Page MenuHomePhabricator

Special:UploadWizard loading insecure content from commons
Closed, ResolvedPublic

Description

Seen currently on both test.wiki and test2.wiki:

The page at https://test.wikipedia.org/wiki/Special:UploadWizard displayed insecure content from http://upload.wikimedia.org/wikipedia/commons/4/42/Loading.gif.


Version: unspecified
Severity: minor

Details

Reference
bz34599

Event Timeline

bzimport raised the priority of this task from to Needs Triage.Nov 22 2014, 12:18 AM
bzimport added a project: UploadWizard.
bzimport set Reference to bz34599.
bzimport added a subscriber: Unknown Object (MLST).

This appears to actually be in mediawiki.feedback.js in core...

$( '<img src="http://upload.wikimedia.org/wikipedia/commons/4/42/Loading.gif" />' )

As a quick fix I'll just swap it to protocol-relative, but it should be replaced with CSS and a local image.

r112169 does the protocol-relative switch

r112172 does a proper fix, turning it into a locally-hosted .gif loaded via
styles in the module.