[Wikidata-bugs] [Maniphest] [Claimed] T249039: Security Readiness Review For Wikidata Bridge

2020-05-08 Thread sbassett
sbassett claimed this task. sbassett moved this task from Back Orders to Waiting on the secscrum board. sbassett added a project: user-sbassett. TASK DETAIL https://phabricator.wikimedia.org/T249039 WORKBOARD https://phabricator.wikimedia.org/project/board/4630/ EMAIL PREFERENCES https

[Wikidata-bugs] [Maniphest] [Commented On] T249039: Security Readiness Review For Wikidata Bridge

2020-05-08 Thread sbassett
sbassett added a comment. @darthmon_wmde - we don't currently have this review assigned/scheduled, though I could probably have a look at it next week. Before we do that, I think we'd need: 1. Confirmed commit shas for the various code bases and files defined within sections one

[Wikidata-bugs] [Maniphest] [Commented On] T251834: PrivateSettings: PHP Notice: Undefined offset: 1

2020-05-04 Thread sbassett
sbassett added a comment. This was caused by this security patch to PS.php <https://phabricator.wikimedia.org/T250887#6102375>. Which was reverted and re-synced <https://sal.toolforge.org/log/0F-m4XEBj_Bg1xd3x-G7>. An updated version <https://phabricator.wikimedia.o

[Wikidata-bugs] [Maniphest] [Triaged] T249039: Security Readiness Review For Wikidata Bridge

2020-04-06 Thread sbassett
sbassett moved this task from Incoming to Back Orders on the secscrum board. sbassett triaged this task as "Low" priority. TASK DETAIL https://phabricator.wikimedia.org/T249039 WORKBOARD https://phabricator.wikimedia.org/project/board/4630/ EMAIL PREFERENC

[Wikidata-bugs] [Maniphest] [Commented On] T241536: Remove the use of chronology_id in wdqs-updater

2020-02-06 Thread sbassett
sbassett added a comment. I've made this task public now that T241410 should be completely resolved with all data flushed (and hopefully able to become public soon itself). TASK DETAIL https://phabricator.wikimedia.org/T241536 EMAIL PREFERENCES https://phabricator.wikimedia.org/settings

[Wikidata-bugs] [Maniphest] [Changed Policy] T241536: Remove the use of chronology_id in wdqs-updater

2020-02-06 Thread sbassett
sbassett changed the visibility from "Custom Policy" to "Public (No Login Required)". TASK DETAIL https://phabricator.wikimedia.org/T241536 EMAIL PREFERENCES https://phabricator.wikimedia.org/settings/panel/emailpreferences/ To: sbassett Cc: Addshore, sbassett, Zby

[Wikidata-bugs] [Maniphest] [Changed Subscribers] T240884: Standalone service to evaluate user-provided regular expressions

2020-01-16 Thread sbassett
sbassett added a subscriber: Daimona. sbassett added a comment. In T240884#5810094 <https://phabricator.wikimedia.org/T240884#5810094>, @Ladsgroup wrote: > One complicating factor here is that AbuseFilter and SpamBlacklist both don't have a clear maintainer. I think

[Wikidata-bugs] [Maniphest] [Updated] T237667: PHP Warning: preg_match(): Unknown modifier 'p' (from MwTimeIsoParser.php, API action=wbparsevalue) [8 story points]

2019-12-26 Thread sbassett
sbassett removed a project: Patch-For-Review. sbassett moved this task from External (Non-WMF) Issues to Done on the Security board. TASK DETAIL https://phabricator.wikimedia.org/T237667 WORKBOARD https://phabricator.wikimedia.org/project/board/30/ EMAIL PREFERENCES https

[Wikidata-bugs] [Maniphest] [Updated] T237667: PHP Warning: preg_match(): Unknown modifier 'p' (from MwTimeIsoParser.php, API action=wbparsevalue) [8 story points]

2019-12-10 Thread sbassett
sbassett added a comment. In T237667#5728294 <https://phabricator.wikimedia.org/T237667#5728294>, @Ladsgroup wrote: > Sorry, When I made the patch to gerrit it made sense to open the ticket so the bots can add the patch to this ticket, when the patch is in gerrit, this can

[Wikidata-bugs] [Maniphest] [Updated] T233213: XSS in Wikidata Query Service UI, DATATYPE_MATHML - CVE-2019-19329

2019-12-02 Thread sbassett
sbassett removed a project: Patch-For-Review. sbassett moved this task from Backlog / Other to Done on the Security board. TASK DETAIL https://phabricator.wikimedia.org/T233213 WORKBOARD https://phabricator.wikimedia.org/project/board/30/ EMAIL PREFERENCES https

