Page MenuHomePhabricator

RhinosF1 (Samuel)
Volunteer Configurator

Today

  • Clear sailing ahead.

Tomorrow

  • Clear sailing ahead.

Saturday

  • Clear sailing ahead.

User Details

User Since
Dec 27 2018, 1:42 PM (344 w, 6 d)
Availability
Available
IRC Nick
RhinosF1
LDAP User
RhinosF1
MediaWiki User
RhinosF1 [ Global Accounts ]

See meta.wikimedia.org/wiki/User:RhinosF1

A list of valid alts is at https://meta.wikimedia.org/wiki/User:RhinosF1/Alts

Recent Activity

Wed, Jul 9

RhinosF1 updated the task description for T399132: Add security reports from 1.39.13/1.42.7/1.43.2/1.44.0 (+ extension supplement) to security hall of fame.
Wed, Jul 9, 8:57 PM · SecTeam-Processed, affects-Miraheze, Security-Team
RhinosF1 updated the task description for T399132: Add security reports from 1.39.13/1.42.7/1.43.2/1.44.0 (+ extension supplement) to security hall of fame.
Wed, Jul 9, 8:55 PM · SecTeam-Processed, affects-Miraheze, Security-Team
RhinosF1 created T399132: Add security reports from 1.39.13/1.42.7/1.43.2/1.44.0 (+ extension supplement) to security hall of fame.
Wed, Jul 9, 8:43 PM · SecTeam-Processed, affects-Miraheze, Security-Team

Jul 7 2025

RhinosF1 updated subscribers of T392341: CVE-2025-53483, CVE-2025-53484, CVE-2025-53485: SecurePoll is vulnerable to XSS, CSRF, and lack of authorisation.
Jul 7 2025, 8:01 PM · Trust and Safety Product Sprint (Sprint Rum baba (July 28 - August 15)), Patch-For-Review, Trust and Safety Product Team, Vuln-BrokenAccessControl, affects-Miraheze, Vuln-CSRF, Vuln-XSS, MediaWiki-extensions-SecurePoll, Security, Security-Team

Jul 5 2025

RhinosF1 added a comment to T398753: Too Many Requests Error on certain useragents (QtWebEngine, outdated chromium based browsers, Safari 605).

I suspect it's similar to https://lists.wikimedia.org/hyperkitty/list/[email protected]/message/3DNR7FALKHAU4L5ZUBRNP4Q4YWXLGABB/

Jul 5 2025, 2:47 PM · Traffic

Jul 3 2025

RhinosF1 added a comment to T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).

I'm extremely late adding them so if I'm too late then apologies but I added the 2 other ManageWiki CVEs that I forgot to add here

Since they are tracked outside of Phab/Gerrit and have CVEs assigned and merged patches already, it should be fairly trivial to include them for this release.

Thanks, I added the 5 CVEs from the last citizen release too. I'll try and think of a good way of tracking the ones we find that are from non-Wikimedia maintained extensions. It shouldn't be too difficult now both me and @Paladox have security access to create a Miraheze equivalent we can sync up to here close to the release for the next one. Obviously not sharing anything from here the other way around, just us sharing up to you.

Jul 3 2025, 6:11 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 updated the task description for T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).
Jul 3 2025, 6:02 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 updated the task description for T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).
Jul 3 2025, 5:55 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 updated the task description for T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).
Jul 3 2025, 5:53 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 updated the task description for T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).
Jul 3 2025, 5:51 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 updated the task description for T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).
Jul 3 2025, 5:51 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 added a comment to T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).

T394869: CVE-2025-7056: Stored XSS through a system message in UrlShortener and T394612: CVE-2025-7057: Stored XSS through a system message in Extension:Quiz are WMF tracked and missing off the list too

Jul 3 2025, 12:22 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 updated the task description for T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).
Jul 3 2025, 12:21 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 updated subscribers of T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).

I'm extremely late adding them so if I'm too late then apologies but I added the 2 other ManageWiki CVEs that I forgot to add here

Since they are tracked outside of Phab/Gerrit and have CVEs assigned and merged patches already, it should be fairly trivial to include them for this release.

Jul 3 2025, 12:17 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 updated the task description for T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).
Jul 3 2025, 12:12 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security

Jul 2 2025

RhinosF1 added a comment to T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).

I'm extremely late adding them so if I'm too late then apologies but I added the 2 other ManageWiki CVEs that I forgot to add here

Jul 2 2025, 4:34 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 updated the task description for T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).
Jul 2 2025, 4:33 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 added a comment to T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).

