Page MenuHomePhabricator

sbassett (Scott Bassett)
Staff Security EngineerAdministrator

Today

  • Clear sailing ahead.

Tomorrow

  • Clear sailing ahead.

Friday

  • Clear sailing ahead.

User Details

User Since
Sep 12 2018, 3:52 PM (322 w, 6 d)
Roles
Administrator
Availability
Available
IRC Nick
sbassett
LDAP User
SBassett
MediaWiki User
SBassett (WMF) [ Global Accounts ]

Member of the Security-Team. My user-sbassett board should be fairly up-to-date, though we also track some other work within Asana these days.

Recent Activity

Yesterday

sbassett added a comment to T376745: Grant Phabricator security access to Jon Robson.

@Jdlrobson-WMF - Yes, I think you should be good now with the above explanation. We can enable security access for your -WMF account now. Thanks.

Tue, Nov 19, 6:23 PM · SecTeam-Processed, Security, Security-Team
sbassett added a project to T379009: As a user I should be able to perform CRUD operations via the django REST API for various mutable objects: user-sbassett.
Tue, Nov 19, 6:20 PM · user-sbassett, SecTeam-Processed, Universal Security Dashboard, Security, Security-Team
sbassett claimed T379009: As a user I should be able to perform CRUD operations via the django REST API for various mutable objects.
Tue, Nov 19, 6:19 PM · user-sbassett, SecTeam-Processed, Universal Security Dashboard, Security, Security-Team
sbassett assigned T379007: Discuss best authn/z methods for initial phase of application development to mmartorana.
Tue, Nov 19, 6:17 PM · SecTeam-Processed, Universal Security Dashboard, Security, Security-Team
sbassett created T380306: Create basic specification (one-pager) and/or Decision Record Overview documents for USD.
Tue, Nov 19, 5:58 PM · Universal Security Dashboard, Security, Security-Team
sbassett added a comment to T380014: Onboard Jimmy Ly to the Security Team.
Tue, Nov 19, 4:40 PM · SecTeam-Processed, Security Team AppSec, Security-Team
sbassett removed a member for Trusted-Contributors: Jly.
Tue, Nov 19, 4:39 PM
sbassett removed a member for acl*security_secteam: Jly.
Tue, Nov 19, 4:39 PM
sbassett updated the task description for T380014: Onboard Jimmy Ly to the Security Team.
Tue, Nov 19, 4:13 PM · SecTeam-Processed, Security Team AppSec, Security-Team
sbassett updated the task description for T380014: Onboard Jimmy Ly to the Security Team.
Tue, Nov 19, 4:12 PM · SecTeam-Processed, Security Team AppSec, Security-Team
sbassett added a comment to T379526: Review and update documentation/ policy from volunteer developer perspective about deploying extensions to WMF production.

I think the above diff I added is helpful and solves the main goal of this ticket: letting a developer know early on in the extension writing process that it is mandatory to partner with a WMF team to get an extension deployed to WMF production.

Are there any other actionables? Should the ticket be marked resolved?

Tue, Nov 19, 3:57 PM · Wikimedia-extension-review-queue, Documentation

Mon, Nov 18

sbassett removed a watcher for Charts: sbassett.
Mon, Nov 18, 8:09 PM
sbassett changed the status of T380014: Onboard Jimmy Ly to the Security Team from Open to In Progress.
Mon, Nov 18, 5:22 PM · SecTeam-Processed, Security Team AppSec, Security-Team
sbassett moved T379677: FancyCaptcha uses unescaped i18n messages from Incoming to Our Part Is Done on the Security-Team board.
Mon, Nov 18, 4:44 PM · SecTeam-Processed, Vuln-XSS, MediaWiki-Platform-Team, ConfirmEdit (CAPTCHA extension), Security, Security-Team
sbassett closed T379677: FancyCaptcha uses unescaped i18n messages as Resolved.
Mon, Nov 18, 4:40 PM · SecTeam-Processed, Vuln-XSS, MediaWiki-Platform-Team, ConfirmEdit (CAPTCHA extension), Security, Security-Team
sbassett updated subscribers of T379677: FancyCaptcha uses unescaped i18n messages.

