[02:58:48] lol, i got a console warning saying that miraheze.org could be a bounce tracker [02:58:51] https://firefox-source-docs.mozilla.org/toolkit/components/antitracking/anti-tracking/bounce-tracking-protection/index.html [03:31:27] Bounce tracker ? [03:31:42] apparently some sort of tracker that relies on redirects? [03:31:52] Huh [03:40:25] I wonder what's causing that, I'd guess something with interwiki or redirection from top level > mainpage and our logging. [03:50:17] maybe sul2? [03:50:36] funny enough, i got that warning while i was on phorge of all places [11:14:37] @blankeclair you are an angel for T13428 [11:15:00] you're welcome <3 [11:15:22] Hmmm..... [11:15:25] Access denied.... [11:16:02] I wonder what CVE number it'll be. [11:17:14] CVE-2025-6969 [11:18:28] Ahh, the fated UserLogin XSS by typing in aklapper's name three times and putting a script in the password reset screen [13:59:34] pre condition being that you must _not_ have brought a goat sacrifice with you [14:55:20] Ah dangnamit. [21:09:54] @rhinosf1 uuuuh can we action https://issue-tracker.miraheze.org/T13431 [21:12:09] PrivateSettings.php [21:12:34] i've noticed an api key variable in the ED config for a wiki already [21:13:08] and if we can't do PrivateSettings.php, perhaps a per-wiki managewiki/settings hack with a restricted visibility [21:14:32] i thought we had a way to do private settinfs [21:14:43] or are webhooks for discord notifs public [21:17:08] Replied [21:17:17] They are not [21:17:23] We can do private in ManageWiki [21:17:25] Thought so [21:17:28] Okay cool [21:17:33] I wanna understand the use case though [21:17:53] They look like read only apis for accessing public services [21:18:10] Rate limits maybe? [21:18:11] So might be able to use 1 key farm wide [21:18:22] Something to know [21:18:38] in ManageWiki = users responsible to rotate in an incident etc [21:18:46] In PS.php = our problem [21:18:56] Also good morning @blankeclair [21:19:20] How? [21:19:39] Something in ManageWikiSettings.php [21:20:06] I dont think we can. We can restrict from editing per permission but there's no way to hide them from showing iirc? [21:20:44] Example https://github.com/miraheze/mw-config/blob/master/ManageWikiSettings.php#L2170 [21:20:47] @originalauthority ^ [21:20:52] Ye we can [21:20:54] And we do it [21:21:00] And it's had a few CVEs [21:21:09] Huh wyf [21:21:14] I've never noticed that before [21:22:07] Maybe I should ask @blankeclair to security review and find another few CVEs before we add anything more [21:22:19] I guess you learn every day [21:22:23] [1/2] mornyan~ [21:22:23] [2/2] https://catgirl.center/notes/a5tur7rk4stf0tx6 is a mood [21:22:50] sec rev managewiki? [21:23:09] Just the visibility function of ManageWikiSettings [21:23:16] I have waiting mode [21:23:19] sounds like a mw sec rev lol [21:23:20] It's not too bad [21:23:28] But I do that a lot [21:23:43] It takes me time to get in the zone [21:24:15] I am often early [21:24:30] I'm either early or late [21:24:34] I don't do on time [21:24:52] I'm either early cause I've been in waiting mode or late because I haven't sat down for 3 hours @blankeclair [21:27:26] what [21:27:40] Ye [21:28:16] Well 1 [21:28:18] CVE-2021-29483 [21:33:52] omg why is my fedi instance accessible at school [21:33:54] i'm dying lmfao [22:00:06] @pixldev I think Zotero is fine for MWS.php [22:00:12] Based on the use case [22:00:16] The other one public [22:00:32] PS [22:07:04] @pixldev are you offering to do that bit? [22:08:38] Never said that [22:08:47] I have someone i can throw at it [22:08:54] can ask [22:14:04] You asked if we can action it so I assumed you wanted to [22:17:26] I mean we as a group technically [22:17:48] i pretend to be part of tech [22:19:54] You're just missing a few buttons [22:20:14] I will finish the separating beta task at some point [22:20:20] Then we can make you have beta shell [22:20:44] I will try to finish that task before you turn 18 @pixldev [22:20:54] How long do I have [23:04:31] is anyone ssh'd in atm on mwtask heh [23:05:12] i cba to log in but I merged Claire's patch for UPV2 so once its pulled the task can be closed and I cba to boot my mac heh