Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 749564 - Gentoo Wiki: Internal error. Error page reveals sensitive information. Cannot sign in via two-factor-authentication.
Summary: Gentoo Wiki: Internal error. Error page reveals sensitive information. Cannot...
Status: RESOLVED FIXED
Alias: None
Product: Websites
Classification: Unclassified
Component: Wiki (show other bugs)
Hardware: AMD64 Linux
: Normal major (vote)
Assignee: Gentoo Wiki Team
URL: https://wiki.gentoo.org/index.php?tit...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2020-10-16 14:33 UTC by Ramon Fischer
Modified: 2020-10-20 13:51 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Ramon Fischer 2020-10-16 14:33:27 UTC
Hello,

when I try to log in via two-factor-authentication, I get an "internal error", which also provides me some PHP backtrace information, revealing where certain PHP files are saved on the server.

I made a screenshot of it. To whom can I send it?

-Ramon

Reproducible: Always

Steps to Reproduce:
1. On the right hand side, click on "User", to expand a context menu
2. Click on "Log in"
3. Fill out "username" and "password"
4. Click on "Log in"
5. Enter a "time-based one-time password" as "Token"
6. Click on "Continue login"
Actual Results:  
PHP backtrace information are shown, which I cannot show here, due to security concerns.

Expected Results:  
Login is successful and forwards me to the main page of the Wiki.
Comment 1 Ramon Fischer 2020-10-16 14:44:03 UTC
I am using "ungoogled-chromium" from "PF4Public" Gentoo overlay[1]:

$ chromium --version
Chromium 85.0.4183.121 (with ungoogled-chromium patches)

I could also reproduce this issue with "firefox-bin":

$ firefox-bin --version
Mozilla Firefox 81.0.1

---

[1] https://github.com/PF4Public
Comment 2 Ramon Fischer 2020-10-20 12:36:58 UTC
Today, I tried to log in again and it returns me the following error message:

[6e609c005febe77de818cf24] 2020-10-20 12:29:01: Fatal exception of type "TypeError"

I sent the screenshots to "wiki@gentoo.org".
Comment 3 Brian Evans (RETIRED) gentoo-dev 2020-10-20 13:44:14 UTC
Thank you for the backtrace.  It allowed me to find the flaw in the mediawiki code and update it.

Note that we are planning on moving to MW 1.35 soon which has this fixed as well.
Comment 4 Ramon Fischer 2020-10-20 13:51:22 UTC
Awesome. Thank you!