Resolved now, right? Or are you waiting for the MW release to close this?

Mon, Nov 18, 4:40 PM · SecTeam-Processed, Vuln-XSS, MediaWiki-Platform-Team, ConfirmEdit (CAPTCHA extension), Security, Security-Team
sbassett closed T379677: FancyCaptcha uses unescaped i18n messages, a subtask of T373732: Audit SUL3 shared-domain i18n messages for XSS, as Resolved.
Mon, Nov 18, 4:40 PM · MW-1.44-notes (1.44.0-wmf.4; 2024-11-19), Security, MediaWiki-Platform-Team, SUL3

Sat, Nov 16

sbassett triaged T291852: Weird anoneditwarning output when adding an external link as Medium priority.
Sat, Nov 16, 5:17 PM · MW-1.44-notes (1.44.0-wmf.5; 2024-11-25), Patch-For-Review, SecTeam-Processed, MediaWiki-Page-editing, Security
sbassett added a comment to T379011: Determine list of projects for initial phase of development.

These look fine. We could probably add a few more highly-used ones. Not sure about Cargo though, as that isn't run in Wikimedia production. I guess if we wanted to have one "mostly third party" extension, that could be a possible choice.

Sat, Nov 16, 3:27 PM · Security, Universal Security Dashboard, Security-Team

Fri, Nov 15

sbassett added a comment to T379005: Discuss and determine django ORM structure for initial application.

Hey @sbassett - let’s discuss further in the MR I’ll submit - it should make things clearer.

Fri, Nov 15, 5:20 PM · SecTeam-Processed, Universal Security Dashboard, Security, Security-Team
sbassett updated the task description for T380014: Onboard Jimmy Ly to the Security Team.
Fri, Nov 15, 5:19 PM · SecTeam-Processed, Security Team AppSec, Security-Team
sbassett added a comment to T375989: Account recognizer (LoginNotify) is broken!.

(Heh, I got logged out here, checkbox says "Keep me logged in (for up to 365 days)"... We can all see I was logged in more recently than THAT, my first login was creating this thread)

Fri, Nov 15, 5:15 PM · SecTeam-Processed, Community-Tech, MediaWiki-extensions-LoginNotify

Thu, Nov 14

sbassett added a comment to T379005: Discuss and determine django ORM structure for initial application.

Hey @mmartorana - once https://gitlab.wikimedia.org/repos/security/universal-security-dashboard/-/merge_requests/5 is merged, all of the django app structure should be in place to begin working on usd_api/models.py, etc.

Thu, Nov 14, 5:22 PM · SecTeam-Processed, Universal Security Dashboard, Security, Security-Team

Wed, Nov 13

sbassett added a comment to T379800: Application Security Review Request : Codex PHP.

@sbassett is end of Q3 reasonable? Let me know and I'll try to help manage expectations in terms of potential usage.

Wed, Nov 13, 9:46 PM · Design-System-Team, secscrum, Security, Application Security Reviews
sbassett added a comment to T379800: Application Security Review Request : Codex PHP.

@egardner - End of Q2 2024? - as in, by the end of December 2024? I don't believe there is any way we can accommodate that date.

Wed, Nov 13, 9:38 PM · Design-System-Team, secscrum, Security, Application Security Reviews
sbassett moved T379800: Application Security Review Request : Codex PHP from Incoming to Upcoming Quarter Planning Queue on the secscrum board.
Wed, Nov 13, 9:34 PM · Design-System-Team, secscrum, Security, Application Security Reviews
sbassett awarded T379793: [EPIC] Remove Webpack from MobileFrontend a Like token.
Wed, Nov 13, 6:41 PM · Web-Team-Roadmap, Epic, Web Team Essential Work 2024 (Remove Webpack from MobileFrontend), MobileFrontend, patch-welcome, User-Jdlrobson
sbassett assigned T379005: Discuss and determine django ORM structure for initial application to mmartorana.
Wed, Nov 13, 3:40 PM · SecTeam-Processed, Universal Security Dashboard, Security, Security-Team
sbassett merged task T377766: Create basic django models for initial release of the project into T379005: Discuss and determine django ORM structure for initial application.
Wed, Nov 13, 3:40 PM · Universal Security Dashboard, Security, Security-Team
sbassett merged T377766: Create basic django models for initial release of the project into T379005: Discuss and determine django ORM structure for initial application.
Wed, Nov 13, 3:40 PM · SecTeam-Processed, Universal Security Dashboard, Security, Security-Team
sbassett added a parent task for T379677: FancyCaptcha uses unescaped i18n messages: Unknown Object (Task).
Wed, Nov 13, 3:26 PM · SecTeam-Processed, Vuln-XSS, MediaWiki-Platform-Team, ConfirmEdit (CAPTCHA extension), Security, Security-Team

