Fix oldid parameter not blocked on Special pages for anonymous users #9
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Problem
Anonymous users were able to access Special pages with the
oldidquery parameter, bypassing crawler protection. While regular pages correctly blocked this parameter, Special pages were not being checked.Example from server logs showing the issue:
This request to Special:Connexion (Login) with
oldid=4463returned 200 OK instead of being blocked with 403 Forbidden.Root Cause
The extension uses two hooks to protect pages:
onMediaWikiPerformAction- Handles regular page views and correctly checks foroldidparameteronSpecialPageBeforeExecute- Handles Special page views but only checked for specific page names (recentchangeslinked,whatlinkshere) without checking for theoldidparameterWhen a Special page was accessed with an
oldidparameter, it went through the second hook which didn't have the oldid check, allowing the request to proceed.Solution
Added oldid parameter checking to the
onSpecialPageBeforeExecutemethod to ensure consistent blocking across all page types:Testing
Added comprehensive test coverage including:
Impact
oldidparameter now consistently receive 403 ForbiddenFixes issue where crawlers could access revision history through Special page URLs.
Original prompt
Fixes #8
💬 Share your feedback on Copilot coding agent for the chance to win a $200 gift card! Click here to start the survey.