[Bug 60534] Installer should write LocalSettings.php itself when it's able to

2014-02-28 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=60534

Andre Klapper aklap...@wikimedia.org changed:

   What|Removed |Added

   Keywords|patch, patch-need-review|

-- 
You are receiving this mail because:
You are the assignee for the bug.
You are on the CC list for the bug.
___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l


[Bug 60534] Installer should write LocalSettings.php itself when it's able to

2014-02-25 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=60534

--- Comment #9 from Tyler Romeo tylerro...@gmail.com ---
(In reply to Mayank from comment #8)
 Thanks for pointing this out! Can we have a workaround say something which
 allows you to change the server writing permissions just for copying the
 LocalSettings.php and afterwards making it read-only ? Can this be done ?

I mean, that doesn't really solve the problem. The best possible thing we can
do is maybe write LocalSettings.php to a temporary directory, and then tell the
user to copy it over to the web root.

-- 
You are receiving this mail because:
You are the assignee for the bug.
You are on the CC list for the bug.
___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l


[Bug 60534] Installer should write LocalSettings.php itself when it's able to

2014-02-25 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=60534

--- Comment #10 from Jackmcbarn jackmcbarn+w...@gmail.com ---
The way this is coded now, wouldn't it go completely unnoticed for users who
don't have the directory writable? For users that already do, mainly MediaWiki
developers (via XAMPP, etc.), it would be a convenience, and security wouldn't
be a worry for them, since their installations don't tend to be public-facing.

-- 
You are receiving this mail because:
You are the assignee for the bug.
You are on the CC list for the bug.
___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l


[Bug 60534] Installer should write LocalSettings.php itself when it's able to

2014-02-24 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=60534

--- Comment #6 from Gerrit Notification Bot gerritad...@wikimedia.org ---
Change 114966 had a related patch set uploaded by Nemo bis:
Automatically copy the LocalSettings.php file to the desired location

https://gerrit.wikimedia.org/r/114966

-- 
You are receiving this mail because:
You are the assignee for the bug.
You are on the CC list for the bug.
___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l


[Bug 60534] Installer should write LocalSettings.php itself when it's able to

2014-02-24 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=60534

Tyler Romeo tylerro...@gmail.com changed:

   What|Removed |Added

 CC||tylerro...@gmail.com

--- Comment #7 from Tyler Romeo tylerro...@gmail.com ---
(In reply to Jackmcbarn from comment #0)
 Unless there's a reason not to

The directory where MediaWiki is installed should not be writeable by the web
server. That's considered a security vulnerability since then the source code
of MediaWiki can be changed via the web interface if there is an exploit.
Generally the installation directory should be read-only to the web server.

Downloading LocalSettings.php rather than writing it is to encourage the idea
that you must SSH into your server in order to change files. The other side of
the argument is that when downloading LocalSettings.php you are transmitting
the database password over plaintext, but assuming you already entered your
database password on the installer form that is kind of a moot issue.

-- 
You are receiving this mail because:
You are the assignee for the bug.
You are on the CC list for the bug.
___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l


[Bug 60534] Installer should write LocalSettings.php itself when it's able to

2014-02-24 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=60534

--- Comment #8 from Mayank mayank25080...@gmail.com ---
(In reply to Tyler Romeo from comment #7)
 (In reply to Jackmcbarn from comment #0)
  Unless there's a reason not to
 
 The directory where MediaWiki is installed should not be writeable by the
 web server. That's considered a security vulnerability since then the source
 code of MediaWiki can be changed via the web interface if there is an
 exploit. Generally the installation directory should be read-only to the web
 server.
 
 Downloading LocalSettings.php rather than writing it is to encourage the
 idea that you must SSH into your server in order to change files. The other
 side of the argument is that when downloading LocalSettings.php you are
 transmitting the database password over plaintext, but assuming you already
 entered your database password on the installer form that is kind of a moot
 issue.

Thanks for pointing this out! Can we have a workaround say something which
allows you to change the server writing permissions just for copying the
LocalSettings.php and afterwards making it read-only ? Can this be done ?

-- 
You are receiving this mail because:
You are the assignee for the bug.
You are on the CC list for the bug.
___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l


[Bug 60534] Installer should write LocalSettings.php itself when it's able to

2014-02-23 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=60534

Gerrit Notification Bot gerritad...@wikimedia.org changed:

   What|Removed |Added

 Status|NEW |PATCH_TO_REVIEW

-- 
You are receiving this mail because:
You are the assignee for the bug.
You are on the CC list for the bug.
___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l


[Bug 60534] Installer should write LocalSettings.php itself when it's able to

2014-02-23 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=60534

--- Comment #5 from Gerrit Notification Bot gerritad...@wikimedia.org ---
Change 114966 had a related patch set uploaded by Mjnovice:
Automatically copies the LocalSettings.php file to the desired location, fixes
bug 60534.

https://gerrit.wikimedia.org/r/114966

-- 
You are receiving this mail because:
You are the assignee for the bug.
You are on the CC list for the bug.
___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l


[Bug 60534] Installer should write LocalSettings.php itself when it's able to

2014-02-14 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=60534

Andre Klapper aklap...@wikimedia.org changed:

   What|Removed |Added

   Keywords||patch, patch-need-review
 CC||aklap...@wikimedia.org

--- Comment #4 from Andre Klapper aklap...@wikimedia.org ---
Hi Mayank! Thanks for your patch!

You are welcome to use Developer access
  https://www.mediawiki.org/wiki/Developer_access
to submit this as a Git branch directly into Gerrit:
  https://www.mediawiki.org/wiki/Git/Tutorial

Putting your branch in Git makes it easier to review it quickly. If you don't
want to set up Git/Gerrit, you can also use
https://tools.wmflabs.org/gerrit-patch-uploader/

-- 
You are receiving this mail because:
You are the assignee for the bug.
You are on the CC list for the bug.
___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l


[Bug 60534] Installer should write LocalSettings.php itself when it's able to

2014-02-13 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=60534

--- Comment #3 from Mayank mayank25080...@gmail.com ---
Created attachment 14583
  -- https://bugzilla.wikimedia.org/attachment.cgi?id=14583action=edit
This copies the LocalSettings.php file automatically.

In addition to copying the file to the desired location, it also gives an
option to download the file in case the copying does not take place due to any
reasons whatsoever!

-- 
You are receiving this mail because:
You are the assignee for the bug.
You are on the CC list for the bug.
___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l


[Bug 60534] Installer should write LocalSettings.php itself when it's able to

2014-02-12 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=60534

--- Comment #2 from Jackmcbarn jackmcbarn+w...@gmail.com ---
Right.

-- 
You are receiving this mail because:
You are the assignee for the bug.
You are on the CC list for the bug.
___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l


[Bug 60534] Installer should write LocalSettings.php itself when it's able to

2014-02-11 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=60534

Mayank mayank25080...@gmail.com changed:

   What|Removed |Added

 CC||mayank25080...@gmail.com

--- Comment #1 from Mayank mayank25080...@gmail.com ---
If I am not wrong, then you are saying that the file should be created and
saved automatically instead of us, copying and pasting it from the downloads to
your http://localhost, right ?

-- 
You are receiving this mail because:
You are the assignee for the bug.
You are on the CC list for the bug.
___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l


[Bug 60534] Installer should write LocalSettings.php itself when it's able to

2014-01-28 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=60534

Andre Klapper aklap...@wikimedia.org changed:

   What|Removed |Added

   Priority|Unprioritized   |Low
Version|unspecified |1.23-git

-- 
You are receiving this mail because:
You are the assignee for the bug.
You are on the CC list for the bug.
___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l