Tue, Nov 12

sbassett added a comment to T377249: improve Opensource Review Process .

Assuming this is likely stalled until we hire a new PM?

Tue, Nov 12, 10:12 PM · Security-Team
sbassett updated subscribers of T379677: FancyCaptcha uses unescaped i18n messages.

Tue, Nov 12, 10:11 PM · SecTeam-Processed, Vuln-XSS, MediaWiki-Platform-Team, ConfirmEdit (CAPTCHA extension), Security, Security-Team
sbassett added a comment to T379526: Review and update documentation/ policy from volunteer developer perspective about deploying extensions to WMF production.

A lot of power and flexibility is offered for user-developed tools via ext:Gadgets and toolforge/wmcs. In most cases, those environments should likely be preferred unless they are completely unacceptable for some reason (which would be a high bar IMO). The WMF does currently have an internal working group devoted to code ownership/maintenance (in the context of Wikimedia-deployed code) but it's a very difficult problem to address and solve. We want to enable volunteers as much as possible, but are also limited by how much security and legal risk is acceptable for the WMF to absorb, since they are the primary entity that must absorb said risks.

Tue, Nov 12, 4:14 PM · Wikimedia-extension-review-queue, Documentation

Fri, Nov 8

sbassett added a comment to T379005: Discuss and determine django ORM structure for initial application.

Regarding the classes, I think for now, since we're aiming for an MVP, we could add a Result class, a User class (to handle different roles), and a Configuration/Settings class to store various tool settings.

Fri, Nov 8, 9:18 PM · SecTeam-Processed, Universal Security Dashboard, Security, Security-Team
sbassett added a comment to T379007: Discuss best authn/z methods for initial phase of application development.

Yes, this should probably be fine. The default django admin/auth does support token-based auth for django rest framework, so that should be all we need for now.

Fri, Nov 8, 9:15 PM · SecTeam-Processed, Universal Security Dashboard, Security, Security-Team
sbassett added a comment to T355150: Application Security Review Request : Adiutor MediaWiki extension.

@sbassett is this scheduled for security review this quarter?

Fri, Nov 8, 7:11 PM · Adiutor, secscrum, Security, Application Security Reviews

Thu, Nov 7

sbassett closed T377763: Establish baseline dependencies and application structure as Resolved.

@sbassett is there anything else needed for this ticket? I want to close it

Thu, Nov 7, 4:30 PM · SecTeam-Processed, Universal Security Dashboard, Security, Security-Team
sbassett moved T377763: Establish baseline dependencies and application structure from Backlog to Done on the Universal Security Dashboard board.
Thu, Nov 7, 4:30 PM · SecTeam-Processed, Universal Security Dashboard, Security, Security-Team
sbassett closed T377763: Establish baseline dependencies and application structure, a subtask of T371814: [EPIC] Universal Security Dashboard, as Resolved.
Thu, Nov 7, 4:30 PM · SecTeam-Processed, Universal Security Dashboard, user-sbassett, Epic, Security, Security-Team

Wed, Nov 6

sbassett added a comment to T365298: Design request: Central Login Design Review and Recommendations.

Personally, I'm not sure I see an enormous issue with sso.wikimedia.org. The other proposed options seem a bit too vague to me for what SUL3 is actually trying to accomplish.

