because:
You are the assignee for the bug.
You are on the CC list for the bug.
___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l


[Bug 61115] Drop URL parameter setlang

2014-03-21 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=61115

Fomafix foma...@googlemail.com changed:

   What|Removed |Added

 Status|RESOLVED|REOPENED
 Resolution|WONTFIX |---
 Ever confirmed|0   |1

--- Comment #4 from Fomafix foma...@googlemail.com ---
(In reply to Amir E. Aharoni from comment #3)
 I find the setlang parameter useful and I don't see any convincing reason to
 remove it. I don't consider its availability a problem. It is useful to
 force a language using a parameter.

setlang is a security risk. Here is a demonstrator for this risk:
https://bugzilla.wikimedia.org/attachment.cgi?id=14788

uselang allows to force a language using a parameter without a risk.

(In reply to Amir E. Aharoni from comment #3)
 Replacing its use in some places, such as mw.uls.changeLanguage() can be
 considered, but it should not be removed entirely.

In https://gerrit.wikimedia.org/r/110360 is a implementation for
mw.uls.changeLanguage() with the same functionality without setlang. Other uses
of setlang can also changed on this way.

-- 
You are receiving this mail because:
You are the assignee for the bug.
You are on the CC list for the bug.
___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l


[Bug 61115] Drop URL parameter setlang

2014-03-07 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=61115

Nemo federicol...@tiscali.it changed:

   What|Removed |Added

 Status|NEW |UNCONFIRMED
 CC||federicol...@tiscali.it
 Ever confirmed|1   |0

-- 
You are receiving this mail because:
You are the assignee for the bug.
You are on the CC list for the bug.
___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l


[Bug 61115] Drop URL parameter setlang

2014-02-09 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=61115

Andre Klapper aklap...@wikimedia.org changed:

   What|Removed |Added

   Severity|normal  |enhancement

--- Comment #1 from Andre Klapper aklap...@wikimedia.org ---
(In reply to comment #0)
 2. On situations where no API call is possible use uselang instead of setlang
 and implement a popup to easily keep this language

I might misunderstand some technical details as I'm not part of language
engineering, but uselang and setlang feel like two different usecases to me.
I appreciate uselang to be able to quickly and one-time test a problem, using
values en or qqx, but I'd never want to set qqx as prefered language. ;)

-- 
You are receiving this mail because:
You are the assignee for the bug.
You are on the CC list for the bug.
___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l


[Bug 61115] Drop URL parameter setlang

2014-02-09 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=61115

--- Comment #2 from Fomafix foma...@googlemail.com ---
(In reply to comment #1)
 I appreciate uselang to be able to quickly and one-time test a problem,
 using
 values en or qqx, but I'd never want to set qqx as prefered language.

Languages that are now excluded for setlang like qqx should not present a popup
to easily keep this language as default language when given as uselang. So it
is not possible to set qqx as preferred language.

You can still use uselang for a quickly and one-time test and you can keep
this language as default language with a single click on the popup.

-- 
You are receiving this mail because:
You are the assignee for the bug.
You are on the CC list for the bug.
___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l