https://bugzilla.wikimedia.org/show_bug.cgi?id=60616

       Web browser: ---
            Bug ID: 60616
           Summary: Annotations from anonymous users can't be
                    edited/deleted
           Product: MediaWiki extensions
           Version: unspecified
          Hardware: All
                OS: All
            Status: UNCONFIRMED
          Severity: normal
          Priority: Unprioritized
         Component: Annotator
          Assignee: wikibugs-l@lists.wikimedia.org
          Reporter: gabriel.bi...@tib.uni-hannover.de
                CC: mflasc...@wikimedia.org, richa.jain1...@gmail.com,
                    tylerro...@gmail.com
    Classification: Unclassified
   Mobile Platform: ---

Annotations from anonymous users are stored with user id 0. However, the code
for updating/deleting annotations checks for user id identity so even logged in
users can only edit their own comments. This could result in undeleteable,
uneditable  offensive comments all over the wiki.

My proposal for this would be new permissions named "updateannotation" and
"deleteannotation" assigned to the sysop user by default. These permissions
would allow to bypass the "only update/delete your own annotation" restriction.

-- 
You are receiving this mail because:
You are the assignee for the bug.
You are on the CC list for the bug.
_______________________________________________
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l

Reply via email to