Wed, Nov 6, 6:07 PM · SUL3, Design, Wikimedia-Design
sbassett added a project to T379010: Design task/job queue for task runs for initial phase of project: SecTeam-Processed.
Wed, Nov 6, 5:57 PM · SecTeam-Processed, Universal Security Dashboard, Security, Security-Team
sbassett moved T379009: As a user I should be able to perform CRUD operations via the django REST API for various mutable objects from Incoming to Back Orders on the Security-Team board.
Wed, Nov 6, 5:57 PM · user-sbassett, SecTeam-Processed, Universal Security Dashboard, Security, Security-Team
sbassett moved T379007: Discuss best authn/z methods for initial phase of application development from Incoming to Back Orders on the Security-Team board.
Wed, Nov 6, 5:55 PM · SecTeam-Processed, Universal Security Dashboard, Security, Security-Team
sbassett moved T379003: Commit and merge basic django app framework structure from Incoming to In Progress on the Security-Team board.
Wed, Nov 6, 5:54 PM · Patch-For-Review, SecTeam-Processed, Universal Security Dashboard, Security, Security-Team
sbassett moved T379005: Discuss and determine django ORM structure for initial application from Incoming to In Progress on the Security-Team board.
Wed, Nov 6, 5:52 PM · SecTeam-Processed, Universal Security Dashboard, Security, Security-Team
sbassett changed the status of T379011: Determine list of projects for initial phase of development from Open to In Progress.
Wed, Nov 6, 5:49 PM · Security, Universal Security Dashboard, Security-Team
sbassett changed the status of T379011: Determine list of projects for initial phase of development, a subtask of T371814: [EPIC] Universal Security Dashboard, from Open to In Progress.
Wed, Nov 6, 5:48 PM · SecTeam-Processed, Universal Security Dashboard, user-sbassett, Epic, Security, Security-Team
sbassett moved T379088: Application Security Review Request : Wikifunctions Rust-Based Function Evaluator from Incoming to Upcoming Quarter Planning Queue on the secscrum board.
Wed, Nov 6, 5:31 PM · Abstract Wikipedia team (25Q2 (Oct–Dec)), function-evaluator, secscrum, Security, Application Security Reviews
sbassett moved T378722: Application Security Review Request : SUL3 from Incoming to Upcoming Quarter Planning Queue on the secscrum board.
Wed, Nov 6, 5:31 PM · MediaWiki-Platform-Team, SUL3, secscrum, Security, Application Security Reviews

Mon, Nov 4

sbassett updated the task description for T379011: Determine list of projects for initial phase of development.
Mon, Nov 4, 11:29 PM · Security, Universal Security Dashboard, Security-Team
sbassett added a comment to T364302: Complete the Mitre CNA Partner Process for the Wikimedia Foundation .
Mon, Nov 4, 11:21 PM · User-notice-archive, Security-Team
sbassett added a comment to T364302: Complete the Mitre CNA Partner Process for the Wikimedia Foundation .

@Quiddity @Johan - I've seen that this was not mentioned in the last couple of Tech News posts to wikitech-l. Is there a scheduled date when this notice might appear? Thanks.

Mon, Nov 4, 9:52 PM · User-notice-archive, Security-Team
sbassett updated the task description for T379005: Discuss and determine django ORM structure for initial application.
Mon, Nov 4, 5:58 PM · SecTeam-Processed, Universal Security Dashboard, Security, Security-Team
sbassett created T379011: Determine list of projects for initial phase of development.
Mon, Nov 4, 5:46 PM · Security, Universal Security Dashboard, Security-Team
sbassett created T379010: Design task/job queue for task runs for initial phase of project.
Mon, Nov 4, 5:37 PM · SecTeam-Processed, Universal Security Dashboard, Security, Security-Team
sbassett updated the task description for T379009: As a user I should be able to perform CRUD operations via the django REST API for various mutable objects.
Mon, Nov 4, 5:30 PM · user-sbassett, SecTeam-Processed, Universal Security Dashboard, Security, Security-Team
sbassett updated the task description for T379009: As a user I should be able to perform CRUD operations via the django REST API for various mutable objects.
Mon, Nov 4, 5:28 PM · user-sbassett, SecTeam-Processed, Universal Security Dashboard, Security, Security-Team
sbassett created T379009: As a user I should be able to perform CRUD operations via the django REST API for various mutable objects.
Mon, Nov 4, 5:28 PM · user-sbassett, SecTeam-Processed, Universal Security Dashboard, Security, Security-Team
sbassett created T379007: Discuss best authn/z methods for initial phase of application development.
Mon, Nov 4, 5:22 PM · SecTeam-Processed, Universal Security Dashboard, Security, Security-Team
sbassett created T379005: Discuss and determine django ORM structure for initial application.
Mon, Nov 4, 5:15 PM · SecTeam-Processed, Universal Security Dashboard, Security, Security-Team
sbassett created T379003: Commit and merge basic django app framework structure.
Mon, Nov 4, 5:13 PM · Patch-For-Review, SecTeam-Processed, Universal Security Dashboard, Security, Security-Team

