Page MenuHomeMiraheze

Dmehus (Doug Mehus)
Steward; Trust and Safety Responder

Projects

Today

  • Clear sailing ahead.

Tomorrow

  • Clear sailing ahead.

Saturday

  • Clear sailing ahead.

User Details

User Since
Jun 7 2020, 14:12 (182 w, 3 d)
Availability
Available
IRC Nickname
dmehus
GitHub User
dmehus
Miraheze User
Dmehus [ Global Accounts ]

I am Miraheze community volunteer, primarily interested in helping to draft, fill in, and edit Miraheze Meta and global content and conduct policies. Additionally, my home wikis are chiefly Meta and Public Test Wiki. On Meta, I am active as a wiki creator, assisting new or existing fellow community users with their questions on the noticeboards and talk pages, patrolling Special:RecentChanges and Special:NewPages across namespaces, various wiki maintenance, and other wiki janitorial-type tasks and duties, the latter tasks of which largely comprise my role as a Meta administrator. On Public Test Wiki, I am a consul, having been elected by the local community, bureaucrat, and administrator where I am active in granting requests for permissions, various wiki janitorial-type tasks and duties, and continuing to fill out our content pages. Most recently, I was elected by the community to serve on the Code of Conduct Commission, which is the quasi-judicial arbitration panel to hear complaints or appeals from users that relate to the Code of Conduct global policy.

Globally, I am active as an interwiki administrator, capable of adding interwiki links to the local interwiki table on any wiki (usually following a request a the community noticeboard on Meta, but requests by Discord or IRC are also accepted as well), and, more recently, was elected as a steward, a global functionary that assists in ensuring our global policies are upheld, mediating Content Policy disputes, and fulfilling requests that can't be performing by local bureaucrats for various reasons, among other tasks and duties.

You can see my full profile at here.

Recent Activity

Jul 2 2023

Dmehus moved T11033: Wiki deletion script run from Backlog to Maintenance Script Run on the MediaWiki board.
Jul 2 2023, 21:02 · MediaWiki, Infrastructure (SRE), Database
Dmehus moved T11033: Wiki deletion script run from Incoming to Short Term on the Infrastructure (SRE) board.
Jul 2 2023, 21:02 · MediaWiki, Infrastructure (SRE), Database
Dmehus updated the task description for T11033: Wiki deletion script run.
Jul 2 2023, 21:02 · MediaWiki, Infrastructure (SRE), Database
Dmehus added projects to T11033: Wiki deletion script run: Infrastructure (SRE), MediaWiki.
Jul 2 2023, 21:01 · MediaWiki, Infrastructure (SRE), Database
Dmehus triaged T11033: Wiki deletion script run as High priority.
Jul 2 2023, 21:01 · MediaWiki, Infrastructure (SRE), Database

Jun 19 2023

Dmehus added a comment to T10931: [ACCESS REQUEST]: New access for AmandaCath.

It's for access to Github repos I believe without needing to PR something, as well as have access to all extension repos. Others would know more though.

Jun 19 2023, 00:51 · Amanda Catherine, Site Reliability Engineering

Jun 18 2023

Dmehus moved T10981: [Removal of access] for Paladox from Radar to Access on the Site Reliability Engineering board.
Jun 18 2023, 21:39 · Site Reliability Engineering
Dmehus moved T10969: [Removal of access] for Reception123 from Radar to Access on the Site Reliability Engineering board.
Jun 18 2023, 21:35 · Site Reliability Engineering
Dmehus added a comment to T10931: [ACCESS REQUEST]: New access for AmandaCath.

Note that an non-disclosure agreement is a required prerequisite before this request can even be evaluated

Actually per previous discussions with Owen via Discord, an NDA is not required for the Software Engineer position.

Jun 18 2023, 21:34 · Amanda Catherine, Site Reliability Engineering
Dmehus added a comment to T10931: [ACCESS REQUEST]: New access for AmandaCath.

Note that an non-disclosure agreement is a required prerequisite before this request can even be evaluated

Jun 18 2023, 17:33 · Amanda Catherine, Site Reliability Engineering

Jun 17 2023

Dmehus triaged T10989: Request to regenerate ManageWiki Cache for meta.miraheze.org as High priority.
Jun 17 2023, 22:38 · ManageWiki, MediaWiki, MediaWiki (SRE)
Dmehus added a comment to T10935: [ACCESS REQUEST] New access for OrangeStar.

