Page MenuHomeGitPull.it

Co-exists LockDown extension with VisualEditor
Closed, ResolvedPublic4 Points

Description

It seems VisualEditor is not compatible with the LockDown extension because the MediaWiki server needs to do some HTTP requests to some RESTbase API entry points.

https://www.mediawiki.org/wiki/File:Restbase_request_flow.svg

The problem with this design is that MediaWiki does anonymous HTTP requests to these APIs and so with the LockDown extension is not authorized to see its content.

This may have some big security considerations and needs some thoughts.

Event Timeline

valerio.bozzolan triaged this task as Low priority.Dec 9 2020, 01:11
valerio.bozzolan created this task.
valerio.bozzolan updated the task description. (Show Details)
valerio.bozzolan changed the point value for this task from 1 to 4.
valerio.bozzolan closed this task as Resolved.Dec 16 2020, 00:59

Well. Now it works. Don't know why.