Thu, Oct 31

sbassett removed a project from T377855: API list=globalblocks can reveal IP of autoblock if username and IP are included in the bgtargets parameter: Patch-For-Review.
Thu, Oct 31, 4:43 PM · SecTeam-Processed, Trust and Safety Product Sprint (Sprint Accordion October 28 - November 15), Temporary accounts (Blockers to minor pilot wiki deployment), Trust and Safety Product Team, GlobalBlocking, Security, Security-Team
sbassett triaged T377855: API list=globalblocks can reveal IP of autoblock if username and IP are included in the bgtargets parameter as Medium priority.
Thu, Oct 31, 4:42 PM · SecTeam-Processed, Trust and Safety Product Sprint (Sprint Accordion October 28 - November 15), Temporary accounts (Blockers to minor pilot wiki deployment), Trust and Safety Product Team, GlobalBlocking, Security, Security-Team
sbassett added a comment to T377222: Don’t use raw HTML messages in safe mode.

It still has <strong> tags and is parsed due to the wikitext links. I guess one could argue that the <strong> tags are superfluous.

But it's parsed so it's safe HTML, not raw HTML.

Thu, Oct 31, 4:32 PM · MW-1.44-notes (1.44.0-wmf.4; 2024-11-19), SecTeam-Processed, Vuln-XSS, Vuln-Misconfiguration, I18n, MediaWiki-Internationalization, Security, Security-Team
sbassett updated the task description for T377769: Research and determine initial security tools .
Thu, Oct 31, 4:27 PM · Universal Security Dashboard, Security, Security-Team

Wed, Oct 30

sbassett added a comment to T377222: Don’t use raw HTML messages in safe mode.
  • stopforumspam-is-blocked (20bb7d1d - seems wrong? the message is not actually HTML)
Wed, Oct 30, 9:13 PM · MW-1.44-notes (1.44.0-wmf.4; 2024-11-19), SecTeam-Processed, Vuln-XSS, Vuln-Misconfiguration, I18n, MediaWiki-Internationalization, Security, Security-Team
sbassett added a project to T378511: abuse_filter_log still exists on some replicas: SecTeam-Processed.
Wed, Oct 30, 8:50 PM · SecTeam-Processed, cloud-services-team (FY2024/2025-Q1-Q2), Data-Services, Security-Team, Security
sbassett set Author Affiliation to tech on T378511: abuse_filter_log still exists on some replicas.
Wed, Oct 30, 8:50 PM · SecTeam-Processed, cloud-services-team (FY2024/2025-Q1-Q2), Data-Services, Security-Team, Security
sbassett awarded T375751: Public wiki replicas contain abuse filter logs for filters that are private or protected a Like token.
Wed, Oct 30, 8:46 PM · cloud-services-team (FY2024/2025-Q1-Q2), Data-Platform-SRE (2024.10.19 - 2024.11.08), Trust and Safety Product Sprint (Sprint Accordion October 28 - November 15), Data Products, SecTeam-Processed, Privacy Engineering, Patch-For-Review, SRE, Data-Services, Vuln-Infoleak, AbuseFilter, Security
sbassett added a comment to T369950: Application Security Review Request : Chart extension and chart-renderer service.

Oh, just to clarify, we are still planning to deploy to test wiki before the review. We just won't deploy to any real wikis.

