Page MenuHomePhabricator

Setting protocol relative wikilinks (urls) circumvents blacklist
Closed, ResolvedPublic

Description

By use of the protocol relative urls, one is able to create urls that circumvent the blacklist

eg. [//skiptest.info skiptest]] will form a clickable functional url

I have tested at meta against the global spamlist, and at local wiki against the Mediawiki:Spam-blacklist at that wiki, both times success (if you call that success <urk>)


Version: 1.18.x
Severity: major

Details

Reference
bz33985

Event Timeline

bzimport raised the priority of this task from to High.Nov 22 2014, 12:08 AM
bzimport set Reference to bz33985.

Already fixed with r107857. I have tagged the revision for merge to live site.

Tagging as "shell" for Sam to deploy when he gets a chance

Note that bug 34179 was created as a result of how this was fixed.