Page MenuHomePhorge
Feed All Stories

Dec 7 2024

speck added a comment to T15965: Repository Identity "Automatically Detected User": it reads unverified emails, with spam concerns.

What can a malicious user accomplish by claiming unverified email for commits? The idea outlined here sounds right but I’d like to understand what potential harm could be done on its current state, and also whether there’s any legitimate use case for the current behavior.

Dec 7 2024, 16:10 · Spam mitigation, Diffusion, Security
taavi created T15970: phurl: Allow setting default edit policy for URLs.
Dec 7 2024, 11:26 · Policy, Feature Requests

Dec 6 2024

aklapper closed T15968: Unit test PhabricatorAuthInviteTestCase::testDuplicateInvite fails, a subtask of T15064: Make Phorge compatible with PHP 8.1/8.2/8.3/8.4, as Resolved.
Dec 6 2024, 12:17 · PHP 8 support
aklapper closed D25848: Fix PhabricatorAuthInviteTestCase::testDuplicateInvite unit test.
Dec 6 2024, 12:17
aklapper closed T15968: Unit test PhabricatorAuthInviteTestCase::testDuplicateInvite fails as Resolved by committing rARCabda70208340: Fix PhabricatorAuthInviteTestCase::testDuplicateInvite unit test.
Dec 6 2024, 12:17 · PHP 8 support
aklapper committed rARCabda70208340: Fix PhabricatorAuthInviteTestCase::testDuplicateInvite unit test.
Dec 6 2024, 12:17
valerio.bozzolan closed D25844: Add first unit test for mimemailparser headers.
Dec 6 2024, 12:13
valerio.bozzolan committed rP9d3e25885335: Add first unit test for mimemailparser headers.
Dec 6 2024, 12:12
valerio.bozzolan accepted D25848: Fix PhabricatorAuthInviteTestCase::testDuplicateInvite unit test.

Double slam-accept

Dec 6 2024, 12:12
aklapper updated the diff for D25849: Hovercards: Avoid "Undefined index: objectPHID" when passing bogus data.

Right... one day I may get used to all those Phorge shortcuts, thanks

Dec 6 2024, 11:58
aklapper updated the diff for D25848: Fix PhabricatorAuthInviteTestCase::testDuplicateInvite unit test.

Oops, no for real

Dec 6 2024, 11:49
aklapper updated the diff for D25848: Fix PhabricatorAuthInviteTestCase::testDuplicateInvite unit test.

Uhm, right, heh

Dec 6 2024, 11:48

Dec 5 2024

valerio.bozzolan accepted D25849: Hovercards: Avoid "Undefined index: objectPHID" when passing bogus data.

...like line 105 :)

Dec 5 2024, 22:57
valerio.bozzolan added a comment to D25849: Hovercards: Avoid "Undefined index: objectPHID" when passing bogus data.

Thaaanks - If I'm not wrong we can = idx($card, 'objectPHID');

Dec 5 2024, 22:40
aklapper added a revision to T15969: Hovercards "RuntimeException: Undefined index: objectPHID" when passing bogus data: D25849: Hovercards: Avoid "Undefined index: objectPHID" when passing bogus data.
Dec 5 2024, 22:38
aklapper requested review of D25849: Hovercards: Avoid "Undefined index: objectPHID" when passing bogus data.
Dec 5 2024, 22:38
aklapper created T15969: Hovercards "RuntimeException: Undefined index: objectPHID" when passing bogus data.
Dec 5 2024, 22:28
valerio.bozzolan accepted D25848: Fix PhabricatorAuthInviteTestCase::testDuplicateInvite unit test.