Subject: MediaWiki Extensions and Skins Security Release Supplement (1.39.13/1.42.7/1.43.2)

Greetings-

With the security/maintenance release of MediaWiki 1.39.13/1.42.7/1.43.2, we would also like to provide this supplementary announcement of MediaWiki extensions and skins with now-public Phabricator tasks, security patches and backports [1]:

ManageWiki
+ (https://github.com/miraheze/ManageWiki/security/advisories/GHSA-gg42-cv66-f5x7, CVE-2025-32956) - SQL injection vulnerability in NamespaceMigrationJob
https://github.com/miraheze/ManageWiki/commit/f504ed8eeb59b57ebb90f93cd44f23da4c5bc4c9

The Wikimedia Security Team recommends updating these extensions and/or skins to the current master branch or relevant, supported release branch [2] as soon as possible. Some of the referenced Phabricator tasks above _may_ still be private. Unfortunately, when security issues are reported, sometimes sensitive information is exposed and since Phabricator is historical, we cannot make these tasks public without exposing this sensitive information. If you have any additional questions or concerns regarding this update, please feel free to contact [email protected] or file a security task within Phabricator [3].

[1] https://phabricator.wikimedia.org/T389312
[2] https://www.mediawiki.org/wiki/Version_lifecycle
[3] https://www.mediawiki.org/wiki/Reporting_security_bugs

Jul 2 2025, 4:29 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security

Jun 29 2025

RhinosF1 updated subscribers of T394614: New upstream release for Pywikibot.

@rook used to be, I created https://github.com/toolforge/paws/pull/488

Jun 29 2025, 4:58 PM · User-RhinosF1, PAWS

Jun 26 2025

RhinosF1 updated the task description for T397900: Warning: User::loadFromSession called before the end of Setup.php.
Jun 26 2025, 7:02 AM · MW-1.45-notes (1.45.0-wmf.14; 2025-08-12), Trust and Safety Product Sprint (Sprint Rum baba (July 28 - August 15)), MediaWiki-Platform-Team (Radar), affects-Miraheze, Trust and Safety Product Team, MediaWiki-extensions-CentralAuth, GlobalBlocking
RhinosF1 updated the task description for T397900: Warning: User::loadFromSession called before the end of Setup.php.
Jun 26 2025, 6:54 AM · MW-1.45-notes (1.45.0-wmf.14; 2025-08-12), Trust and Safety Product Sprint (Sprint Rum baba (July 28 - August 15)), MediaWiki-Platform-Team (Radar), affects-Miraheze, Trust and Safety Product Team, MediaWiki-extensions-CentralAuth, GlobalBlocking
RhinosF1 removed a project from T397900: Warning: User::loadFromSession called before the end of Setup.php: Wikimedia-production-error.
Jun 26 2025, 6:50 AM · MW-1.45-notes (1.45.0-wmf.14; 2025-08-12), Trust and Safety Product Sprint (Sprint Rum baba (July 28 - August 15)), MediaWiki-Platform-Team (Radar), affects-Miraheze, Trust and Safety Product Team, MediaWiki-extensions-CentralAuth, GlobalBlocking
RhinosF1 created T397900: Warning: User::loadFromSession called before the end of Setup.php.
Jun 26 2025, 6:50 AM · MW-1.45-notes (1.45.0-wmf.14; 2025-08-12), Trust and Safety Product Sprint (Sprint Rum baba (July 28 - August 15)), MediaWiki-Platform-Team (Radar), affects-Miraheze, Trust and Safety Product Team, MediaWiki-extensions-CentralAuth, GlobalBlocking

Jun 24 2025

RhinosF1 added a comment to T385811: Vector should not direct third-party wikis to report dark mode issues to MW.o.

It's saddening to see this antipattern again after years of MediaViewer third-party misconfiguration issues (mis)filed in Wikimedia Phabricator due to hardcoding a Wikimedia URI in an extension that can also be used outside of Wikimedia.

Jun 24 2025, 10:59 AM · MW-1.44-release, Patch-For-Review, affects-Miraheze, good first task, patch-welcome, WikimediaMessages, Web-Team, MW-1.43-release, Vector 2022
RhinosF1 added a comment to T397679: Non Wikimedia wikis users report dark mode issues on mediawiki.org and causing IP leaks..

There is already a task for this. I don't think it's a security issue or there's need to suppress IPs.

