[wp-meta] [Making WordPress.org] #401: Settings menu disappeared on Rosetta sites
Making WordPress.org
noreply at wordpress.org
Tue Mar 11 23:46:10 UTC 2014
#401: Settings menu disappeared on Rosetta sites
----------------------------+-------------------------------------------
Reporter: vanillalounge | Owner:
Type: defect | Status: closed
Priority: normal | Component: International Sites (Rosetta)
Resolution: wontfix | Keywords:
----------------------------+-------------------------------------------
Changes (by Otto42):
* status: new => closed
* resolution: => wontfix
Comment:
Okay then, yeah, that's intentional. For security reasons any settings
areas like that have to be going through the proxies for w.org. When
you're not proxied, you're an "admin" but not a "super-admin".
In other words, you can't wear your cape unless you're also proxied.
I don't think it's actually documented anywhere, but it's been like that
for at least 2 years. Probably longer. Maybe we'll lighten up on this when
we go 100% SSL, but I doubt it.
The rationale is that a lot of us go to WordCamps or other places which
are using unsecured WiFi, and if somebody snagged a caped user's password
or cookie, then they'd still not be able to affect any major changes
without also having our SSH keys for the proxy.
You could just call it plain old paranoia, if you prefer. :)
--
Ticket URL: <https://meta.trac.wordpress.org/ticket/401#comment:3>
Making WordPress.org <https://meta.trac.wordpress.org/>
Making WordPress.org
More information about the wp-meta
mailing list