lgtm

Dec 5 2024, 22:07
aklapper added a revision to T15968: Unit test PhabricatorAuthInviteTestCase::testDuplicateInvite fails: D25848: Fix PhabricatorAuthInviteTestCase::testDuplicateInvite unit test.
Dec 5 2024, 18:04 · PHP 8 support
aklapper requested review of D25848: Fix PhabricatorAuthInviteTestCase::testDuplicateInvite unit test.
Dec 5 2024, 18:04
pppery closed D25838: Rewrite regex for project names to be not prone to catastrophic backtracking.
Dec 5 2024, 17:40
pppery closed T15371: RuntimeException in preg_replace_callback: Text disappears due to catastrophic backtracking regex in Remarkup parsing as Resolved by committing rP9c73d62c4466: Rewrite regex for project names to be not prone to catastrophic backtracking.
Dec 5 2024, 17:40 · Bug Reports, Remarkup, Affects-Wikimedia
pppery committed rP9c73d62c4466: Rewrite regex for project names to be not prone to catastrophic backtracking.
Dec 5 2024, 17:40
pppery updated the diff for D25838: Rewrite regex for project names to be not prone to catastrophic backtracking.

Rebase

Dec 5 2024, 17:39
aklapper accepted D25847: Remarkup: harden how we recognize internal/external URIs (mailto, mobile phones, ...).

I applied this patch locally on top of git master and output does not complain anymore about 'link-brackets.txt' (thus it's correct) but fails in link-edge-cases.txt now (thus it's likely not complete):

Dec 5 2024, 17:38 · Remarkup
aklapper created T15968: Unit test PhabricatorAuthInviteTestCase::testDuplicateInvite fails.
Dec 5 2024, 17:25 · PHP 8 support
valerio.bozzolan added a revision to T15967: Fix unit test PhutilPygmentizeParserTestCase: D25847: Remarkup: harden how we recognize internal/external URIs (mailto, mobile phones, ...).
Dec 5 2024, 15:52 · Wikimedia Hackathon 2025, Bug Reports, User-valerio.bozzolan, Remarkup
valerio.bozzolan requested review of D25847: Remarkup: harden how we recognize internal/external URIs (mailto, mobile phones, ...).
Dec 5 2024, 15:52 · Remarkup
valerio.bozzolan updated the task description for T15967: Fix unit test PhutilPygmentizeParserTestCase.
Dec 5 2024, 15:50 · Wikimedia Hackathon 2025, Bug Reports, User-valerio.bozzolan, Remarkup
valerio.bozzolan created T15967: Fix unit test PhutilPygmentizeParserTestCase.
Dec 5 2024, 15:48 · Wikimedia Hackathon 2025, Bug Reports, User-valerio.bozzolan, Remarkup
valerio.bozzolan moved T15966: Fix unit test PhabricatorChangeParserTestCase::testSubversionPartialParser for non-English terminals from Backlog to PingDeath 🌚 on the User-valerio.bozzolan board.
Dec 5 2024, 15:44 · Bug Reports, User-valerio.bozzolan, Diffusion
valerio.bozzolan added a revision to T15966: Fix unit test PhabricatorChangeParserTestCase::testSubversionPartialParser for non-English terminals: D25846: Fix Diffusion commands in non-English environments.
Dec 5 2024, 15:43 · Bug Reports, User-valerio.bozzolan, Diffusion
valerio.bozzolan requested review of D25846: Fix Diffusion commands in non-English environments.
Dec 5 2024, 15:43
valerio.bozzolan updated the diff for D25845: Repository Identity "Automatically Detected User": don't trust unverified emails.

run unit test

Dec 5 2024, 15:35
valerio.bozzolan created T15966: Fix unit test PhabricatorChangeParserTestCase::testSubversionPartialParser for non-English terminals.
Dec 5 2024, 15:34 · Bug Reports, User-valerio.bozzolan, Diffusion
valerio.bozzolan claimed T15965: Repository Identity "Automatically Detected User": it reads unverified emails, with spam concerns.
Dec 5 2024, 10:09 · Spam mitigation, Diffusion, Security
valerio.bozzolan changed the visibility for D25845: Repository Identity "Automatically Detected User": don't trust unverified emails.
Dec 5 2024, 10:02
valerio.bozzolan updated subscribers of T15965: Repository Identity "Automatically Detected User": it reads unverified emails, with spam concerns.

