TL;DR: Should we merge https://gerrit.wikimedia.org/r/#/c/165979/ and
release it with MediaWiki 1.24?
A lot of sites have used MediaWiki:Common.js and MediaWiki:Common.css to
customize the appearance of their site.
In a recent security release[1], support for JS and CSS with on-wiki
origins was removed from being displayed on the Special:Login and
Special:Preferences page.
Because of how the on-wiki MediaWiki:Common.* pages are used and the
access restrictions on them, I think it is reasonable to allow JS and
CSS from them while continuing to disallow individual's JS and CSS on
the Special:Preferences and Special:Login page.
Alexia filed a bug[2] and Kunal (Legoktm) has provided a patch[3] to allow
site-wide styling back on those pages.
I'd like to merge this, but I want some input from the community and
security people before I do that.
Thanks,
Mark.
(Reply-to set to mediawiki-l.)
Footnotes:
[1] https://bugzilla.wikimedia.org/70672
[2] https://bugzilla.wikimedia.org/71621
[3] https://gerrit.wikimedia.org/r/#/c/165979/
--
Mark A. Hershberger
NicheWork LLC
717-271-1084
A few of us wiki enthusiasts started an informal organization with the
intent of coordinating periodic meet-ups, sharing open-source MediaWiki
extensions, and soliciting collaboration in new development beneficial for
those of us using MediaWiki in a corporate environment.
We are working on setting up an event the afternoon of Monday December 1st
in Houston. Before we finalize the location, we need to get an idea of how
many people intend to attend.
Some items we are considering for the agenda include:
- Hands-on demo of Visual Editor
- Discuss what's new in MediaWiki 1.24
- The history of the NASA wiki and how we use Meeting Minutes to reduce
email
- Share some of the extensions we have developed to better suit
MediaWiki for corporate use
If you or anyone else you know would be interested in attending this
meet-up, please email back with names and email addresses so we can
coordinate.
Thanks!
Daren and James
Hello everyone,
The prior maintenance release announcement email titled
MediaWiki Security and Maintenance Releases: 1.23.6, 1.22.13 and 1.19.21
included the word "Security" in the subject. This inclusion was a
mistake. There are no security fixes included in these releases.
Best,
Mark A. Hershberger
(Wiki Release Team)
Hello everyone,
This is a notice that on Wednesday, October 28, 2014, between
20:00-22:00 UTC, we will release maintenance updates for current and
supported branches of the MediaWiki software. Downloads and patches will
be available at that time.
Best,
Mark. A. Hershberger
(Wiki Release Team)