On Wed, May 28, 2008 at 8:22 AM,
<werdna(a)svn.wikimedia.org> wrote:
+ // We expect at least one
permissions error, because we're trying to do an action on a specialpage.
+ return count($this->getTitle()->getUserPermissionsErrors(
'centralauth-merge', $user ))<=1;
This is horrible. Why is it that we use a whitelist of allowed
actions for special pages instead of a blacklist?
Because it's easier to whitelist a few known actions than to blacklist
quadrillions of possible character combinations?
Not sure what you're getting at... :)
- -- brion
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.8 (Darwin)
Comment: Using GnuPG with Mozilla -
http://enigmail.mozdev.org
iEYEARECAAYFAkg9h5AACgkQwRnhpk1wk46LYQCfaoPxdJnC+qV5/c77mi+fE1gn
DcYAn3C4F6u8Y7kCLGuH44G3rMH/+8Xj
=cWNw
-----END PGP SIGNATURE-----