Jun 24 2025, 7:22 AM · SecTeam-Processed, affects-Miraheze
RhinosF1 merged T397679: Non Wikimedia wikis users report dark mode issues on mediawiki.org and causing IP leaks. into T385811: Vector should not direct third-party wikis to report dark mode issues to MW.o.
Jun 24 2025, 7:20 AM · MW-1.44-release, Patch-For-Review, affects-Miraheze, good first task, patch-welcome, WikimediaMessages, Web-Team, MW-1.43-release, Vector 2022
RhinosF1 merged task T397679: Non Wikimedia wikis users report dark mode issues on mediawiki.org and causing IP leaks. into T385811: Vector should not direct third-party wikis to report dark mode issues to MW.o.
Jun 24 2025, 7:20 AM · SecTeam-Processed, affects-Miraheze

Jun 11 2025

RhinosF1 updated subscribers of T396413: CVE-2025-53497: Stored XSS in RelatedArticles.
Jun 11 2025, 3:34 PM · Web-Team, RelatedArticles, affects-Miraheze, Vuln-XSS, Security, Security-Team
RhinosF1 updated subscribers of T396413: CVE-2025-53497: Stored XSS in RelatedArticles.
Jun 11 2025, 3:34 PM · Web-Team, RelatedArticles, affects-Miraheze, Vuln-XSS, Security, Security-Team
RhinosF1 added a comment to T396413: CVE-2025-53497: Stored XSS in RelatedArticles.
Jun 11 2025, 3:33 PM · Web-Team, RelatedArticles, affects-Miraheze, Vuln-XSS, Security, Security-Team
RhinosF1 added a comment to T396413: CVE-2025-53497: Stored XSS in RelatedArticles.

...I would recommend quickly assessing whether there is any impact outside RelatedArticles before applying the fix and making this public.

We'd plan to deploy this as a security patch to Wikimedia production. We'd want to hold off on making it public in gerrit until the next supplemental security release.

Jun 11 2025, 1:26 PM · Web-Team, RelatedArticles, affects-Miraheze, Vuln-XSS, Security, Security-Team

Jun 9 2025

RhinosF1 added a comment to T394708: Security issue access for Paladox.

Thanks all!

Jun 9 2025, 4:19 PM · SecTeam-Processed, Security, Security-Team, affects-Miraheze

Jun 5 2025

RhinosF1 added a comment to T395934: NEW BUG REPORT: Investigate rise in May 2025 Reader metrics.

Slightly note of an interest, I saw a very similar pattern recently for Miraheze in our Cloudflare data so possible this affects for than the WMF. I can pull actual data later.

Jun 5 2025, 6:14 AM · Data-Engineering (Q1 FY25/26 July 1st - September 30th), Traffic, Movement-Insights

May 29 2025

RhinosF1 updated subscribers of T394708: Security issue access for Paladox.

@KFrancis: can you start that?

May 29 2025, 4:07 PM · SecTeam-Processed, Security, Security-Team, affects-Miraheze

May 27 2025

RhinosF1 added a comment to T394938: CVE-2025-53494: Stored XSS through a system message in TwoColConflict.

I removed it because it needed to be brought to security team's attention again because somehow the report in _security & via email was completely missed.

It's not for you to remove. Please do not do it again. There are other ways of contacting the Security-Team, as you've mentioned above. Both of which did receive replies as you have incorrectly noted here. Two on-call WMF staff members both correctly described this issue as low risk and not an immediate worry in #mediawiki_security, responding to @Urbanecm's message. That answer should absolutely have sufficed. I also replied to your email this morning and noted that the security team would be getting to these issues today during our clinic, which was delayed due to a Monday US holiday and an ongoing Wikimedia production incident. The Security-Team does not have unlimited resources nor do we guarantee 24/7 on-call services for every possible security-related issue.

There is still a process to follow though that security team are supposed to manage for WMF Deployed code. If this was a third party extension, we'd normally wait on task for your triage and for you to determine whether it's safe to be made public via a gerrit patch (and normally ensure that patch gets a speedy review). For a WMF Deployed Security issue, you guys are supposed to help us manage the private patch and deployment process to ensure WMF wikis are patched before the issue is exposed and normally would then release yourselves at security release time. This task has gone against the norm for reasons I'm not certain of but the lack of engagement is again embarrassing.

Processes are great when they are followed. That wasn't the case here and not due to the actions of anyone on the Security-Team. When incidents like this happen, people have to take out-of-process actions to correct the matter, which doesn't always happen perfectly and instantly.

As far as I can tell, _security was ignored. My email wasn't read. The patch was +2'd despite already being merged. This isn't an effective security release and someone needs to explain why again we're chasing the basics.

Most of this is incorrect as I mentioned above. I gave a quick +2 because from the comments on this task, it seemed like the patch hadn't been merged yet, nor cut for 1.45.0-wmf.3, both of which were incorrect. You're free to form your own opinions but I would advise not doing so on false assumptions and misinformation.

May 27 2025, 5:14 PM · SecTeam-Processed, WMDE-TechWish-Sprint-2025-05-14, Two-Column-Edit-Conflict-Merge, affects-Miraheze, Vuln-XSS, Security, Security-Team
RhinosF1 added a comment to T394938: CVE-2025-53494: Stored XSS through a system message in TwoColConflict.

Please don't remove SecTeam-Processed. That's an internal tag for the Security-Team's tracking.

I removed it because it needed to be brought to security team's attention again because somehow the report in _security & via email was completely missed.

This is already on 1.45.0-wmf.3, so at this point it just needs to ride the train the rest of the week to land in Wikimedia production. For most of these message XSS issues, we've traditionally considered them low risk since you'd need to compromise the MediaWiki message as well, which is non-trivial for unprivileged users.

Once a patch is up in gerrit, it can be backported by pretty much anyone. I can get those started now for supported release versions.

There is still a process to follow though that security team are supposed to manage for WMF Deployed code. If this was a third party extension, we'd normally wait on task for your triage and for you to determine whether it's safe to be made public via a gerrit patch (and normally ensure that patch gets a speedy review). For a WMF Deployed Security issue, you guys are supposed to help us manage the private patch and deployment process to ensure WMF wikis are patched before the issue is exposed and normally would then release yourselves at security release time. This task has gone against the norm for reasons I'm not certain of but the lack of engagement is again embarrassing.

May 27 2025, 4:36 PM · SecTeam-Processed, WMDE-TechWish-Sprint-2025-05-14, Two-Column-Edit-Conflict-Merge, affects-Miraheze, Vuln-XSS, Security, Security-Team
RhinosF1 removed a project from T394938: CVE-2025-53494: Stored XSS through a system message in TwoColConflict: SecTeam-Processed.
May 27 2025, 4:03 PM · SecTeam-Processed, WMDE-TechWish-Sprint-2025-05-14, Two-Column-Edit-Conflict-Merge, affects-Miraheze, Vuln-XSS, Security, Security-Team
RhinosF1 updated subscribers of T394938: CVE-2025-53494: Stored XSS through a system message in TwoColConflict.

Untagging Security-Team as it looks like WMDE plans to review this? Since this extension is Wikimedia-production-deployed, please code-review on this task and do not push the patch to gerrit. Once reviewed, the Security-Team can assist with a Wikimedia production deployment.

A bit late for that one. As per my email to security-help and flag by @Urbanecm in _security on IRC, this has been public for 48 hours on gerrit and afaik not deployed to production.

May 27 2025, 4:02 PM · SecTeam-Processed, WMDE-TechWish-Sprint-2025-05-14, Two-Column-Edit-Conflict-Merge, affects-Miraheze, Vuln-XSS, Security, Security-Team

May 25 2025

RhinosF1 added a comment to T395201: Quarry down - web service unreachable.

04:32:28 <wmcs-alerts> FIRING: [2x] TargetDown: Job app is unreachable in project quarry instance quarry.wmcloud.org:443  - https://prometheus-alerts.wmcloud.org/?q=alertname%3DTargetDown
04:32:39 <wmcs-alerts> FIRING: QuarryDown: Quarry application is unreachable  - https://prometheus-alerts.wmcloud.org/?q=alertname%3DQuarryDown

May 25 2025, 7:11 AM · Quarry
RhinosF1 renamed T395201: Quarry down - web service unreachable from Is Quarry down? to Quarry down - web service unreachable.
May 25 2025, 7:09 AM · Quarry

May 22 2025

RhinosF1 updated subscribers of T394721: CVE-2025-7363: XSS in TitleIcon.

Please also do a version bump to 6.2.1 in extension.json in all patched branches that did not get a MW version bump and a version bump to 6.3.0 in all branches that got a MW version bump from 1.39.0 to 1.40.0. Thank you!

Hi Cindy, I don't think that's a normal part of the security patching process. If you want to follow up with a version bump, you're more than welcome to.

May 22 2025, 7:47 PM · SecTeam-Processed, Vuln-XSS, MediaWiki-extensions-Title-Icon, affects-Miraheze, Security, Security-Team

May 19 2025

RhinosF1 added a comment to T394708: Security issue access for Paladox.

