Skip to content

Allow anonymous revision metadata queries to bypass crawler protection - #82

Open
jeffw16 wants to merge 1 commit into
mainfrom
feature/allow-revision-metadata-popups
Open

jeffw16 wants to merge 1 commit into
mainfrom
feature/allow-revision-metadata-popups

Conversation

@jeffw16

@jeffw16 jeffw16 commented Oct 9, 2026

Copy link
Copy Markdown
Member

Summary

This change adds a new configuration option $wgCrawlerProtectionAllowRevisionMetadata that exempts specific API queries from crawler protection. When enabled (default), anonymous users can request revision timestamps for single pages, which is necessary for Page Previews (Popups) to function properly while still protecting the revisions module from broader access.

Key Changes

  • New configuration option: $wgCrawlerProtectionAllowRevisionMetadata (defaults to true)

    • When enabled, allows anonymous action=query requests that only ask for revision timestamps of a single page
    • Maintains protection against requests for revision content, multiple pages, or other revision parameters
  • New method isRevisionMetadataQuery(): Validates that a query request qualifies for the exemption by checking:

    • Only the revisions module is protected in the request
    • Exactly one page is targeted (via titles or pageids, not generator or revids)
    • rvprop parameter contains only timestamp
    • No other rv* parameters are present
  • New utility method splitApiMultiValue(): Handles both pipe-separated (|) and unit-separator (\x1f) forms of multi-value API parameters, matching MediaWiki's API behavior

  • Integration with existing logic: The exemption is applied in checkApiModules() after determining the request would normally be denied, but before the CrawlerProtectionShouldDeny hook, allowing hooks to still override the decision

Notable Implementation Details

  • The exemption is deliberately narrow to prevent abuse while supporting the specific Page Previews use case
  • Registered users are never affected by this protection, regardless of the flag setting
  • The CrawlerProtectionShouldDeny hook receives the final decision after the exemption is applied
  • Comprehensive test coverage includes unit tests for the validation logic and integration tests verifying the feature works end-to-end
  • Version bumped to 1.8.0 to reflect the new feature

https://claude.ai/code/session_01Dk5bcSgoy2euC39AzvNmnV

Since 1.7.0 action=query sub-modules are matched against
$wgCrawlerProtectedApiModules, so protecting 'revisions' broke Page
Previews (Popups) for anonymous readers: its preview request includes
prop=revisions&rvprop=timestamp for a single title.

Add $wgCrawlerProtectionAllowRevisionMetadata (default true). When set,
an anonymous action=query request is not denied on account of
'revisions' if it is the only protected module, the request names
exactly one page via titles or pageids (no generator, no revids),
rvprop is given explicitly and contains only 'timestamp', and no other
rv* parameter is present. The CrawlerProtectionShouldDeny hook still
receives the final decision.

The multi-value separator logic is factored out into
CrawlerProtectionService::splitApiMultiValue() and shared with
Hooks::getApiModuleNames().

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Dk5bcSgoy2euC39AzvNmnV
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants