Svoboda | Graniru | BBC Russia | Golosameriki | Facebook
BBC RussianHomePhabricator
Log In
Maniphest T349745

Remove unused CentralAuth code identified by new monitoring
Closed, ResolvedPublic

Description

While adding the monitoring code in T327046, I've noticed several chunks of code that are probably unused. I'd like to use this monitoring to verify that, and then remove it.

Event Timeline

Restricted Application added a subscriber: Aklapper. · View Herald Transcript

Change 968383 had a related patch set uploaded (by Bartosz Dziewoński; author: Bartosz Dziewoński):

[mediawiki/extensions/CentralAuth@master] Bump some login logging to info level

https://gerrit.wikimedia.org/r/968383

Change 968383 merged by jenkins-bot:

[mediawiki/extensions/CentralAuth@master] Bump some login debug logging to info level

https://gerrit.wikimedia.org/r/968383

Change 974195 had a related patch set uploaded (by Bartosz Dziewoński; author: Bartosz Dziewoński):

[mediawiki/extensions/CentralAuth@master] Remove option to display a message after central login success

https://gerrit.wikimedia.org/r/974195

Change 974198 had a related patch set uploaded (by Bartosz Dziewoński; author: Bartosz Dziewoński):

[mediawiki/extensions/CentralAuth@master] Remove unused 'gu_id' URL parameter

https://gerrit.wikimedia.org/r/974198

Change 974203 had a related patch set uploaded (by Bartosz Dziewoński; author: Bartosz Dziewoński):

[mediawiki/extensions/CentralAuth@master] Remove support for inconsistent $wgCentralAuthLoginWiki

https://gerrit.wikimedia.org/r/974203

The latter two have a very small, but non-zero, number of hits in the logs:

A few of them look like someone accidentally copy-pasted the edge login HTML from Wikipedia in 2013 to their personal website. A few others look like they might be automated vulnerability scanning / pentesting. I think the code is still safe to remove (and thus respond to these requests with errors).

Change 974198 merged by jenkins-bot:

[mediawiki/extensions/CentralAuth@master] Remove unused 'gu_id' URL parameter

https://gerrit.wikimedia.org/r/974198

Change 974203 merged by jenkins-bot:

[mediawiki/extensions/CentralAuth@master] Remove support for inconsistent $wgCentralAuthLoginWiki

https://gerrit.wikimedia.org/r/974203

Change 974195 merged by jenkins-bot:

[mediawiki/extensions/CentralAuth@master] Remove option to display a message after central login success

https://gerrit.wikimedia.org/r/974195