I followed https://wikitech.wikimedia.org/wiki/Volunteer_NDA because you need an NDA as part of getting security issue access

May 19 2025, 6:25 PM · SecTeam-Processed, Security, Security-Team, affects-Miraheze
RhinosF1 created T394708: Security issue access for Paladox.
May 19 2025, 5:14 PM · SecTeam-Processed, Security, Security-Team, affects-Miraheze
RhinosF1 added a comment to T394383: CVE-2025-53487: Stored XSS through system messages in Extension:ApprovedRevs.

Similar to my comment in T394612#10835735, the above patch should likely be pushed through gerrit since it isn't Wikimedia-deployed. Unless Miraheze would like to hold the patch until they've patched their production environments.

We're looking at this now, I also PM'd you on IRC a question.

May 19 2025, 4:56 PM · MediaWiki-extensions-Approved-Revs, Patch-For-Review, Vuln-XSS, SecTeam-Processed, affects-Miraheze, Security
RhinosF1 updated subscribers of T394612: CVE-2025-7057: Stored XSS through a system message in Extension:Quiz.
May 19 2025, 4:46 PM · Security-Team, SecTeam-Processed, MediaWiki-extensions-Quiz, Vuln-XSS, affects-Miraheze, Security
RhinosF1 updated subscribers of T394383: CVE-2025-53487: Stored XSS through system messages in Extension:ApprovedRevs.
May 19 2025, 4:46 PM · MediaWiki-extensions-Approved-Revs, Patch-For-Review, Vuln-XSS, SecTeam-Processed, affects-Miraheze, Security

May 7 2025

RhinosF1 updated the task description for T390914: Upgrade cloud-vps openstack to version 'Epoxy'.
May 7 2025, 7:46 PM · cloud-services-team, Cloud-VPS

May 5 2025

RhinosF1 added a member for Wikimedia-Incident: RhinosF1.
May 5 2025, 10:03 AM

May 1 2025

RhinosF1 added projects to T393092: Confusion over which interface sets ssh keys for use with Gerrit (hint: not IDM): collaboration-services, Release-Engineering-Team.
May 1 2025, 11:18 AM · Essential-Work, Release-Engineering-Team (Doing 😎), collaboration-services, Bitu, Gerrit, Infrastructure-Foundations

Apr 30 2025

RhinosF1 added a member for Trusted-Contributors: OriginalAuthority.
Apr 30 2025, 6:05 AM

Apr 29 2025

RhinosF1 added a member for Trusted-Contributors: SomeRandomDeveloper.
Apr 29 2025, 5:21 PM

Apr 26 2025

RhinosF1 added a comment to T392746: CVE-2025-6590: Complete content leak of private wikis due to PasswordReset Wikitext injection in error message.

Does anyone have a problem if I deploy this patch to Miraheze too?

No problems with you all deploying, but please be extremely careful to avoid public disclosure of the issue and the patch at this time.

Apr 26 2025, 1:37 PM · MW-1.39-release, MW-1.42-release, MW-1.43-release, MW-1.44-notes, SecTeam-Processed, MediaWiki-User-login-and-signup, MediaWiki-HTMLForm, Vuln-Infoleak, Security, Security-Team
RhinosF1 added a comment to T392746: CVE-2025-6590: Complete content leak of private wikis due to PasswordReset Wikitext injection in error message.

Apr 26 2025, 7:58 AM · MW-1.39-release, MW-1.42-release, MW-1.43-release, MW-1.44-notes, SecTeam-Processed, MediaWiki-User-login-and-signup, MediaWiki-HTMLForm, Vuln-Infoleak, Security, Security-Team

Apr 21 2025

RhinosF1 updated the task description for T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).
Apr 21 2025, 5:30 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 added a comment to T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).

@sbassett: Thanks for adding the template. CVE is pending review and we'll issue through GitHub's CNA.

Apr 21 2025, 5:26 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security
RhinosF1 updated the task description for T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).
Apr 21 2025, 5:25 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security

Apr 20 2025

RhinosF1 added a comment to T389312: Write and send supplementary release announcement for extensions and skins with security patches (1.39.13/1.42.7/1.43.2).

https://github.com/miraheze/ManageWiki/security/advisories/GHSA-gg42-cv66-f5x7 should probably be included

Apr 20 2025, 7:40 PM · affects-Miraheze, user-sbassett, MediaWiki-Releasing, Security

Apr 15 2025

RhinosF1 added a comment to T388996: Move CampaignEvents maintenance scripts to job queue.

