https://bugzilla.wikimedia.org/show_bug.cgi?id=28840

--- Comment #37 from Tim Starling <tstarl...@wikimedia.org> 2011-06-01 02:56:16 
UTC ---
It should be somewhat better as of r89249. It should mostly only block requests
that have dots in the last parameter of the query string now. 

One possible way to make it break less things would be to have it redirect to a
safe equivalent of the same URL, instead of showing an error page. It wouldn't
help with POST requests that have some parameters in the URL, and it wouldn't
help with API clients that don't understand redirects, but at least it would
fix any JavaScript client issues. What do you think?

-- 
Configure bugmail: https://bugzilla.wikimedia.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.
You are on the CC list for the bug.

_______________________________________________
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l

Reply via email to