Adding @aklapper as subscriber in this security issue since I trust this user (unclear if this should be flagged as security thought, feel free to open)

Dec 5 2024, 10:01 · Spam mitigation, Diffusion, Security
valerio.bozzolan changed the edit policy for D25845: Repository Identity "Automatically Detected User": don't trust unverified emails.
Dec 5 2024, 09:58
valerio.bozzolan requested review of D25845: Repository Identity "Automatically Detected User": don't trust unverified emails.
Dec 5 2024, 09:58
valerio.bozzolan added a revision to T15965: Repository Identity "Automatically Detected User": it reads unverified emails, with spam concerns: D25845: Repository Identity "Automatically Detected User": don't trust unverified emails.
Dec 5 2024, 09:58 · Spam mitigation, Diffusion, Security
valerio.bozzolan created T15965: Repository Identity "Automatically Detected User": it reads unverified emails, with spam concerns.
Dec 5 2024, 09:57 · Spam mitigation, Diffusion, Security
valerio.bozzolan raised the priority of T15556: Improve Diffusion identity reassignment propagation from Low to Normal.
Dec 5 2024, 08:21 · Bug Reports, Diffusion

Dec 4 2024

valerio.bozzolan assigned T15412: PHP 8.1 "strlen(null)" exception when running "arc diff" with no active branch to jkimbo.
Dec 4 2024, 16:08 · PHP 8 support
l2dy added a comment to T15036: Phorge upstream mail should not use @secure.phorge.dev addresses.

This seems to impact mail deliverability to @icloud.com addresses too.

Dec 4 2024, 15:29 · phorge.it install
valerio.bozzolan added a member for Trusted Contributors: reet-.
Dec 4 2024, 10:55
reet- added a comment to Q160: Is it possible to delete repositories as normal user? (Answer 199).

Thanks a lot @valerio.bozzolan for addressing this so quickly!

Dec 4 2024, 08:23
valerio.bozzolan awarded T15036: Phorge upstream mail should not use @secure.phorge.dev addresses a Cup of Joe token.
Dec 4 2024, 08:06 · phorge.it install
avivey claimed T15036: Phorge upstream mail should not use @secure.phorge.dev addresses.

Please "remind" me about this ticket as often as possible, so I will fix it. I have everything I need to actually fix this, except the willpower.

Dec 4 2024, 08:05 · phorge.it install
valerio.bozzolan added a subtask for T15059: we.phorge.it doesn't email @outlook.com addresses: T15036: Phorge upstream mail should not use @secure.phorge.dev addresses.
Dec 4 2024, 07:50 · phorge.it install
valerio.bozzolan added a parent task for T15036: Phorge upstream mail should not use @secure.phorge.dev addresses: T15059: we.phorge.it doesn't email @outlook.com addresses.
Dec 4 2024, 07:50 · phorge.it install
valerio.bozzolan added inline comments to D25844: Add first unit test for mimemailparser headers.
Dec 4 2024, 07:49
valerio.bozzolan added inline comments to D25835: Strip surrounding whitespace from project and task titles.
Dec 4 2024, 06:59 · Projects, Maniphest
valerio.bozzolan added a comment to Q160: Is it possible to delete repositories as normal user? (Answer 199).

Hi @reet- hoping to be useful maybe see recent activity in T15964 :) You may like this

Dec 4 2024, 06:53
valerio.bozzolan closed T15964: "Delete Repository" button: it's a bit scaring (always active) as Resolved by committing rP48fd3f1c40de: Delete Repository button: disable if not admin, but show popup to all.
Dec 4 2024, 06:52 · UX, Diffusion
valerio.bozzolan closed D25843: Delete Repository button: disable if not admin, but show popup to all.
Dec 4 2024, 06:52
valerio.bozzolan committed rP48fd3f1c40de: Delete Repository button: disable if not admin, but show popup to all.
Dec 4 2024, 06:51
valerio.bozzolan added a comment to T15036: Phorge upstream mail should not use @secure.phorge.dev addresses.