Naleksuh was a generally globally disruptive user (particularly on Meta Wiki and Phabricator), who Stewards should've globally locked as such prior to the events getting out of hand, so I can appreciate they have a tendency to ruffle peoples' feathers and cause them to act with some degree of irrationality. As such, I can partially forgive Orange Star for that irrationality, but at the same time and given the recency of the events, we're handing a lot of significant technical access with the MWE role, it does give me pause as to consider the likelihood for similar actions, either community or technical. So, while I would not necessarily oppose this request, perhaps only weakly, at the same time, I cannot support it, either

Jun 17 2023, 18:15 · Site Reliability Engineering

Jun 12 2023

Dmehus added a comment to T10943: Take over discord tokens for relay.

@Void What did you need done on the listed Discord servers? Do you just need the Discord server administrator to re-add the new relay bot to the Discord server, or to DM you their new token? Pokey is the Discord server administrator and bureaucrat on buffalonaswiki. Not sure what his wiki username is, but on IRC he is pokey@spikeyCactus/hoosky. :)

Jun 12 2023, 12:01 · Infrastructure (SRE)

Jun 11 2023

Dmehus added a comment to T10926: Consider dropping orain.org domains.

Cloudflare also has a domain registrar business that is independent and segregated from the rest of their business; you don't have to subscribe to other services. Where possible, I register all my domains with Cloudflare as they give you the wholesale registration cost (i.e., what the domain registry charges) with zero registrar markup + the $0.18 per year ICANN fee. Where they don't support a specific TLD, I use Google Domains; they're not the cheapest, but the service is great and they're reliable.

Jun 11 2023, 04:42 · Site Reliability Engineering
Dmehus updated subscribers of T10931: [ACCESS REQUEST]: New access for AmandaCath.
Jun 11 2023, 04:17 · Amanda Catherine, Site Reliability Engineering

May 22 2023

Dmehus added a comment to T10568: Allow OS requests to be made through TSPortal.

I would probably suggest keeping this separate from the actual TSportal. That being said, I think the TSportal codebase could be forked to provide a separate OSrequests portal. Ideally, I would prefer TSportal to be moved to a more specific subdomain, perhaps tsreports.miraheze.org, and then the OSrequests portal could live at osrequests.miraheze.org (or something like that). You get the idea. But in general, I like the idea of using this for OS requests. :)

May 22 2023, 22:26 · MediaWiki (SRE), TSPortal
Dmehus triaged T10858: Image thumbnails not loading on arboretumfictoria.miraheze.org as Normal priority.
May 22 2023, 03:21 · MediaWiki, MediaWiki (SRE)
Dmehus added a project to T10861: Cannot load pages on private wiki "My Apartment Manager is not an Isekai Character": MediaWiki.
May 22 2023, 03:20 · MediaWiki, MediaWiki (SRE)
Dmehus closed T10861: Cannot load pages on private wiki "My Apartment Manager is not an Isekai Character" as Invalid.

It sounds like a caching and/or cookie issue as Agent Isai suggests. Somewhat boldly closing this.

May 22 2023, 03:20 · MediaWiki, MediaWiki (SRE)
Dmehus closed T10860: Please enable cargo as Declined.

@Agent_Isai can correct me if my information is out of date, or can add information, but I believe the Cargo extension is disabled due to security issues.

May 22 2023, 03:19 · MediaWiki (SRE), Extensions
Dmehus triaged T10864: Request to change wiki (domain) link as Normal priority.

Confirmed wiki database name does not exist, so triaged this. Your request is in the queue.

May 22 2023, 03:17 · MediaWiki (SRE), Database

Aug 1 2022

Dmehus moved T9613: Add file upload utility to TSportal from Backlog to Internal on the Trust & Safety board.
Aug 1 2022, 21:39 · TSPortal, Trust & Safety
Dmehus triaged T9613: Add file upload utility to TSportal as Normal priority.
Aug 1 2022, 21:39 · TSPortal, Trust & Safety
Dmehus added a comment to T9457: Review wma.wmcloud.org CSP entry.

Given that according to the Wikimedia Cloud Services Terms of Use as well as various Wikimedia Cloud Services/Toolforge-hosted project website/wiki footers state they are not subject to the Wikimedia Terms of Use and Wikimedia Privacy Policy, I suspect this the main reason why this entry was referred for a CSP review. @Reception123, I'm not sure at what stage SRE is at in in terms of its part of the CSP review, so will defer to you until your processes have been completed. If it progresses to the T&S stage, I'm happy to review this further.

Aug 1 2022, 21:17 · MediaWiki (SRE), Trust & Safety, CSP Review

Jul 30 2022

Dmehus awarded T9500: Retention of UserBoard data as part of the SocialProfile extension a Like token.
Jul 30 2022, 21:15 · RemovePII, MediaWiki (SRE), Trust & Safety, Security
Dmehus added a comment to T9500: Retention of UserBoard data as part of the SocialProfile extension.
In T9500#193867, @Universal_Omega wrote:
Jul 30 2022, 21:15 · RemovePII, MediaWiki (SRE), Trust & Safety, Security

Jul 7 2022

Dmehus updated the task description for T9500: Retention of UserBoard data as part of the SocialProfile extension.
Jul 7 2022, 02:59 · RemovePII, MediaWiki (SRE), Trust & Safety, Security
Dmehus created T9500: Retention of UserBoard data as part of the SocialProfile extension.
Jul 7 2022, 02:57 · RemovePII, MediaWiki (SRE), Trust & Safety, Security

Jul 3 2022

Dmehus awarded T9268: [Existing] Server Resource Request for db112 a Haypence token.
Jul 3 2022, 01:57 · Infrastructure (SRE)

Jun 20 2022

Dmehus awarded T9421: MirahezeRC has disconnected a Like token.
Jun 20 2022, 07:42 · Monitoring, Infrastructure (SRE)
Dmehus moved T9421: MirahezeRC has disconnected from Incoming to Short Term on the Infrastructure (SRE) board.
Jun 20 2022, 04:52 · Monitoring, Infrastructure (SRE)
Dmehus triaged T9421: MirahezeRC has disconnected as Normal priority.
Jun 20 2022, 04:52 · Monitoring, Infrastructure (SRE)

Jun 11 2022

Dmehus added a comment to T9324: Fixing automatic import summary for bnwikiwiki.

I think I know what might be happening. @MdsShakil, did you tick the box to locally assign edits where the user exists locally or no? If not, think this is a bug with non-English (more specifically, non-Latin character wikis) in translating the User: namespace, which is মডিউল: on this wiki. For users with Bengali script usernames, there's no issue and their edits would be locally assigned. For users without Latin script usernames, such as MusikAnimal in the first case, there's likely an issue. Of course, this is all dependent on whether or not MdsShakil locally assigned edits. If he did not, then that is the issue. If he did, then my likely theory is the issue, which would make this an upstream bug (assuming to be MediaWiki core, since Special:Import is part of MediaWiki, as far as I'm aware).

Jun 11 2022, 21:19 · MediaWiki (SRE), MediaWiki

Jun 6 2022

Dmehus awarded T9314: Wiki Rename a Like token.
Jun 6 2022, 06:37 · MediaWiki, Database, MediaWiki (SRE)
Dmehus added a comment to T9309: Increase Roundcube session timeout.
In T9309#189235, @Universal_Omega wrote:
In T9309#189233, @Universal_Omega wrote:

I've changed the PR back to 24 hours.

Cool. Thanks! :)

Can any SRE team member approve this, or does it need an EM?

I don't know. Technically this falls under infrastructure, I just decided to do it because I could, I think paladox said to raise to 24 hours needed some discussion so potentially needs EM approval here.

Jun 6 2022, 06:36 · Mail, Infrastructure (SRE)
Dmehus added a comment to T9309: Increase Roundcube session timeout.

This is funny because I was also considering opening a task for this since it's quite annoying to have to log in multiple times per day.

On the technical side however, if Paladox said it needed discussion I'd like his opinion before going forward with this.

Jun 6 2022, 06:35 · Mail, Infrastructure (SRE)
Dmehus added a comment to T9309: Increase Roundcube session timeout.
In T9309#189233, @Universal_Omega wrote:

I've changed the PR back to 24 hours.

Jun 6 2022, 03:37 · Mail, Infrastructure (SRE)
Dmehus added a comment to T9337: Import for [Mandapedia].

@Reception123 I'd recommend T9345 be done first before importing, given you will need to the interwiki prefix for the new subdomain and that will be its new address.

Jun 6 2022, 03:36 · MediaWiki (SRE), MediaWiki
Dmehus added a comment to T9309: Increase Roundcube session timeout.
In T9309#188591, @Universal_Omega wrote:

I've updated the above PR to 12 hours, as I don't really see a need to up it all the way to 24 hours.

Jun 6 2022, 03:29 · Mail, Infrastructure (SRE)
Dmehus added a comment to T9309: Increase Roundcube session timeout.
In T9309#188570, @Universal_Omega wrote:

It is now one hour but we can consider 24 hours, but that needs some discussion.

Jun 6 2022, 03:28 · Mail, Infrastructure (SRE)
Dmehus added a comment to T9346: Rename Phabricator user Mandapedia001 to Mandaepedia001.

In all likelihood @Reception123 will end up claiming this task, but, of course, others are welcome to as well. :)

Jun 6 2022, 03:25 · Infrastructure (SRE), Phabricator
Dmehus updated subscribers of T9346: Rename Phabricator user Mandapedia001 to Mandaepedia001.
Jun 6 2022, 03:15 · Infrastructure (SRE), Phabricator
Dmehus triaged T9346: Rename Phabricator user Mandapedia001 to Mandaepedia001 as Normal priority.
Jun 6 2022, 03:14 · Infrastructure (SRE), Phabricator
Dmehus updated subscribers of T9345: Rename mandapediawiki to mandaepediawiki.
Jun 6 2022, 03:11 · Database, MediaWiki (SRE), MediaWiki
Dmehus moved T9345: Rename mandapediawiki to mandaepediawiki from Backlog to Short Term on the MediaWiki (SRE) board.
Jun 6 2022, 03:11 · Database, MediaWiki (SRE), MediaWiki
Dmehus triaged T9345: Rename mandapediawiki to mandaepediawiki as Normal priority.
Jun 6 2022, 03:10 · Database, MediaWiki (SRE), MediaWiki
Dmehus added a watcher for Database: Dmehus.
Jun 6 2022, 03:07

May 30 2022

Dmehus claimed T9295: Adding a TXT record for rct.wiki.

I can do this task in the next several days, if that's okay?

May 30 2022, 07:32 · Infrastructure (SRE), DNS
Dmehus moved T9309: Increase Roundcube session timeout from Incoming to Short Term on the Infrastructure (SRE) board.
May 30 2022, 07:30 · Mail, Infrastructure (SRE)
Dmehus triaged T9309: Increase Roundcube session timeout as Normal priority.
May 30 2022, 07:30 · Mail, Infrastructure (SRE)
Dmehus added a comment to T9257: Change the source of reCAPTCHA to enable users in mainland of China to register accounts.

Last time we used recaptcha.net was a mess because ReCAPTCHA returned lower scores than it would if we used google.com. There was no observable improvement at all and instead just a deterioration in CAPTCHA service. I would suggest a limited test for a day or two to see if rolling back to using recaptcha.net causes the huge issues it did last time.

May 30 2022, 04:35 · Universal Omega, Extensions, MediaWiki (SRE)
Dmehus added a comment to T9257: Change the source of reCAPTCHA to enable users in mainland of China to register accounts.
In T9257#188481, @Universal_Omega wrote:

When checking LocalSettings.php, I also saw what looked like a config saying we're still on ReCaptcha 3.0. Is that the case? If so, I thought we were going to roll back to ReCaptcha 2.0 because of similar, but unrelated issues?

We are not rolling back to version 2, as far as I know.

May 30 2022, 04:32 · Universal Omega, Extensions, MediaWiki (SRE)
Dmehus added a comment to T8801: Formalise and agree on Infrastructure SLOs.

Has there been any more discussion among SRE team members with regard to agreeing on SLOs for the above?

May 30 2022, 04:30 · Goal-2022-Jul-Dec, Goal-2022-Jan-Jun, Infrastructure (SRE)
Dmehus lowered the priority of T9301: JobQueue spiralling out of control (Late May 2022) from Unbreak Now! to High.

This is definitely a high priority issue, but I feel that unless we can resolve something that is unbreak now within 24 hours or or less, we should use High. Lowering to High on that basis, but @Reception123 or another MWE can feel free to raise to UBN if preferred

May 30 2022, 04:28 · MediaWiki, MediaWiki (SRE)
Dmehus raised the priority of T9257: Change the source of reCAPTCHA to enable users in mainland of China to register accounts from Normal to High.

Increasing priority to match merged in ticket T9307.

