I proposed two related patches in D25683 and D25685, both of them obsoleted by: D25687.
- Queries
- All Stories
- Search
- Advanced Search
- Transactions
- Transaction Logs
Advanced Search
Jun 18 2024
Jun 10 2024
Jun 7 2024
May 6 2024
May 5 2024
After a small database inspection, it seems that uploading the picture causes:
May 2 2024
(Oh sorry avivey, I have not noticed your priority action - I agree)
I do not (yet?) understand the use case of this task.
Indeed reported from a Wikimedia user about Wikimedia Phabricator.
Nov 26 2023
In T15671#14420, @avivey wrote:The feature was removed for performance and private concerns. I thought Gravatar was alread dead.
Maybe this can be done as an extension:
- Abstract the "profile picture provider"
- Allow an extension to write a Gravatar one
There are currently 2-3 sources, so maybe there is some abstraction:
- pokemon-style silhouette
- Character with background (generated from username)
- Upload Picture
Nov 25 2023
The feature was removed for performance and private concerns. I thought Gravatar was alread dead.
Nov 20 2023
Jul 18 2023
We can continue the discussion in Task T15556 - thanks for reporting
Jul 14 2023
Jul 9 2023
Is there a Task about this? if not, feel free to open that in Diffusion at least. I'm interested in seeing this fixed.
Ouch sorry renamed again since I forgot the discussion. Still an annoying bug and found your question.
Jun 27 2023
Jun 19 2023
Jun 3 2023
Yes. The trade off would be user experience. I have absolutely spent 15+ minutes waiting for a reset email on sites after having either typo’d or put in a different email address from the one I signed up with.
If I've understood correctly,
In T15091#9775, @RhinosF1 wrote:Can this be made public?
Can this be made public?
Closing for now as "we're ok with this", and there was no interaction on this ticket for a while.
Jun 2 2023
I wonder if this is related to not being able to use the Diffusion repository file auto-complete when not logged in even though the repo is publicly accessible.
May 27 2023
(Raising to "HIGH", until we figure out if there's a security concern).
The text says "The user who uploaded a file can always view and edit it.". I checked the DB, and the author field for the relevant file is null.
That implies that this upload code is bypassing some security checks...
May 20 2023
Thanks for this Task
May 19 2023
May 2 2023
Hi @Cigaryno thanks for this bug report. Please attach more details than feel free to reopen