We should maybe rewrite a bit the proposed solution, since ideally it's possible to use upstream.phorge.dev but it should be at least reachable to pass some anti-spam checkers I guess. At the moment it isn't:

Dec 4 2024, 06:49 · phorge.it install

Dec 3 2024

aklapper updated the test plan for D25790: Show table of contents by default on wide screens.
Dec 3 2024, 23:07
aklapper accepted D25790: Show table of contents by default on wide screens.

@mturdus: Thanks! LGTM

Dec 3 2024, 23:06
aklapper added a comment to D25835: Strip surrounding whitespace from project and task titles.

@valerio.bozzolan: Feel free to give this revised version another review :)

Dec 3 2024, 23:02 · Projects, Maniphest
aklapper accepted D25838: Rewrite regex for project names to be not prone to catastrophic backtracking.

Big thanks for digging deep into that regex (on which I gave up).

Dec 3 2024, 22:43
aklapper accepted D25844: Add first unit test for mimemailparser headers.

Thanks. Confirming that this works as expected (after manually changing test_accents.mbox to make the arc unit output fail)

Dec 3 2024, 22:24
aklapper updated the test plan for D25844: Add first unit test for mimemailparser headers.
Dec 3 2024, 21:20
taavi added a comment to D25844: Add first unit test for mimemailparser headers.

I hope you won't send me a lawyer

do you really think I could afford one

Dec 3 2024, 17:18
MacFan4000 edited reviewers for D25839: Fix parsing of incoming mail with UTF-8 encoded headers, added: O1: Blessed Committers, taavi, valerio.bozzolan; removed: Blessed Committers.
Dec 3 2024, 17:14
MacFan4000 edited reviewers for D25839: Fix parsing of incoming mail with UTF-8 encoded headers, added: Blessed Committers; removed: 3tayesh.
Dec 3 2024, 17:13
MacFan4000 changed the author of D25839: Fix parsing of incoming mail with UTF-8 encoded headers from 3tayesh to aklapper.
Dec 3 2024, 17:12
avivey changed the visibility for D25043: Upload compressed logo, update HTML.
Dec 3 2024, 16:22
avivey changed the visibility for D25041: Home Page.
Dec 3 2024, 16:21
avivey added a comment to D25839: Fix parsing of incoming mail with UTF-8 encoded headers.

@3tayesh Please don't do that again.

Dec 3 2024, 16:17
avivey changed the visibility for D25839: Fix parsing of incoming mail with UTF-8 encoded headers.
Dec 3 2024, 16:17
Policy changed the edit policy for D25839: Fix parsing of incoming mail with UTF-8 encoded headers.
Dec 3 2024, 16:16
Policy changed the visibility for D25839: Fix parsing of incoming mail with UTF-8 encoded headers.
Dec 3 2024, 16:16
valerio.bozzolan updated the test plan for D25844: Add first unit test for mimemailparser headers.
Dec 3 2024, 15:53
valerio.bozzolan updated the diff for D25844: Add first unit test for mimemailparser headers.

git rebase origin/master

Dec 3 2024, 15:52
valerio.bozzolan added a comment to D25844: Add first unit test for mimemailparser headers.

lol @taavi I've stolen some of your "ä" for the example file test_accents.mbox, I hope you won't send me a lawyer