May 30 2022, 04:25 · Universal Omega, Extensions, MediaWiki (SRE)
Dmehus added a comment to T9257: Change the source of reCAPTCHA to enable users in mainland of China to register accounts.
In T9257#188474, @Universal_Omega wrote:

No test pattern needed. It's confirmed it is the issue, and I've suspected it is for awhile now.

It definitely is, we've known for months also, but last time we tried it it caused even more issues for everyone else, as it returned lower scores.

May 30 2022, 04:25 · Universal Omega, Extensions, MediaWiki (SRE)
Dmehus claimed T9308: Remove matomo special page in worldbox.wiki.
May 30 2022, 03:26 · Configuration, MediaWiki (SRE)
Dmehus added a comment to T9257: Change the source of reCAPTCHA to enable users in mainland of China to register accounts.
In T9257#187879, @Universal_Omega wrote:

I think perhaps an easier idea would be to try to restore recaptcha.net for a day or so and closely monitor the situation.

I would say 2 days, 1 day and it'd be hard to tell. 2 days and we can gather the patterns if we get more users unable to register etc... after 2 days then we immediately revert the change and consider other alternatives.

Yeah, 2 days is a better option. Though I think if we see like 10 times the amount of people using the form after a day it would probably indicate that recaptcha.net is the issue

May 30 2022, 03:21 · Universal Omega, Extensions, MediaWiki (SRE)
Dmehus added a comment to T9257: Change the source of reCAPTCHA to enable users in mainland of China to register accounts.

I think perhaps an easier idea would be to try to restore recaptcha.net for a day or so and closely monitor the situation.

May 30 2022, 03:17 · Universal Omega, Extensions, MediaWiki (SRE)
Dmehus updated the task description for T9307: Requesting reversion of reCAPTCHA verification domain (from google.com back to recaptcha.net).
May 30 2022, 03:08 · MediaWiki (SRE), MediaWiki
Dmehus updated the task description for T9307: Requesting reversion of reCAPTCHA verification domain (from google.com back to recaptcha.net).
May 30 2022, 03:07 · MediaWiki (SRE), MediaWiki
Dmehus added projects to T9307: Requesting reversion of reCAPTCHA verification domain (from google.com back to recaptcha.net): MediaWiki, MediaWiki (SRE).
May 30 2022, 03:06 · MediaWiki (SRE), MediaWiki
Dmehus triaged T9307: Requesting reversion of reCAPTCHA verification domain (from google.com back to recaptcha.net) as High priority.
May 30 2022, 03:05 · MediaWiki (SRE), MediaWiki

May 26 2022

Dmehus added a comment to T9214: Allow LucidChart iframes in CSP.

Please can I have an update on this?

Sorry for the delay, I have now reviewed the website and the next step will be for our Trust & Safety team to review it.

(Comments: lucidapp.com/lucid.co seems to generally adhere to our checklist and there don't seem to be any particular issues, so this should be good to approve). Passing onto T&S for review.

May 26 2022, 06:24 · Trust & Safety, CSP Review, MediaWiki (SRE)
Dmehus added a comment to T9252: bilibili.com CSP whitelist.

Since the initial CSP review has been done by a non-SRE user, I will comment on my additional findings.

  • Regarding GDPR, I don't see any specific mentions of GDPR being complied with but relevant elements seem to exist. I'm not sure whether that's enough?
  • Regarding whether measures to protect security are described, it seems like there is a relatively detailed paragraph explaining

Overall, it seems like while Bilbili may have had some problems in the past, it has (as far as I can see) not had any clear issues with reputation, etc. and generally the privacy policy seems appropriate. The main issue would be whether them not specifically making mention of the GDPR would be an issue. I will transfer this to Trust & Safety for the next step, especially to review the GDPR aspect. I would likely say though that on the 'approval' scale, this website would likely be on the lower end.

May 26 2022, 05:56 · Trust & Safety, CSP Review, MediaWiki (SRE)
Dmehus added a comment to T9279: Fix stuck global rename for Vardan97.

Thanks. :)

May 26 2022, 05:43 · MediaWiki, MediaWiki (SRE)
Dmehus awarded T9279: Fix stuck global rename for Vardan97 a Like token.
May 26 2022, 05:43 · MediaWiki, MediaWiki (SRE)
Dmehus moved T9278: Run refreshLinks.php on Category:Pages with broken file links for obeymewiki from Backlog to Maintenance Script Run on the MediaWiki board.