[Wikidata-bugs] [Maniphest] [Changed Policy] T233213: XSS in Wikidata Query Service UI

2019-11-12 Thread sbassett
sbassett changed the visibility from "Custom Policy" to "Public (No Login Required)". TASK DETAIL https://phabricator.wikimedia.org/T233213 EMAIL PREFERENCES https://phabricator.wikimedia.org/settings/panel/emailpreferences/ To: sbassett Cc: Tarrow, hoo, Jakob_WMDE,

[Wikidata-bugs] [Maniphest] [Commented On] T236500: large number of 504 errors from ulsfo

2019-10-28 Thread sbassett
sbassett added a comment. In T236500#5609046 <https://phabricator.wikimedia.org/T236500#5609046>, @Bugreporter wrote: > @jijiki The Custom Policy does not make sense since #Traffic <https://phabricator.wikimedia.org/tag/traffic/> is currently a public-joinable pro

[Wikidata-bugs] [Maniphest] [Updated] T130856: query.wikidata.org is making requests to http://themes.googleusercontent.com

2019-10-16 Thread sbassett
sbassett removed a project: Patch-For-Review. TASK DETAIL https://phabricator.wikimedia.org/T130856 EMAIL PREFERENCES https://phabricator.wikimedia.org/settings/panel/emailpreferences/ To: JanZerebecki, sbassett Cc: Gehel, Smalyshev, gerritbot, csteipp, Bovlb, Jonas, Aklapper

[Wikidata-bugs] [Maniphest] [Updated] T124451: Don't make edits if a logged in user gets logged out

2019-10-16 Thread sbassett
sbassett removed a project: Patch-For-Review. TASK DETAIL https://phabricator.wikimedia.org/T124451 EMAIL PREFERENCES https://phabricator.wikimedia.org/settings/panel/emailpreferences/ To: Tarrow, sbassett Cc: gerritbot, Lucas_Werkmeister_WMDE, Addshore, thiemowmde, adrianheine, TerraCodes

[Wikidata-bugs] [Maniphest] [Triaged] T150803: Information leak on wikidata-externalid-url

2019-10-16 Thread sbassett
sbassett triaged this task as "Normal" priority. sbassett removed a project: Cloud-Services. TASK DETAIL https://phabricator.wikimedia.org/T150803 EMAIL PREFERENCES https://phabricator.wikimedia.org/settings/panel/emailpreferences/ To: sbassett Cc: Esc3300, Sjoerddebruin, Multichi

[Wikidata-bugs] [Maniphest] [Triaged] T197777: potential issues with planned release of query logs (Wikidata Query Server)

2019-10-16 Thread sbassett
sbassett triaged this task as "Normal" priority. TASK DETAIL https://phabricator.wikimedia.org/T19 EMAIL PREFERENCES https://phabricator.wikimedia.org/settings/panel/emailpreferences/ To: Smalyshev, sbassett Cc: Krenair, Bawolff, Lydia_Pintscher, APalmer_WMF, Smalysh

[Wikidata-bugs] [Maniphest] [Triaged] T202389: Add phan-taint-check-plugin to Wikibase extension

2019-10-15 Thread sbassett
sbassett triaged this task as "Normal" priority. TASK DETAIL https://phabricator.wikimedia.org/T202389 EMAIL PREFERENCES https://phabricator.wikimedia.org/settings/panel/emailpreferences/ To: Legoktm, sbassett Cc: Legoktm, gerritbot, Aklapper, Umherirrender, darthmon_wmde,

[Wikidata-bugs] [Maniphest] [Triaged] T202390: Add phan-taint-check-plugin to WikibaseLexeme extension

2019-10-15 Thread sbassett
sbassett triaged this task as "Normal" priority. TASK DETAIL https://phabricator.wikimedia.org/T202390 EMAIL PREFERENCES https://phabricator.wikimedia.org/settings/panel/emailpreferences/ To: Legoktm, sbassett Cc: gerritbot, Umherirrender, darthmon_wmde, DannyS712, Nandana

[Wikidata-bugs] [Maniphest] [Commented On] T214378: Check simple format constraints (no grouping) in PHP instead of SPARQL

2019-10-04 Thread sbassett
sbassett added a comment. @RazShuty @Addshore @Lucas_Werkmeister_WMDE - Sorry for the (very) delayed response here. Due to a healthy amount of organizational shift, the #security-team <https://phabricator.wikimedia.org/tag/security-team/> is just now getting our Phab works boards in

[Wikidata-bugs] [Maniphest] [Changed Status] T208329: Gadget with SPARQL services and the Content Security Policy ?

