Page MenuHomeMiraheze

acl*securityPolicy
ActivePublic

Members (5)

Watchers (7)

Details

Description

This project is used for access control within S2. The members of this project have access to security-sensitive tasks.

Do NOT add unauthorized members! Only members belonging to the Technical Team are allowed access. If someone else needs access to a task, please add them as a subscriber.

Recent Activity

Jun 17 2023

Paladox removed a member for acl*security: Paladox.
Jun 17 2023, 20:29

May 9 2023

Reception123 removed a member for acl*security: OrangeStar.
May 9 2023, 15:30

Mar 31 2023

Reception123 added a member for acl*security: OrangeStar.
Mar 31 2023, 05:59

Mar 17 2023

Void removed a member for acl*security: Unknown Object (User).
Mar 17 2023, 18:11
Void removed a member for acl*security: John.
Mar 17 2023, 18:11

Feb 9 2023

BrandonWM added a watcher for acl*security: BrandonWM.
Feb 9 2023, 07:11

Jul 1 2022

Reception123 removed a member for acl*security: RhinosF1.
Jul 1 2022, 17:04

Feb 21 2022

Reception123 added a member for acl*security: MacFan4000.
Feb 21 2022, 17:49

Oct 30 2021

John removed a member for acl*security: Southparkfan.
Oct 30 2021, 19:16

Oct 12 2021

Reception123 added a member for acl*security: Agent_Isai.
Oct 12 2021, 05:07

Aug 9 2021

Void added a member for acl*security: Paladox.
Aug 9 2021, 20:47
Void added a member for acl*security: John.
Aug 9 2021, 20:47

Jun 30 2021

Reception123 added a member for acl*security: Owen.
Jun 30 2021, 15:28

Jun 14 2021

Void added a member for acl*security: Void.
Jun 14 2021, 17:15
Reception123 removed a member for acl*security: Paladox.
Jun 14 2021, 17:11

May 12 2021

Amical added a project to T7278: Help with migration: acl*security.

This is the dump. Thanks in advance!{F1438957}

May 12 2021, 21:14 · MediaWiki, MediaWiki (SRE)
Reception123 added a member for acl*security: Unknown Object (User).
May 12 2021, 06:53

May 3 2021

Reception123 removed a member for acl*security: John.
May 3 2021, 16:47

Apr 3 2021

Unknown Object (User) removed a watcher for acl*security: Unknown Object (User).
Apr 3 2021, 19:51
Reception123 removed a member for acl*security: Unknown Object (User).
Apr 3 2021, 07:20

Feb 15 2021

Reception123 removed a member for acl*security: Zppix.
Feb 15 2021, 08:26

Feb 14 2021

John removed a member for acl*security: NDKilla.
Feb 14 2021, 21:56

Dec 26 2020

Reception123 edited Description on acl*security.
Dec 26 2020, 07:03

Nov 18 2020

Unknown Object (User) added a watcher for acl*security: Unknown Object (User).
Nov 18 2020, 05:06

Nov 15 2020

Reception123 added a member for acl*security: Unknown Object (User).
Nov 15 2020, 19:41

Oct 29 2020

Cocopuff2018 added a watcher for acl*security: Cocopuff2018.
Oct 29 2020, 15:07

Oct 1 2020

John changed the visibility for T6019: Improve how we handle ToU actions.
Oct 1 2020, 22:17 · Site Reliability Engineering, acl*security
John added a project to T6019: Improve how we handle ToU actions: Site Reliability Engineering.
Oct 1 2020, 22:10 · Site Reliability Engineering, acl*security
John closed T6019: Improve how we handle ToU actions as Declined.

No one has made any progress on this, and I'm unsure what such action would look like to achieve a change which wouldn't result in the response of "they were locked unfairly" when the user themselves would communicate that they were locked anyway.

Oct 1 2020, 21:59 · Site Reliability Engineering, acl*security

Aug 10 2020

Reception123 lowered the priority of T6019: Improve how we handle ToU actions from High to Normal.
Aug 10 2020, 14:35 · Site Reliability Engineering, acl*security

Aug 8 2020

Reception123 added a comment to T6019: Improve how we handle ToU actions.
In T6019#117837, @John wrote:

Best approach forwards; ALWAYS assume comments on Phabricator are public. Do not post sensitive information here.

