[00:36:44] 10Phabricator: Error shown when clicking on search link next to "Activity Feed" - https://phabricator.wikimedia.org/T168108#3356404 (10GeoffreyT2000) [14:37:38] Can someone with administrative rights please take a look at Phabricator? There's several users creating bogus tasks and uploading .apk files. [14:38:03] Specifically; https://phabricator.wikimedia.org/p/Badr.ou/ [14:39:19] Also: https://phabricator.wikimedia.org/p/Eddaouyhacker/ [14:41:15] 10Phabricator: Redesign Phabricator login page: LDAP login too prominent; position of MediaWiki SUL login not prominent enough - https://phabricator.wikimedia.org/T862#14621 (10Tgr) Also, the MediaWiki logo is not necessarily recognizable (e.g. to Wikipedia editors who might want to report some UI bug). It would... [14:55:43] 10Phabricator: Cleanup phabricator.wikimedia.org uploaded files, WP zero abuse - https://phabricator.wikimedia.org/T168142#3357049 (10Framawiki) [14:56:06] 10Phabricator: Cleanup phabricator.wikimedia.org uploaded files, WP zero abuse - https://phabricator.wikimedia.org/T168142#3357061 (10Framawiki) [15:44:05] 10Phabricator: Cleanup phabricator.wikimedia.org uploaded files, WP zero abuse - https://phabricator.wikimedia.org/T168142#3357049 (10Ciencia_Al_Poder) See also file number 8472381, a video uploaded and linked from task number 168144 "how to upload file in new wikimedia" [16:16:44] 10Phabricator: Cleanup phabricator.wikimedia.org uploaded files, WP zero abuse - https://phabricator.wikimedia.org/T168142#3357309 (10Paladox) Possibly also spam is https://phabricator.wikimedia.org/T168117 [17:02:32] 10Phabricator: Please disable accounts for WP0 abuse - https://phabricator.wikimedia.org/T168163#3357378 (10zhuyifei1999) [17:04:14] 10Phabricator: Please disable accounts for WP0 abuse - https://phabricator.wikimedia.org/T168163#3357395 (10Framawiki) [17:04:33] 10Phabricator: Please disable accounts for WP0 abuse - https://phabricator.wikimedia.org/T168163#3357378 (10Framawiki) [17:04:35] 10Phabricator: Cleanup phabricator.wikimedia.org uploaded files, WP zero abuse - https://phabricator.wikimedia.org/T168142#3357400 (10Framawiki) [17:04:47] 10Phabricator: Please disable accounts for WP0 abuse - https://phabricator.wikimedia.org/T168163#3357401 (10zhuyifei1999) [17:04:49] 10Phabricator: Cleanup phabricator.wikimedia.org uploaded files, WP zero abuse - https://phabricator.wikimedia.org/T168142#3357402 (10zhuyifei1999) [17:10:12] 10Phabricator: Cleanup phabricator.wikimedia.org uploaded files, WP zero abuse - https://phabricator.wikimedia.org/T168142#3357444 (10zhuyifei1999) Also https://phabricator.wikimedia.org/p/tawfik.trt/ [17:12:43] twentyafterfour, RainbowSprinkles: Please see ^ ASAP. Phabricator is going to be a paradise for the pirates [17:17:55] zhuyifei1999_ we can protect any tasks they made so it carn't be seen in public (to prevent them trying to share copy right material or uploading viruses and people clicking on it) [17:26:42] hmm [17:36:26] 10Phabricator: Cleanup phabricator.wikimedia.org uploaded files, WP zero abuse - https://phabricator.wikimedia.org/T168142#3357500 (10zhuyifei1999) https://phabricator.wikimedia.org/p/ITex_media/ [17:39:20] can we get someone to handle this ASAP [17:39:37] 10Phabricator: Cleanup phabricator.wikimedia.org uploaded files, WP zero abuse - https://phabricator.wikimedia.org/T168142#3357501 (10zhuyifei1999) https://phabricator.wikimedia.org/p/T13024623/ https://phabricator.wikimedia.org/p/Nassim.banouni3/ [17:40:59] 10Phabricator: Cleanup phabricator.wikimedia.org uploaded files, WP zero abuse - https://phabricator.wikimedia.org/T168142#3357502 (10zhuyifei1999) https://phabricator.wikimedia.org/p/Youssefalli1/ https://phabricator.wikimedia.org/p/J118/ [17:42:05] I think an ip block would be a good idea if possible [17:48:47] 10Phabricator: Cleanup phabricator.wikimedia.org uploaded files, WP zero abuse - https://phabricator.wikimedia.org/T168142#3357506 (10zhuyifei1999) https://phabricator.wikimedia.org/p/Soufian/ [17:50:44] 