Dec 3 2024, 15:48
valerio.bozzolan updated the summary of D25844: Add first unit test for mimemailparser headers.
Dec 3 2024, 15:47
valerio.bozzolan requested review of D25844: Add first unit test for mimemailparser headers.
Dec 3 2024, 15:44
valerio.bozzolan added a revision to T15960: Incoming mail parsing fails if specific headers have UTF-8 encoded text in them: D25844: Add first unit test for mimemailparser headers.
Dec 3 2024, 15:44 · Bug Reports
3tayesh commandeered D25839: Fix parsing of incoming mail with UTF-8 encoded headers from aklapper.
Dec 3 2024, 15:09
aklapper closed T15960: Incoming mail parsing fails if specific headers have UTF-8 encoded text in them as Resolved by committing rPc589529155d6: Fix parsing of incoming mail with UTF-8 encoded headers.
Dec 3 2024, 12:39 · Bug Reports
aklapper closed D25839: Fix parsing of incoming mail with UTF-8 encoded headers.
Dec 3 2024, 12:39
aklapper committed rPc589529155d6: Fix parsing of incoming mail with UTF-8 encoded headers.
Dec 3 2024, 12:39
valerio.bozzolan accepted D25839: Fix parsing of incoming mail with UTF-8 encoded headers.

I tried to prepare a unit test but it's not working. But yes the patch itself seems to work thanks

Dec 3 2024, 12:01
valerio.bozzolan added a comment to D25839: Fix parsing of incoming mail with UTF-8 encoded headers.

(Sorry I cannot test now) Does the test plan work with just this?

Dec 3 2024, 11:24
valerio.bozzolan added a comment to D25843: Delete Repository button: disable if not admin, but show popup to all.

Nice question avivey. We could always disable this but maybe "newcomer admins" may not try to click it, so with more confusion from the other (Dark) Side.

Dec 3 2024, 05:52

Dec 2 2024

avivey accepted D25843: Delete Repository button: disable if not admin, but show popup to all.

Since the button doesn't do anything in any case except say why it doesn't do anything, it might always be disabled? Do we have any other similar buttons?
I'm never sure if users discover that disabled buttons are actually clickable (and try to explain why they're disabled). It's a UI feature I really like, but I don't think I've seen it anywhere else.

Dec 2 2024, 21:24
valerio.bozzolan requested review of D25843: Delete Repository button: disable if not admin, but show popup to all.
Dec 2 2024, 20:19
valerio.bozzolan added a revision to T15964: "Delete Repository" button: it's a bit scaring (always active): D25843: Delete Repository button: disable if not admin, but show popup to all.
Dec 2 2024, 20:19 · UX, Diffusion
valerio.bozzolan updated the answer details for Q160: Is it possible to delete repositories as normal user? (Answer 199).
Dec 2 2024, 20:16
valerio.bozzolan added a project to T15964: "Delete Repository" button: it's a bit scaring (always active): UX.
Dec 2 2024, 20:15 · UX, Diffusion
valerio.bozzolan created T15964: "Delete Repository" button: it's a bit scaring (always active).
Dec 2 2024, 20:13 · UX, Diffusion
aklapper closed D25841: Account registration: Restrict Real Name length.
Dec 2 2024, 19:36
aklapper closed T15962: Account registration: Handle too long Real Name more gracefully as Resolved by committing rPeb380f922c9a: Account registration: Restrict Real Name length.
Dec 2 2024, 19:36
aklapper committed rPeb380f922c9a: Account registration: Restrict Real Name length.
Dec 2 2024, 19:36
valerio.bozzolan added a project to T15742: When creating a Diffusion Repo, add helpful text to each field: UX.
Dec 2 2024, 17:37 · UX, Diffusion
l2dy added a comment to T15062: Introducing Phixator 2.

Is the extension still maintained? While there is no extension store yet, it's possible to host repositories here. https://we.phorge.it/w/docs/extensions/phactory/

Dec 2 2024, 13:58 · Phactory: Community Projects
reet- closed Q160: Is it possible to delete repositories as normal user? as resolved.
Dec 2 2024, 11:54 · Diffusion
reet- added a comment to Q160: Is it possible to delete repositories as normal user? (Answer 199).

Thanks for the information. I can confirm that a normal user receives "You Shall Not Pass: rP", "You do not have permission to edit this object."

Dec 2 2024, 11:54