Wed, Oct 30, 8:39 PM · Charts, secscrum, Security, Application Security Reviews

Tue, Oct 29

sbassett added a comment to T375751: Public wiki replicas contain abuse filter logs for filters that are private or protected.

If it's just the analytics replicas that were (potentially) remaining, I'd classify those as low-risk.

Tue, Oct 29, 3:37 PM · cloud-services-team (FY2024/2025-Q1-Q2), Data-Platform-SRE (2024.10.19 - 2024.11.08), Trust and Safety Product Sprint (Sprint Accordion October 28 - November 15), Data Products, SecTeam-Processed, Privacy Engineering, Patch-For-Review, SRE, Data-Services, Vuln-Infoleak, AbuseFilter, Security
sbassett changed the visibility for T375751: Public wiki replicas contain abuse filter logs for filters that are private or protected.
Tue, Oct 29, 3:34 PM · cloud-services-team (FY2024/2025-Q1-Q2), Data-Platform-SRE (2024.10.19 - 2024.11.08), Trust and Safety Product Sprint (Sprint Accordion October 28 - November 15), Data Products, SecTeam-Processed, Privacy Engineering, Patch-For-Review, SRE, Data-Services, Vuln-Infoleak, AbuseFilter, Security
sbassett closed T375751: Public wiki replicas contain abuse filter logs for filters that are private or protected as Resolved.

@sbassett can we make this task public? There is some discussion related to this task at https://en.wikipedia.org/wiki/Wikipedia:Village_pump_(technical)#Edit_filter_graph_links_broken.

Tue, Oct 29, 3:26 PM · cloud-services-team (FY2024/2025-Q1-Q2), Data-Platform-SRE (2024.10.19 - 2024.11.08), Trust and Safety Product Sprint (Sprint Accordion October 28 - November 15), Data Products, SecTeam-Processed, Privacy Engineering, Patch-For-Review, SRE, Data-Services, Vuln-Infoleak, AbuseFilter, Security

Mon, Oct 28

sbassett removed a project from T378249: OpenBao backups: Security-Team.
Mon, Oct 28, 5:27 PM · SecTeam-Processed, Security, Infrastructure-Foundations
sbassett removed a project from T378250: OpenBao audit logs: Security-Team.
Mon, Oct 28, 5:26 PM · SecTeam-Processed, Security, Infrastructure-Foundations
sbassett removed a project from T378248: OpenBao high availability: Security-Team.
Mon, Oct 28, 5:26 PM · SecTeam-Processed, Security, Infrastructure-Foundations
sbassett removed a project from T378247: OpenBao authentication methods: Security-Team.
Mon, Oct 28, 5:24 PM · SecTeam-Processed, Security, Infrastructure-Foundations
sbassett removed a project from T378246: OpenBao unsealing: Security-Team.
Mon, Oct 28, 5:24 PM · SecTeam-Processed, Security, Infrastructure-Foundations
sbassett removed a project from T378243: OpenBao secret engines: Security-Team.
Mon, Oct 28, 5:23 PM · SecTeam-Processed, Security, Infrastructure-Foundations
sbassett removed a project from T378245: OpenBao installation & configuration: Security-Team.
Mon, Oct 28, 5:22 PM · SecTeam-Processed, Security, Infrastructure-Foundations
sbassett removed a project from T378244: OpenBao storage engine: Security-Team.
Mon, Oct 28, 5:22 PM · SecTeam-Processed, Security, Infrastructure-Foundations
sbassett removed a project from T378241: OpenBao human consumer: Security-Team.
Mon, Oct 28, 5:21 PM · SecTeam-Processed, Security, Infrastructure-Foundations
sbassett removed a project from T378240: OpenBao Kubernetes consumer: Security-Team.
Mon, Oct 28, 5:20 PM · SecTeam-Processed, Security, Infrastructure-Foundations
sbassett removed a project from T378239: OpenBao Puppet consumer: Security-Team.
Mon, Oct 28, 5:20 PM · SecTeam-Processed, Security, Infrastructure-Foundations
sbassett removed a project from T378237: OpenBao consumers: Security-Team.
Mon, Oct 28, 5:20 PM · SecTeam-Processed, Security, Infrastructure-Foundations
sbassett removed a project from T378235: OpenBao evaluation: Security-Team.
Mon, Oct 28, 5:20 PM · SecTeam-Processed, Security, Infrastructure-Foundations
sbassett edited projects for T378157: SUL Integration for eventyay (Wikimania virtual event platform), added: SecTeam-Processed; removed Security-Team.