Feel free to email or ping me on IRC

Apr 15 2025, 3:11 PM · Connection-Team, affects-Miraheze, CampaignEvents

Apr 14 2025

RhinosF1 added a comment to T54465: VisualEditor plus Parsoid without using https can break security when using external Parsoid calls (i.e. not using localhost:port Parsoid).

@cscott @ssastry - Per Roan's explanation in T54465#545525, I'm assuming this wasn't a very concerning issue to begin with, and is very likely irrelevant now? Unless an external operator does something extremely dangerous with their own config? If so, I'd love to decline this 11-year-old task.

@cscott: ping again as you had no view permissions before.

Apr 14 2025, 4:04 PM · SecTeam-Processed, Security, VisualEditor, RESTBase
RhinosF1 changed the visibility for T54465: VisualEditor plus Parsoid without using https can break security when using external Parsoid calls (i.e. not using localhost:port Parsoid).
Apr 14 2025, 4:03 PM · SecTeam-Processed, Security, VisualEditor, RESTBase

Apr 13 2025

RhinosF1 added a comment to T391750: QuickInstantCommons does not use the title capitalization of the file repo.

Given that this affects Miraheze and that Miraheze runs 1.43, I assume this should also be backported to the REL1_43 branch for it to take effect there? I'm not 100% sure about how Miraheze deploys extension updates and backports, so some clarity would be appreciated here.

Apr 13 2025, 4:15 PM · affects-Miraheze, MediaWiki-extensions-QuickInstantCommons

Apr 12 2025

RhinosF1 closed T388996: Move CampaignEvents maintenance scripts to job queue as Invalid.

This wasn't needed for us anyway and we're probably not deploying the extension anyway. Closing.

Apr 12 2025, 8:02 PM · Connection-Team, affects-Miraheze, CampaignEvents
RhinosF1 added a project to T391750: QuickInstantCommons does not use the title capitalization of the file repo: affects-Miraheze.

Report originated from one of our wikis

Apr 12 2025, 7:59 PM · affects-Miraheze, MediaWiki-extensions-QuickInstantCommons

Apr 11 2025

RhinosF1 added a comment to T382326: Write and send supplementary release announcement for extensions and skins with security patches (1.39.12/1.42.6/1.43.1).

Given the entire email was the wrong version, I'd say it's probably a good idea to send out the correct supplement, yes.

Ugh, well, I just sent out a correction because I assumed the email content was at least correct :/

Nope, you'll notice in the email all the CVEs are CVE-2024-XXXX

Apr 11 2025, 8:42 PM · user-sbassett, MediaWiki-Releasing, Security
RhinosF1 added a comment to T382326: Write and send supplementary release announcement for extensions and skins with security patches (1.39.12/1.42.6/1.43.1).

Given the entire email was the wrong version, I'd say it's probably a good idea to send out the correct supplement, yes.

Apr 11 2025, 8:37 PM · user-sbassett, MediaWiki-Releasing, Security
RhinosF1 reopened T382326: Write and send supplementary release announcement for extensions and skins with security patches (1.39.12/1.42.6/1.43.1) as "Open".

Email linked and sent is

MediaWiki Extensions and Skins Security Release Supplement (1.39.9/1.41.3/1.42.2)

NOT

Subject: MediaWiki Extensions and Skins Security Release Supplement (1.39.12/1.42.6/1.43.1)

Apr 11 2025, 5:35 PM · user-sbassett, MediaWiki-Releasing, Security

Apr 1 2025

RhinosF1 closed T390593: wikistats - import miraheze timer/service failed as Resolved.
Apr 1 2025, 6:57 AM · VPS-project-Wikistats, affects-Miraheze
RhinosF1 added a comment to T390593: wikistats - import miraheze timer/service failed.

Thank you! The service runs again.

regarding the API change: Maybe it could be reconsidered if renaming siteprop to prop (not sure it says why) is worth breaking it for all users of the API.

Apr 1 2025, 6:56 AM · VPS-project-Wikistats, affects-Miraheze

Mar 16 2025

RhinosF1 added a comment to T387861: Remove SUL3 opt-in code from CentralAuth.

