T121240
|
T121240: Network isolation for production and semi-production services
|
open
|
Medium (orange)
|
GWicke (Gabriel Wicke)
|
|
|
|
|
T140813
|
T140813: Protect sensitive user-related information with a UserData / auth / session service
|
open
|
Medium (orange)
|
GWicke (Gabriel Wicke)
|
|
|
|
|
T152972
|
T152972: Accessing private information through SecurePoll should be logged
|
open
|
Needs Triage (violet)
|
Huji (Huji Lee)
|
|
|
|
|
T169328
|
T169328: Protect against PHP code execution via memcached/unserialize
|
open
|
Medium (orange)
|
daniel (Daniel Kinzler)
|
daniel (Daniel Kinzler)
|
|
|
|
T189641
|
T189641: Service for checking the Pwned Passwords database
|
open
|
Low (yellow)
|
Tgr (Gergő Tisza)
|
|
|
|
|
T208188
|
T208188: RFC: Partial opt-out method for Content security policy
|
open
|
Medium (orange)
|
Bawolff (Brian Wolff)
|
|
|
|
|
T236701
|
T236701: Consider enforcing read permissions at the storage layer
|
open
|
Medium (orange)
|
daniel (Daniel Kinzler)
|
|
|
|
|
T241039
|
T241039: Create an API for sending yourself an arbitrary HTML email
|
open
|
Medium (orange)
|
Tgr (Gergő Tisza)
|
|
|
|
|
T255370
|
T255370: Document best practices for user login if user is using 2FA
|
open
|
Low (yellow)
|
Reedy (Sam Reed)
|
|
|
|
|
T256535
|
T256535: Same-Origin policy prevents reading HTML pages cross-origin
|
open
|
Medium (orange)
|
dbarratt (David Barratt)
|
|
|
|
|
T258322
|
T258322: Open redirect in wikis that use http://domain.tld/index.php format
|
open
|
Low (yellow)
|
Reedy (Sam Reed)
|
|
|
|
|
T261050
|
T261050: Frequent "Invalid CSRF token" errors on Wikimedia projects using Pywikibot since August 2020
|
open
|
High (red)
|
Multichill (Maarten Dammers)
|
|
|
|
|
T263220
|
T263220: Limit concurrency of DPL queries
|
open
|
High (red)
|
Urbanecm
|
|
|
|
|
T263927
|
T263927: MediaWiki user and password fields should have the proper autocomplete value
|
open
|
Needs Triage (violet)
|
Tgr (Gergő Tisza)
|
|
|
|
|
T284274
|
T284274: action=history with a high limit like >= 2000, can be slow and might timeout
|
open
|
Needs Triage (violet)
|
Legoktm (Legoktm)
|
|
|
|
|
T32018
|
T32018: Require some user groups to have a periodically confirmed valid email address
|
open
|
Lowest (sky)
|
bzimport (bugzilla import bot)
|
|
|
|
|
T6845
|
T6845: CAPTCHA doesn't work for people with visual impairments
|
open
|
Medium (orange)
|
tstarling (Tim Starling)
|
DrMel (Dr Mel Ganus (z))
|
|
|
|