https://bugzilla.wikimedia.org/show_bug.cgi?id=33392

       Web browser: ---
             Bug #: 33392
           Summary: Users without abusefilter-modify-restricted can remove
                    restricted actions
           Product: MediaWiki extensions
           Version: any
          Platform: All
        OS/Version: All
            Status: NEW
          Severity: normal
          Priority: Unprioritized
         Component: AbuseFilter
        AssignedTo: [email protected]
        ReportedBy: [email protected]
                CC: [email protected]
    Classification: Unclassified


Created attachment 9770
  --> https://bugzilla.wikimedia.org/attachment.cgi?id=9770
Proposed patch

Users who do not have abusefilter-modify-restricted can remove all the
restricted actions from a filter, and then they'll be able to modify it. The
code only checks if the new version that's about to be saved has restricted
actions, which prevents unprivileged users from adding them, but not removing
them. I've attached a patch that also checks if the previous version of the
filter had restricted actions.

-- 
Configure bugmail: https://bugzilla.wikimedia.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.
You are on the CC list for the bug.

_______________________________________________
Wikibugs-l mailing list
[email protected]
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l

Reply via email to