[wp-meta] [Making WordPress.org] #401: Settings menu disappeared on Rosetta sites

Making WordPress.org noreply at wordpress.org
Tue Mar 11 23:46:10 UTC 2014


#401: Settings menu disappeared on Rosetta sites
----------------------------+-------------------------------------------
  Reporter:  vanillalounge  |      Owner:
      Type:  defect         |     Status:  closed
  Priority:  normal         |  Component:  International Sites (Rosetta)
Resolution:  wontfix        |   Keywords:
----------------------------+-------------------------------------------
Changes (by Otto42):

 * status:  new => closed
 * resolution:   => wontfix


Comment:

 Okay then, yeah, that's intentional. For security reasons any settings
 areas like that have to be going through the proxies for w.org. When
 you're not proxied, you're an "admin" but not a "super-admin".

 In other words, you can't wear your cape unless you're also proxied.

 I don't think it's actually documented anywhere, but it's been like that
 for at least 2 years. Probably longer. Maybe we'll lighten up on this when
 we go 100% SSL, but I doubt it.

 The rationale is that a lot of us go to WordCamps or other places which
 are using unsecured WiFi, and if somebody snagged a caped user's password
 or cookie, then they'd still not be able to affect any major changes
 without also having our SSH keys for the proxy.

 You could just call it plain old paranoia, if you prefer. :)

--
Ticket URL: <https://meta.trac.wordpress.org/ticket/401#comment:3>
Making WordPress.org <https://meta.trac.wordpress.org/>
Making WordPress.org


More information about the wp-meta mailing list