https://bugzilla.wikimedia.org/show_bug.cgi?id=34541

       Web browser: ---
             Bug #: 34541
           Summary: File link-feature should not allow external links
           Product: MediaWiki
           Version: unspecified
          Platform: All
        OS/Version: All
            Status: NEW
          Severity: critical
          Priority: Unprioritized
         Component: Parser
        AssignedTo: [email protected]
        ReportedBy: [email protected]
    Classification: Unclassified
   Mobile Platform: ---


External links inside of files ([[File:...|link=http://...]]) have a high
potenital of abuse, as the link itself is only shown in the browser's
link-preview. If a transparent picture is used and positioned absolute, every
click on the whole page would lead to the possible malicious link.

This happened in dewiki today:
http://de.wikipedia.org/w/index.php?diff=prev&oldid=99889277 (Hidden by an
admin)

Additionally, in contrast to normal links, where the reader knows, that it is
an external link, most users of Wikipedia click on an image to get to the
description page and aren't expecting to end on an external page.

So in my opinion this feature should be removed. If you need an external link
on a file, it should be enough to put it in the caption.

-- 
Configure bugmail: https://bugzilla.wikimedia.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.
You are on the CC list for the bug.

_______________________________________________
Wikibugs-l mailing list
[email protected]
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l

Reply via email to