The third isn't of interested to me, we can change all wikis at once. I'd just like us to be able to plan it properly. The second kind of is because I'd love to use the SUL3 opportunity to get rid of the historical abomination that is using loginwiki for GlobalUserPage

Mar 16 2025, 8:46 PM · MW-1.44-notes (1.44.0-wmf.27; 2025-04-29), affects-Miraheze, MediaWiki-Platform-Team, MediaWiki-extensions-CentralAuth, SUL3

Mar 11 2025

RhinosF1 added a member for Trusted-Contributors: Aeyeu.
Mar 11 2025, 7:48 AM

Mar 10 2025

RhinosF1 added projects to T388359: SimpleBlogPage breaks with BlueSpice function requirements: BlueSpice, Gerrit.
Mar 10 2025, 6:46 AM · BlueSpice, affects-Miraheze

Mar 6 2025

RhinosF1 added a project to T387861: Remove SUL3 opt-in code from CentralAuth: affects-Miraheze.

Maybe we want to keep isSul3Enabled() and simplify it to a simple per-wiki yes/no flag, for third-party wikis, but I'm not sure we want to do even that much, rather than just assuming SUL3 is always enabled. Although we have to keep in it at least a few places in the code for at least a year because of API backwards compatibility (e.g. T364829: Update Wikimedia apps to use central login domain).

Mar 6 2025, 7:24 PM · MW-1.44-notes (1.44.0-wmf.27; 2025-04-29), affects-Miraheze, MediaWiki-Platform-Team, MediaWiki-extensions-CentralAuth, SUL3
RhinosF1 added a member for SUL3: RhinosF1.
Mar 6 2025, 7:21 PM

Mar 2 2025

RhinosF1 closed T387672: Template Rendering Issue as Invalid.

This is a content error and poses no security risk.

Mar 2 2025, 7:28 PM · SecTeam-Processed

Feb 27 2025

RhinosF1 added a watcher for Vulnerability Management: RhinosF1.
Feb 27 2025, 6:19 PM

Feb 13 2025

RhinosF1 updated subscribers of T386382: Phabricator Bot request for WMDE GitHub notifications.
Feb 13 2025, 4:29 PM · Release-Engineering-Team (Priority Backlog 📥), Phabricator-Bot-Requests
RhinosF1 added a project to T386382: Phabricator Bot request for WMDE GitHub notifications: Phabricator maintenance bot.

I think @Maintenance_bot will automatically remove the Patch for Review tag in this case.

Feb 13 2025, 4:28 PM · Release-Engineering-Team (Priority Backlog 📥), Phabricator-Bot-Requests

Feb 6 2025

RhinosF1 added a comment to T385803: deployment-prep is broken following 2025-02-06 WMCS reboots.

15:31:32 <wmf-insecte> Yippee, build fixed!
15:31:33 <wmf-insecte> Project beta-update-databases-eqiad build #82385: FIXED in 11 min: https://integration.wikimedia.org/ci/job/beta-update-databases-eqiad/82385/

Feb 6 2025, 3:33 PM · User-bd808, Beta-Cluster-Infrastructure
RhinosF1 updated the task description for T385803: deployment-prep is broken following 2025-02-06 WMCS reboots.
Feb 6 2025, 3:16 PM · User-bd808, Beta-Cluster-Infrastructure
RhinosF1 added a comment to T385803: deployment-prep is broken following 2025-02-06 WMCS reboots.

15:14:33 <@andrewbogott> RhinosF1: ok, I can't arm keyholder on that host with the scap password or the deploy-service password or the mwdeploy password

Feb 6 2025, 3:15 PM · User-bd808, Beta-Cluster-Infrastructure
RhinosF1 triaged T385803: deployment-prep is broken following 2025-02-06 WMCS reboots as High priority.
Feb 6 2025, 2:42 PM · User-bd808, Beta-Cluster-Infrastructure
RhinosF1 created T385803: deployment-prep is broken following 2025-02-06 WMCS reboots.
Feb 6 2025, 2:42 PM · User-bd808, Beta-Cluster-Infrastructure

Jan 31 2025

RhinosF1 added a project to T385222: Support TLS 1.3: affects-Miraheze.
Jan 31 2025, 6:31 AM · affects-Miraheze, AutoWikiBrowser-Priorities

Jan 30 2025

RhinosF1 added a project to T385223: Make AWB use newer .NET version?: affects-Miraheze.
Jan 30 2025, 7:54 PM · affects-Miraheze, AutoWikiBrowser-Priorities

Jan 21 2025

RhinosF1 added a comment to T383098: Add BlankEclair to Security Team Hall of Fame.

@RhinosF1 I think it's correct now

Jan 21 2025, 4:56 PM · SecTeam-Processed, Security Team AppSec, Security-Team
RhinosF1 added a comment to T383098: Add BlankEclair to Security Team Hall of Fame.

@sbassett: can you get the CVE IDs updated to the correct too?