SRE will action this request as soon as they are able to do so. Thank you for your patience and understanding.

May 26 2022, 05:37 · MediaWiki (SRE), MediaWiki
Dmehus moved T9278: Run refreshLinks.php on Category:Pages with broken file links for obeymewiki from Backlog to Short Term on the MediaWiki (SRE) board.
May 26 2022, 05:37 · MediaWiki (SRE), MediaWiki
Dmehus added projects to T9278: Run refreshLinks.php on Category:Pages with broken file links for obeymewiki: MediaWiki, MediaWiki (SRE).
May 26 2022, 05:36 · MediaWiki (SRE), MediaWiki
Dmehus triaged T9278: Run refreshLinks.php on Category:Pages with broken file links for obeymewiki as Normal priority.
May 26 2022, 05:36 · MediaWiki (SRE), MediaWiki
Dmehus moved T9279: Fix stuck global rename for Vardan97 from Backlog to Short Term on the MediaWiki (SRE) board.
May 26 2022, 02:22 · MediaWiki, MediaWiki (SRE)
Dmehus moved T9279: Fix stuck global rename for Vardan97 from Backlog to Maintenance Script Run on the MediaWiki board.
May 26 2022, 02:21 · MediaWiki, MediaWiki (SRE)
Dmehus triaged T9279: Fix stuck global rename for Vardan97 as High priority.
May 26 2022, 02:21 · MediaWiki, MediaWiki (SRE)

May 2 2022

Dmehus added a comment to T9169: [ACCESS REQUEST] New access for Agent.

After discussing with John, I've decided to approve this request and that it could be helpful for Agent to be able to access such logs in his role as CSE, especially since sometimes more technically-able users ask for the backtraces so they can debug things.

May 2 2022, 06:50 · Site Reliability Engineering
Dmehus added a comment to T9169: [ACCESS REQUEST] New access for Agent.

So my understanding is that this is an unsolicited nomination by @RhinosF1. As a personal best practice, I do strongly recommend nominators obtain the nominees consent before nominating them. There's no reason not to.

This was discussed on IRC

May 2 2022, 00:03 · Site Reliability Engineering

May 1 2022

Dmehus added a comment to T9169: [ACCESS REQUEST] New access for Agent.

So my understanding is that this is an unsolicited nomination by @RhinosF1. As a personal best practice, I do strongly recommend nominators obtain the nominees consent before nominating them. There's no reason not to.

May 1 2022, 20:16 · Site Reliability Engineering

Apr 24 2022

Dmehus claimed T9127: Investigate why spam blacklist hits are not logged.
Apr 24 2022, 16:46 · Configuration, MediaWiki (SRE)
Dmehus updated the task description for T9127: Investigate why spam blacklist hits are not logged.
Apr 24 2022, 16:32 · Configuration, MediaWiki (SRE)
Dmehus moved T9127: Investigate why spam blacklist hits are not logged from Backlog to Short Term on the MediaWiki (SRE) board.
Apr 24 2022, 16:32 · Configuration, MediaWiki (SRE)
Dmehus moved T9127: Investigate why spam blacklist hits are not logged from Backlog to In Progress on the Configuration board.
Apr 24 2022, 16:32 · Configuration, MediaWiki (SRE)
Dmehus triaged T9127: Investigate why spam blacklist hits are not logged as High priority.
Apr 24 2022, 16:31 · Configuration, MediaWiki (SRE)

Apr 19 2022

Dmehus awarded T9098: Create an ImportDump Phabricator tag a Like token.
Apr 19 2022, 05:30 · MediaWiki (SRE), Phabricator

Apr 17 2022

Dmehus added a comment to T9061: CreateRedirect has weak (no?) permissions checks.
In T9061#184218, @Universal_Omega wrote:

I was directed to this task over IRC. It appears to already be closed, and have little relevance to me at all. What is going on here?

You must've been directed to the wrong task, I'd assume? T9071 is probably what they meant to direct you to, I'm assuming, based off conversation I have observed. But that task is currently private.

Apr 17 2022, 07:29 · Extensions, Trust & Safety, MediaWiki (SRE), Security
Dmehus added a comment to T9061: CreateRedirect has weak (no?) permissions checks.

