Mark A. Hershberger wrote:
> 23126   Locked and hidden accounts can unify new local accounts
>         https://bugzilla.wikimedia.org/23126
>             Tim says this is apparently a deliberate chage, and later
>             comments leave me confused: should this be closed or the fix
>             for this bug reverted?

Now creation logs are not shown for autocreated accounts, which is what
comment 11 complains about, so it may be fixed. I would open a new bug
if locked accounts can use Special:EmailUser.


> 19161   Auto account creation creates privacy vulnerability
>         https://bugzilla.wikimedia.org/19161
>             I think this one is fixed but I'm relying on you to help me
>             determine what, if anything, still needs to happen.  This is
>             refered to in #23126 as well.

This is currently fixed as the account creation does not appear in the
logs (although smart users could still find the log), and the ability of
disabling global login.
However, it's not clear if those measures will be undone.

These are very linked with bug 27287, which requests to have creation
logs again, and could reopen them.
https://bugzilla.wikimedia.org/show_bug.cgi?id=27287

Perhaps the account creation log should perform an union of local tables
and centralauth ones.


_______________________________________________
Wikitech-l mailing list
Wikitech-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikitech-l

Reply via email to