10Phabricator: Cleanup phabricator.wikimedia.org uploaded files, WP zero abuse - https://phabricator.wikimedia.org/T168142#3357507 (10Framawiki) We are in the week-end : volunteers are here, WMF admins are sleeping :) Ping @mmodell @Aklapper [17:52:51] 10Phabricator: Cleanup phabricator.wikimedia.org uploaded files, WP zero abuse - https://phabricator.wikimedia.org/T168142#3357508 (10Framawiki) It's visible on graphs: network from phabricator increases https://grafana.wikimedia.org/dashboard/db/phabricator?orgId=1&from=1497549011340&to=1497721811342 This serve... [17:55:05] I will let you know when I see andre__ around here [17:55:05] @notify andre__ [17:55:39] zhuyifei1999_: https://phabricator.wikimedia.org/file/info/PHID-FILE-o7aq7quzr2upy56qmrl3/ [17:56:27] 10Phabricator: Cleanup phabricator.wikimedia.org uploaded files, WP zero abuse - https://phabricator.wikimedia.org/T168142#3357509 (10Paladox) Phab needs a system where you doint have to be an admin to block users :) [17:56:29] 10Phabricator: Cleanup phabricator.wikimedia.org uploaded files, WP zero abuse - https://phabricator.wikimedia.org/T168142#3357049 (10Zppix) https://phabricator.wikimedia.org/file/info/PHID-FILE-o7aq7quzr2upy56qmrl3/ [17:56:39] Reedy_ hi are you around for ^^? [17:57:51] 10Phabricator: Cleanup phabricator.wikimedia.org uploaded files, WP zero abuse - https://phabricator.wikimedia.org/T168142#3357512 (10Zppix) p:05High>03Unbreak! [18:00:40] 10Phabricator: Cleanup phabricator.wikimedia.org uploaded files, WP zero abuse - https://phabricator.wikimedia.org/T168142#3357049 (10Framawiki) We probably need to block OAuth for WP Zero, OAuth process is the key to access to phab and other tools. [18:03:36] paladox: is there nothing like 'default object policy' to block users? [18:03:41] 10Phabricator: Cleanup phabricator.wikimedia.org uploaded files, WP zero abuse - https://phabricator.wikimedia.org/T168142#3357531 (10Zppix) >>! In T168142#3357514, @Framawiki wrote: > We probably need to block OAuth for WP Zero, OAuth process is the key to access to phab and other tools. I disagree, keep oauth... [18:03:56] zhuyifei1999_ nope you need to be an admin i think [18:04:40] but i think we need to rise priority on implementing spam preventation as soon as possible since most of the admins are wmf employees who take the weekend off. leaving a gap where spammers can do bad stuff. [18:10:27] paladox: someone is definitely locking these accounts though [18:10:39] zhuyifei1999_ reedy's online [18:10:40] he has an admin status [18:11:00] oh thanks Reedy_ [18:11:06] 10Phabricator: Cleanup phabricator.wikimedia.org uploaded files, WP zero abuse - https://phabricator.wikimedia.org/T168142#3357548 (10Framawiki) >>! In T168142#3357531, @Zppix wrote: >>>! In T168142#3357514, @Framawiki wrote: >> We probably need to block OAuth for WP Zero, OAuth process is the key to access to p... [18:12:04] ? [18:12:19] Reedy_ he presumed you were banning the users [18:12:23] Nope [18:12:39] since your an admin [18:12:40] oh [18:13:52] well, many of the listed are now disabled [18:14:51] maybe andre__ or twentyafterfour did it :) [18:24:20] 10Phabricator, 10Wikimedia-Site-requests: Cleanup phabricator.wikimedia.org uploaded files, WP zero abuse - https://phabricator.wikimedia.org/T168142#3357618 (10Framawiki) [18:27:51] 10Phabricator, 10Wikimedia-Site-requests: Cleanup phabricator.wikimedia.org uploaded files, WP zero abuse - https://phabricator.wikimedia.org/T168142#3357620 (10Zppix) https://phabricator.wikimedia.org/file/info/PHID-FILE-g3doxzwaur6pzftyzt65/ [18:29:30] how did the bot managed to join devtool [18:29:31] ZPpix ^^ [18:37:21] paladox: that was me nicking to it [18:37:29] ok [18:37:30] to do some things [19:43:34] 10Phabricator, 10Wikimedia-Site-requests: Cleanup phabricator.wikimedia.org uploaded files, WP zero abuse - https://phabricator.wikimedia.org/T168142#3357722 (10Aklapper) >>! In T168142#3357507, @Framawiki wrote: > We are in the week-end : volunteers are here, WMF admins are sleeping :) Eh, no? [19:49:44] 10Phabricator, 10Wikimedia-Site-requests: Cleanup phabricator.wikimedia.org uploaded files, WP zero abuse - https://phabricator.wikimedia.org/T168142#3357784 (10Reedy) [19:58:01] Reedy: alanajjar is fine [19:58:24] ? [19:58:35] I've not disabled them :P [19:58:35] Reedy removed a subscriber: alanajjar. [19:58:38] Oh [19:58:39] Meh [20:05:28] Reedy, andre__: could you delete the 7 recent rars? https://phabricator.wikimedia.org/file/query/hL5zlSgia41x/#R [20:05:34] I can't, nope [20:05:43] zhuyifei1999_, yes, will do. thanks! [20:05:51] k [20:06:59] why does phab allow blatant rar uploads anyways [20:10:38] Phab spam handling is awful [20:10:48] I guess, they've not expected these things to be a problem [20:10:56] And for FB they want to upload things like rar too [20:13:47] we don't care about facebook. they can rot [20:14:38] 10Phabricator, 10Upstream: Phab admins should be able to delete files that belong to other users - https://phabricator.wikimedia.org/T168182#3357851 (10Reedy) [20:14:57] we wouldn't have have all these troubles it it wasn't for facebook zero [20:14:58] Well, except they're responsible in one way or another for most of it's development [20:47:33] zhuyifei1999_: considering its a development/issue tracker sometimes with certain programs rars would be uploaded to send log files and such, in wikimedia's case we wouldnt per say need rar uploads and such to be allowed but i dont think theres a way to white/blacklist certain file ext [20:48:01] use zip [20:48:29] free format vs nonfree format [20:50:12] 10Phabricator: Phab admins should be able to delete files that belong to other users - https://phabricator.wikimedia.org/T168182#3357883 (10Aklapper) > Having to use SQL to change ownership, then delete them, is a crappy workflow Phab admins don't have SQL access so that's not the workflow either foar admins. `... [20:50:56] zhuyifei1999_: rar/zip are pretty similar as far as i can recall i believe theres only minor differences [20:51:31] I mean zip is a free format whereas rar is not [20:52:22] zhuyifei1999_: what do you mean by free? I can create a rar file right now w/o paying anything [20:52:57] https://en.wikipedia.org/wiki/Open_format [20:53:18] compare https://en.wikipedia.org/wiki/RAR_(file_format) vs https://en.wikipedia.org/wiki/Zip_(file_format) [20:54:28] potientally spam/abuser (im unsure empty task desc with name simple, see T168183) [20:54:29] T168183: simple - https://phabricator.wikimedia.org/T168183 [20:55:48] 10Phabricator, 10Wikimedia Phabricator RfC: Make sure anti-vandalism features are up to snuff - https://phabricator.wikimedia.org/T84#3357902 (10Aklapper) 2017-06-17: Registriation of dozens of accounts from a large variety of IP addresses, upload of illegal material and creation of dozens of tasks (see https:... [20:56:39] zhuyifei1999_: I wonder if we can get a phab version of enwp.org/user:Cluebot_NG :P [20:57:29] cluebot ng works with edits not files [20:58:30] for files you want something like my https://commons.wikimedia.org/wiki/Special:Log/delete/Embedded_Data_Bot :) [20:58:32] zhuyifei1999_: i know it was a joke although it would help if it could work :P [20:59:18] yeah, I still don't really understand AI [21:02:36] 10Phabricator, 10Wikimedia-Site-requests: Cleanup phabricator.wikimedia.org uploaded files, WP zero abuse - https://phabricator.wikimedia.org/T168142#3357049 (10Nemo_bis) I've [[https://www.mediawiki.org/w/index.php?title=Special:Log&dir=prev&offset=20170617192014&limit=65&type=block&user=Nemo+bis|blocked a fe... [21:07:20] I'm going to turn on /config/edit/auth.require-approval/ for a while, so new user accounts need to be confirmed by a Phab admin [21:11:27] andre__: sounds good to me, however what if a geniune user say from -tech or such that needs to register do we have them register then we ping an phab admin or what? [21:11:36] Zppix. [21:11:50] ? [21:12:07] "Require administrators to approve newly registered accounts" [21:12:38] so i take that as a yes [21:13:17] no? [21:13:35] I can't make that up from what I wrote. [21:14:54] 10Phabricator, 10Wikimedia-Site-requests: Cleanup phabricator.wikimedia.org uploaded files, WP zero abuse - https://phabricator.wikimedia.org/T168142#3357939 (10Aklapper) As far as I've checked accounts and files, all seems to be cleaned up? Thanks a lot everybody who helped and has been around! Also, https://... [21:20:13] andre__: As far as I've checked accounts and files, all seems to be cleaned up? <= LGTM :) [21:22:15] Yay. Thanks everybody! Sigh :-/ [21:22:30] T84 is the corresponding general task about dealing with stuff like this [21:22:30] T84: Make sure anti-vandalism features are up to snuff - https://phabricator.wikimedia.org/T84 [21:28:08] 10Phabricator, 10Wikimedia-Site-requests: Cleanup phabricator.wikimedia.org uploaded files, WP zero abuse - https://phabricator.wikimedia.org/T168142#3357946 (10Framawiki) Thanks for your work, @aklapper and @nemo_bis. The solution I foud, blocking OAuth, seems not the best. Does somebody have an idea ? We ne... [21:32:55] 10Phabricator, 10Wikimedia-Site-requests: Cleanup phabricator.wikimedia.org uploaded files, WP zero abuse - https://phabricator.wikimedia.org/T168142#3357948 (10Framawiki) p:05Unbreak!>03High The rush is done. @nemo_bis, can you confirm that a blocked account onwiki can't use OAuth ? And that mw.org is th... [21:37:32] 10Phabricator: Remove "Release Details" field from simple task creation form or explain what it is / means - https://phabricator.wikimedia.org/T168186#3357951 (10Aklapper) [21:38:29] 10Phabricator, 10Wikimedia-Site-requests: Cleanup phabricator.wikimedia.org uploaded files, WP zero abuse - https://phabricator.wikimedia.org/T168142#3357049 (10Volans) Sorry for the late reply, partially because I was too busy cleaning stuff around to reply here (thanks Reedy for the help) and partially to no... [21:42:43] 10Phabricator: Should we allow blocked users on mediawiki to create accounts on phabricator - https://phabricator.wikimedia.org/T162996#3357965 (10Peachey88) {T168142} [22:19:38] 10Phabricator: Error shown when clicking on search link next to "Activity Feed" - https://phabricator.wikimedia.org/T168108#3358005 (10Aklapper) Thanks! [[ https://mediawiki.org/wiki/How_to_report_a_bug | Clear steps to reproduce and providing the complete error message welcome. ]] I assume this is about the fro... [22:20:07] 10Phabricator: Unhandled Exception ("InvalidArgumentException") error when clicking on search link in "Activity Feed" panel - https://phabricator.wikimedia.org/T168108#3358006 (10Aklapper) [22:25:45] 10Phabricator: EXCEPTION: (AphrontParameterQueryException) Array for %Ls conversion is empty. Query: user.phid - https://phabricator.wikimedia.org/T166984#3358007 (10Paladox) [22:25:54] 10Phabricator: EXCEPTION: (AphrontParameterQueryException) Array for %Ls conversion is empty. Query: user.phid - https://phabricator.wikimedia.org/T166984#3313528 (10Paladox) [22:26:05] 10Phabricator, 10Release-Engineering-Team (Kanban): EXCEPTION: (AphrontParameterQueryException) Array for %Ls conversion is empty. Query: user.phid - https://phabricator.wikimedia.org/T166984#3358011 (10Paladox) 05Open>03Resolved a:03mmodell [22:33:56] 10Phabricator: Unhandled Exception ("InvalidArgumentException") error when clicking on search link in "Activity Feed" panel - https://phabricator.wikimedia.org/T168108#3358012 (10Paladox) Another user @robh reported this too a few weeks ago. This problem was caused by the feed being modernised. Though i am unsu... [22:57:25] 10Phabricator: Disallow blocked users on mediawiki to create accounts on phabricator - https://phabricator.wikimedia.org/T162996#3358014 (10Aklapper) [23:39:05] 10Phabricator: Phab admins should be able to delete files that belong to other users - https://phabricator.wikimedia.org/T168182#3358031 (10Reedy) >>! In T168182#3357883, @Aklapper wrote: >> Having to use SQL to change ownership, then delete them, is a crappy workflow > Phab admins don't have SQL access so that'...