SECURITY: Do not directly redirect to interwikis, but use splash page
authorBrian Wolff <bawolff+wn@gmail.com>
Sun, 7 Feb 2016 13:07:20 +0000 (08:07 -0500)
committerChad Horohoe <chadh@wikimedia.org>
Thu, 6 Apr 2017 20:42:38 +0000 (13:42 -0700)
commit14beae88b5d8d71f291befa2839c1c72d02ede20
treedc9437e395fe596f16dd3cc0cad19e86b2bad708
parent93ba0cc7354e24dc9a9e470eb5628d8b41864024
SECURITY: Do not directly redirect to interwikis, but use splash page

Directly redirecting based on a url paramter might potentially
be used in a phishing attack to confuse users.

Bug: T109140
Bug: T122209
Change-Id: I6c604439320fa876719933cc7f3a3ff04fb1a6ad
16 files changed:
RELEASE-NOTES-1.29
autoload.php
includes/OutputPage.php
includes/Title.php
includes/specialpage/RedirectSpecialPage.php
includes/specialpage/SpecialPageFactory.php
includes/specials/SpecialChangeCredentials.php
includes/specials/SpecialChangeEmail.php
includes/specials/SpecialGoToInterwiki.php [new file with mode: 0644]
includes/specials/SpecialPageLanguage.php
includes/specials/SpecialPreferences.php
includes/specials/SpecialSearch.php
includes/specials/helpers/LoginHelper.php
languages/i18n/en.json
languages/i18n/qqq.json
languages/messages/MessagesEn.php