Jan 21 2025, 4:19 PM · SecTeam-Processed, Security Team AppSec, Security-Team

Jan 18 2025

RhinosF1 reopened T383098: Add BlankEclair to Security Team Hall of Fame as "Open".

Hi Security Team,

Jan 18 2025, 10:28 AM · SecTeam-Processed, Security Team AppSec, Security-Team

Jan 15 2025

RhinosF1 updated subscribers of T383472: CVE-2025-32077: XSSes in Extension:SimpleCalendar.
Jan 15 2025, 8:58 AM · SecTeam-Processed, Vuln-XSS, MediaWiki-extensions-Other, affects-Miraheze, Security

Jan 13 2025

RhinosF1 updated the task description for T383622: Revision Deletion UI for 'createaccount' log entries is misleading.
Jan 13 2025, 8:23 PM · MediaWiki-Logevents, MediaWiki-User-login-and-signup, MediaWiki-Revision-deletion
RhinosF1 created T383622: Revision Deletion UI for 'createaccount' log entries is misleading.
Jan 13 2025, 8:21 PM · MediaWiki-Logevents, MediaWiki-User-login-and-signup, MediaWiki-Revision-deletion

Jan 12 2025

RhinosF1 added a project to T383524: CSS is ignored on Parsoid: affects-Miraheze.
Jan 12 2025, 8:11 PM · Parsoid (Third-party), patch-welcome, affects-Miraheze, MediaWiki-extensions-CSS

Jan 6 2025

RhinosF1 added a comment to T374318: Wikifunctions is down.

I wonder if we can raise that ban again? I think the crawler in combination with T374241 was causing the site instability issue. I would suggest that we de-ban the bot, and see if it causes issues again, because I don't think that the crawling itself would cause the issues described here.

My bot (that runs the featured tool from the newsletter) that continuously tries to locally update every Z2 all the time, and has sent (by my really really rough estimate) 100,000 requests to Wikifunctions in the past week, has not caused any significant harm, so I don't think that ClaudeBot could have possibly been worse.

100,000 requests a week is by my count about a request every 6 seconds. It's absolutely possible for a crawler to do worse than that.

Jan 6 2025, 7:08 AM · Traffic, Abstract Wikipedia team

Jan 5 2025

RhinosF1 added a member for WE4.2 CAPTCHA evaluation framework: RhinosF1.
Jan 5 2025, 6:24 PM

Dec 27 2024

RhinosF1 edited projects for T382783: Missing composer.json patch causes upgrade failures, added: MediaWiki-Releasing, MW-1.42-release, Parsoid; removed Release-Engineering-Team.
Dec 27 2024, 8:47 AM · MW-1.42-release, MediaWiki-Releasing

Dec 19 2024

Restricted Application added a project to T373388: Merge CentralAuth locks into GlobalBlocking: Trust and Safety Product Team.
Dec 19 2024, 5:46 PM · MediaWiki-Platform-Team (Roadmap), Trust and Safety Product Team, Epic, GlobalBlocking, MediaWiki-extensions-CentralAuth

Dec 14 2024

RhinosF1 updated subscribers of T382138: Why have all images disappeared from https://wikidocumentaries.wmcloud.org/?.

@TuukaH was recently active and created the only instance in that project

Dec 14 2024, 2:17 PM · VPS-Projects, Wikidocumentaries
RhinosF1 added a comment to T382138: Why have all images disappeared from https://wikidocumentaries.wmcloud.org/?.

@TuukkaH was recently active and created the only instance in that project

Dec 14 2024, 2:16 PM · VPS-Projects, Wikidocumentaries

Dec 9 2024

RhinosF1 added a project to T381769: Potential RCE in Extension:ArticleFeedbackv5: affects-Miraheze.
Dec 9 2024, 12:11 PM · affects-Miraheze, ArticleFeedbackv5, Security

Dec 8 2024

RhinosF1 added a project to T33951: Merge Interwiki extension into MediaWiki core: translatewiki.net.

Adding translatewiki.net so someone can see if the above can be addressed

Dec 8 2024, 9:20 PM · Release-Engineering-Team, translatewiki.net, MW-1.44-notes (1.44.0-wmf.8; 2024-12-17), MediaWiki-Interwiki, MediaWiki-extensions-Interwiki

Nov 30 2024

RhinosF1 added a comment to T381208: Requesting GitLab account activation for King ChristLike1.

@KingChristLike: just to check, have you lost access to your KingChristLike account? I assume that's yours.

Nov 30 2024, 8:00 PM · GitLab (Account Approval), Release-Engineering-Team