It doesn't look like there are any immediate asks from the Security-Team for this? If there are, please let us know.

Mon, Oct 28, 5:20 PM · MediaWiki-Platform-Team (Radar), SecTeam-Processed, Security
sbassett moved T377762: Create a workable docker-compose.yml for the USD application from Backlog to In Progress on the user-sbassett board.
Mon, Oct 28, 5:17 PM · Patch-For-Review, SecTeam-Processed, Universal Security Dashboard, user-sbassett, Security, Security-Team
sbassett changed the status of T377762: Create a workable docker-compose.yml for the USD application from Open to In Progress.
Mon, Oct 28, 5:17 PM · Patch-For-Review, SecTeam-Processed, Universal Security Dashboard, user-sbassett, Security, Security-Team
sbassett changed the status of T377762: Create a workable docker-compose.yml for the USD application, a subtask of T371814: [EPIC] Universal Security Dashboard, from Open to In Progress.
Mon, Oct 28, 5:15 PM · SecTeam-Processed, Universal Security Dashboard, user-sbassett, Epic, Security, Security-Team
sbassett added a project to T377763: Establish baseline dependencies and application structure: SecTeam-Processed.
Mon, Oct 28, 5:14 PM · SecTeam-Processed, Universal Security Dashboard, Security, Security-Team
sbassett changed the status of T377763: Establish baseline dependencies and application structure, a subtask of T371814: [EPIC] Universal Security Dashboard, from Open to In Progress.
Mon, Oct 28, 5:14 PM · SecTeam-Processed, Universal Security Dashboard, user-sbassett, Epic, Security, Security-Team
sbassett changed the status of T377763: Establish baseline dependencies and application structure from Open to In Progress.
Mon, Oct 28, 5:14 PM · SecTeam-Processed, Universal Security Dashboard, Security, Security-Team
sbassett moved T377855: API list=globalblocks can reveal IP of autoblock if username and IP are included in the bgtargets parameter from Incoming to Watching on the Security-Team board.
Mon, Oct 28, 5:14 PM · SecTeam-Processed, Trust and Safety Product Sprint (Sprint Accordion October 28 - November 15), Temporary accounts (Blockers to minor pilot wiki deployment), Trust and Safety Product Team, GlobalBlocking, Security, Security-Team
sbassett updated subscribers of T378305: chart-renderer should validate idPrefix field.
Mon, Oct 28, 3:52 PM · Charts, Security
sbassett triaged T377912: Possible remote user supplied PHP class name loading (translatewiki.net) as Medium priority.
Mon, Oct 28, 3:29 PM · affects-translatewiki.net, MediaWiki-Engineering, MediaWiki-extensions-LiquidThreads, Security, Security-Team
sbassett closed T377912: Possible remote user supplied PHP class name loading (translatewiki.net) as Resolved.
Mon, Oct 28, 3:28 PM · affects-translatewiki.net, MediaWiki-Engineering, MediaWiki-extensions-LiquidThreads, Security, Security-Team
sbassett added a comment to T377912: Possible remote user supplied PHP class name loading (translatewiki.net).

This has been marked as a subtask of T375622 "Tracking bug for MediaWiki 1.39.11/1.41.5/1.42.4", but the bug does not affect any of those versions, just 1.43.

Mon, Oct 28, 3:28 PM · affects-translatewiki.net, MediaWiki-Engineering, MediaWiki-extensions-LiquidThreads, Security, Security-Team

Fri, Oct 25

sbassett added a comment to T377912: Possible remote user supplied PHP class name loading (translatewiki.net).

So where do we need to backport before then? wmf/next?

Fri, Oct 25, 9:11 PM · affects-translatewiki.net, MediaWiki-Engineering, MediaWiki-extensions-LiquidThreads, Security, Security-Team