2019-10-04 Thread sbassett
sbassett changed the task status from "Open" to "Stalled". sbassett triaged this task as "Normal" priority. sbassett moved this task from Backlog to Waiting on the Security-Team board. TASK DETAIL https://phabricator.wikimedia.org/T208329 WORKBOARD https://pha

[Wikidata-bugs] [Maniphest] [Updated] T216692: Security review for WikibaseSchema

2019-04-24 Thread sbassett
sbassett edited projects, added Security-Team-Reviews; removed Security-Team-Review-Active. TASK DETAIL https://phabricator.wikimedia.org/T216692 EMAIL PREFERENCES https://phabricator.wikimedia.org/settings/panel/emailpreferences/ To: Reedy, sbassett Cc: Tarrow, Aklapper, RazShuty, WMDE

[Wikidata-bugs] [Maniphest] [Updated] T216692: Security review for WikibaseSchema

2019-02-21 Thread sbassett
sbassett edited projects, added Security-Team-Reviews; removed Security. TASK DETAIL https://phabricator.wikimedia.org/T216692 EMAIL PREFERENCES https://phabricator.wikimedia.org/settings/panel/emailpreferences/ To: sbassett Cc: Aklapper, RazShuty, WMDE-leszek, Michael, noarave

[Wikidata-bugs] [Maniphest] [Commented On] T204542: Security review for the Wikidata primary sources tool MediaWiki extension

2019-01-23 Thread sbassett
sbassett added a comment. @Hjfocs - But you served as the first reviewer, what am I getting wrong? From T196073#4825203, it looks like @MaxSem found the PrimarySources code as an unmerged gerrit patch set, and offered some initial feedback (thanks!) However, this isn't typical of a standard

[Wikidata-bugs] [Maniphest] [Commented On] T204542: Security review for the Wikidata primary sources tool MediaWiki extension

2019-01-15 Thread sbassett
sbassett added a comment. Hello @Hjfocs Some follow-up here - apologies for the stop/go on this one: Did the mirroring issue with gerrit ever get addressed? It still looks to be an empty repo. I was curious if the tool is actually working in production. On wikidata.org, I added the gadget

[Wikidata-bugs] [Maniphest] [Edited] T204542: Security review for the Wikidata primary sources tool MediaWiki extension

2018-12-14 Thread sbassett
sbassett updated the task description. (Show Details) CHANGES TO TASK DESCRIPTION...* Target date for deployment: N.A. (the related [[https://meta.wikimedia.org/wiki/Grants:IEG/StrepHit:_Wikidata_Statements_Validation_via_References/Renewal/Timeline | project grant]] is over anyway)this code

[Wikidata-bugs] [Maniphest] [Commented On] T204542: Security review for the Wikidata primary sources tool MediaWiki extension

2018-12-14 Thread sbassett
sbassett added a comment. Ok, thanks for the update, @Hjfocs.TASK DETAILhttps://phabricator.wikimedia.org/T204542EMAIL PREFERENCEShttps://phabricator.wikimedia.org/settings/panel/emailpreferences/To: sbassettCc: sbassett, Aklapper, Hjfocs, Nandana, Lahi, Gq86, GoranSMilovanovic, Kiailandi, QZanden

[Wikidata-bugs] [Maniphest] [Triaged] T204542: Security review for the Wikidata primary sources tool MediaWiki extension

2018-12-14 Thread sbassett
sbassett triaged this task as "Low" priority. TASK DETAILhttps://phabricator.wikimedia.org/T204542EMAIL PREFERENCEShttps://phabricator.wikimedia.org/settings/panel/emailpreferences/To: sbassettCc: sbassett, Aklapper, Hjfocs, Nandana, Lahi, Gq86, GoranSMilovanovic, Kiailandi, QZand

[Wikidata-bugs] [Maniphest] [Commented On] T204542: Security review for the Wikidata primary sources tool MediaWiki extension

2018-12-12 Thread sbassett
sbassett added a comment. Not seeing anything in master or REL1_32 for this. Is it somewhere else? If not, is there an estimate for completion?TASK DETAILhttps://phabricator.wikimedia.org/T204542EMAIL PREFERENCEShttps://phabricator.wikimedia.org/settings/panel/emailpreferences/To: sbassettCc

<    1   2