https://bugzilla.wikimedia.org/show_bug.cgi?id=42816

       Web browser: ---
            Bug ID: 42816
           Summary: Abusefilter API does not check whether a user is
                    blocked
           Product: MediaWiki extensions
           Version: unspecified
          Hardware: All
                OS: All
            Status: NEW
          Severity: major
          Priority: Unprioritized
         Component: AbuseFilter
          Assignee: [email protected]
          Reporter: [email protected]
                CC: [email protected], [email protected]
    Classification: Unclassified
   Mobile Platform: ---

Somewhat related to bug 42814, but a bit different.

Blocked users are not able to see
https://en.wikipedia.org/w/index.php?title=Special:AbuseLog&wpSearchFilter=3,
they simply see the standard block message.

However they can still see
https://en.wikipedia.org/w/api.php?action=query&list=abuselog&aflfilter=3,
which provides nearly the same information.

I'm marking this as major, because like the other bug, is providing information
to users who should not be able to see it.

-- 
You are receiving this mail because:
You are the assignee for the bug.
You are watching all bug changes.
_______________________________________________
Wikibugs-l mailing list
[email protected]
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l

Reply via email to