I mentioned the CreateRedirect error on its talk page (sorry, I didn't realise this was a hidden security task! I shouldn't've advertised it publicly), and it looks like the issue has been fixed: https://gerrit.wikimedia.org/r/c/mediawiki/extensions/CreateRedirect/+/780567

Apr 17 2022, 04:36 · Extensions, Trust & Safety, MediaWiki (SRE), Security
Dmehus added a comment to T9061: CreateRedirect has weak (no?) permissions checks.
In T9061#184209, @Universal_Omega wrote:

No problem.

@Dmehus: any issues to making public?

No objections if @John and @Owen have no issues making it public

It already is now.

Apr 17 2022, 04:32 · Extensions, Trust & Safety, MediaWiki (SRE), Security
Dmehus added a comment to T9061: CreateRedirect has weak (no?) permissions checks.

@Samwilson: It looks like create redirect is at fault. I can move the Main_Page without being able to edit it and the user used that. It looks like you are one of 2 project members. Can you look into this?

Apr 17 2022, 04:31 · Extensions, Trust & Safety, MediaWiki (SRE), Security
Dmehus updated subscribers of T9061: CreateRedirect has weak (no?) permissions checks.

No problem.

@Dmehus: any issues to making public?

Apr 17 2022, 04:26 · Extensions, Trust & Safety, MediaWiki (SRE), Security
Dmehus updated Dmehus.
Apr 17 2022, 04:13
Dmehus added a comment to T9079: 16 April 2022 DoS.

logs just need backing up and then we call this resolved. usual are aware and @Owen pinged for release.

Apr 17 2022, 04:09 · Trust & Safety, Monitoring, NGINX, Infrastructure (SRE)
Dmehus awarded T8885: Add farmer log filter option to CreateWiki extension a Like token.
Apr 17 2022, 04:06 · CreateWiki, MediaWiki (SRE)

Apr 16 2022

chrs awarded T8885: Add farmer log filter option to CreateWiki extension a Like token.
Apr 16 2022, 15:38 · CreateWiki, MediaWiki (SRE)

Apr 14 2022

Dmehus awarded T8835: Do something about bots hitting special pages a Dat Boi token.
Apr 14 2022, 04:24 · MediaWiki (SRE), MediaWiki

Apr 13 2022

Dmehus added a comment to T9058: Consider creating a documentation tag on Phabricator.
In T9058#183674, @John wrote:

Incident Reports and CVEs should be tracked as part of the original task, not requiring an additional task as until necessary follow up reports and learning is done, an incident shouldn’t be deemed resolved.

For protracted cases, a workboard column may be more appropriate than a tag.

Apr 13 2022, 02:08 · Site Reliability Engineering, Phabricator

Apr 12 2022

Dmehus added a comment to T9061: CreateRedirect has weak (no?) permissions checks.

@Dmehus

  1. It is yes, this can be seen via LS.php
  2. Is set to true by default and unmodified for MH
  3. Yes, 'mhglobal' is the global blocking DB
  4. Those are the only two settings we have different than the defaults.
Apr 12 2022, 01:38 · Extensions, Trust & Safety, MediaWiki (SRE), Security
Dmehus added a comment to T9061: CreateRedirect has weak (no?) permissions checks.

The issue will have to be tested on a test wiki by applying a global block to an IP and identifying potential extensions and them being disabled/enabled until we can conclude which one is causing it.

Apr 12 2022, 01:37 · Extensions, Trust & Safety, MediaWiki (SRE), Security
Dmehus added a comment to T9058: Consider creating a documentation tag on Phabricator.

While there's not that many documentation tasks I feel like it might be a sensible idea to start creating tasks for specific areas that need documentation as it's clear the current system where there's minimal tracking of docs and no one specifically assigned to work on doc X doesn't work. If we want to go this route and have tasks for areas that need docs/docs that need modifying then I'd agree with creating a tag to go along with it.

@John Any objections?

Apr 12 2022, 01:31 · Site Reliability Engineering, Phabricator
Dmehus awarded T9058: Consider creating a documentation tag on Phabricator a Like token.
Apr 12 2022, 01:28 · Site Reliability Engineering, Phabricator

Apr 11 2022

Dmehus awarded rDNSfc6ba6dfc9ec: T9054: Remove hypotheticalhurricanes.com zone (#265) a Like token.
Apr 11 2022, 06:48
Dmehus updated the task description for T9061: CreateRedirect has weak (no?) permissions checks.
Apr 11 2022, 04:10 · Extensions, Trust & Safety, MediaWiki (SRE), Security