Aug 8 2020, 11:56 · Site Reliability Engineering, acl*security
John added a comment to T6019: Improve how we handle ToU actions.

Best approach forwards; ALWAYS assume comments on Phabricator are public. Do not post sensitive information here.

Aug 8 2020, 09:44 · Site Reliability Engineering, acl*security

Aug 7 2020

Southparkfan added a comment to T6019: Improve how we handle ToU actions.

@Zppix and this is a security-sensitive task because...?
(and what are the concrete actions here?)

Aug 7 2020, 00:27 · Site Reliability Engineering, acl*security

Aug 5 2020

Zppix updated the task description for T6019: Improve how we handle ToU actions.
Aug 5 2020, 18:16 · Site Reliability Engineering, acl*security
Zppix created T6019: Improve how we handle ToU actions.
Aug 5 2020, 18:15 · Site Reliability Engineering, acl*security

Jul 1 2020

Southparkfan edited Description on acl*security.
Jul 1 2020, 21:44
Southparkfan removed a member for acl*security: Owen.
Jul 1 2020, 21:43
Southparkfan removed a member for acl*security: Void.
Jul 1 2020, 21:43
Southparkfan renamed acl*security from Security to acl*security.
Jul 1 2020, 21:41
Paladox added a project to T5543: Reconfigure SaltStack or replace it with another tool: Goal-2020-Jul-Dec.

yup! Let's make it a goal.

Jul 1 2020, 19:24 · Security, Site Reliability Engineering

Jun 30 2020

Reception123 removed a watcher for acl*security: MacFan4000.
Jun 30 2020, 16:55

Jun 28 2020

Southparkfan reassigned T5543: Reconfigure SaltStack or replace it with another tool from Southparkfan to Paladox.

@Paladox Let's replace Salt with Cumin. Not necessarily because we can't secure Salt (as long as we don't open the ports to the internet anymore, we're fine), but since Cumin offers functionality we can benefit from. Goal for Q3/Q4?

Jun 28 2020, 14:57 · Security, Site Reliability Engineering
RhinosF1 updated subscribers of T5798: Title Blacklist not taking an effect.
In T5798#113554, @Void wrote:

Can this be made public now?

Jun 28 2020, 07:44 · Security, Configuration
RhinosF1 reopened T5735: Audit user rights blacklist as "Open".

Sorry, just SocialProfile left to audit

Jun 28 2020, 07:44 · Security, Configuration
RhinosF1 closed T5735: Audit user rights blacklist as Resolved.

Closing then

Jun 28 2020, 07:43 · Security, Configuration
Void added a comment to T5798: Title Blacklist not taking an effect.

Can this be made public now?

Jun 28 2020, 02:34 · Security, Configuration
Void added a comment to T5735: Audit user rights blacklist.

We've both blacklisted titleblacklistlog and disabled the functionality of the extension that generates those logs. For future reference, the wgTitleBlacklistLogHits seems to only log titleblacklist hits that prevent account creations, which reveals the IP address that attempted to create the account. This is somewhat of an edge case, but I do not believe we will need those logs for anything, nor do I believe anyone (without an NDA) should be able to access which logs that do exist (which should only be on test2wiki right now).

Jun 28 2020, 02:33 · Security, Configuration
Paladox added a comment to T5735: Audit user rights blacklist.

viewuserlang comes from WikimediaIncubator. From the looks of it, it looks safe to me.

Jun 28 2020, 01:05 · Security, Configuration
Void closed T5798: Title Blacklist not taking an effect as Resolved.

Resolved with https://git.io/JJeFx

Jun 28 2020, 00:49 · Security, Configuration

Jun 25 2020

Paladox changed the visibility for T5797: wgManageWikiPermissionsBlacklistGroups does not prevent creation/modification of listed groups.
Jun 25 2020, 16:56 · acl*security, ManageWiki