Page MenuHomePhabricator

dom_walden (Dom Walden)
Test Engineer for Community Tech and Product Safety and Integrity

Projects (17)

Today

  • No visible events.

Tomorrow

  • No visible events.

Wednesday

  • No visible events.

User Details

User Since
Oct 22 2018, 4:33 PM (403 w, 6 d)
Availability
Available
LDAP User
Dom Walden
MediaWiki User
DWalden (WMF) [ Global Accounts ]

Recent Activity

Wed, Jul 15

dom_walden added a comment to T432084: Article Guidance: fail to match "Broader autism phenotype" wikidata item to "medical metaclass" outline.

This also seems to affect the crosswiki notability risk as well:

  1. https://test.wikipedia.org/wiki/Special:NewArticle?newarticletitle=Karen_Foo_Kune
  2. Click "Pick type instead"
  3. Choose "Celebrity"
Wed, Jul 15, 9:46 AM · Design, LPL sprints, Article-Guidance
dom_walden added a comment to T432118: unsupportedsubject step does not allow you to change title.

I think this also affects the subjectcovered step, although I cannot find an article to trigger this on testwiki (I don't think there are any wikidata items that have a testwiki sitelink).

Wed, Jul 15, 6:38 AM · Article-Guidance, Language and Product Localization

Tue, Jul 14

dom_walden created T432118: unsupportedsubject step does not allow you to change title.
Tue, Jul 14, 1:39 PM · Article-Guidance, Language and Product Localization
dom_walden updated the task description for T432111: Better handling of invalid titles.
Tue, Jul 14, 1:03 PM · Patch-For-Review, Article-Guidance, Language and Product Localization
dom_walden created T432111: Better handling of invalid titles.
Tue, Jul 14, 12:56 PM · Patch-For-Review, Article-Guidance, Language and Product Localization
dom_walden created T432101: Cannot go back on type selection, unsupportedsubject and subjectcovered screens on desktop.
Tue, Jul 14, 10:53 AM · Language and Product Localization, Article-Guidance

Fri, Jul 10

dom_walden added a comment to T428892: Cannot login: incorrectly claims wrong username and password.

@dom_walden can you try one more login with Dwalden test acctcreation1 using debug mode via WikimediaDebug?

Fri, Jul 10, 10:09 AM · MW-1.47-notes (1.47.0-wmf.8; 2026-06-23), Essential-Work, Product Safety and Integrity (Sprint Venus Flytrap (Jun 29 - Jul 17)), MediaWiki-User-login-and-signup
dom_walden moved T428892: Cannot login: incorrectly claims wrong username and password from QA in Prod to Done on the Product Safety and Integrity (Sprint Venus Flytrap (Jun 29 - Jul 17)) board.

It looks like the passwords we have recorded for QTE-Test1-WMF and QTE-Test11-WMF are incorrect. I am following up.

Fri, Jul 10, 6:29 AM · MW-1.47-notes (1.47.0-wmf.8; 2026-06-23), Essential-Work, Product Safety and Integrity (Sprint Venus Flytrap (Jun 29 - Jul 17)), MediaWiki-User-login-and-signup

Thu, Jul 9

dom_walden moved T429902: ConfirmEdit 'badloginperuser' does not fallback to 'badlogin' CAPTCHA config from QA in Prod to Done on the Product Safety and Integrity (Sprint Venus Flytrap (Jun 29 - Jul 17)) board.

As per T431299#12093252, as far as I can tell, I am now seeing hCaptcha when triggering badloginperuser.

Thu, Jul 9, 5:43 AM · Bot detection and mitigation (WE4.10 hCaptcha), Essential-Work, Product Safety and Integrity (Sprint Venus Flytrap (Jun 29 - Jul 17)), MW-1.47-notes (1.47.0-wmf.7; 2026-06-16), ConfirmEdit (CAPTCHA extension), hCaptcha
dom_walden added a comment to T428892: Cannot login: incorrectly claims wrong username and password.

There are still some users I have not been able to successfully login as, even after filling in an hCaptcha challenge. I cannot know whether the password I used was actually incorrect (although I don't think they were) or if there is still a bug.

Thu, Jul 9, 5:31 AM · MW-1.47-notes (1.47.0-wmf.8; 2026-06-23), Essential-Work, Product Safety and Integrity (Sprint Venus Flytrap (Jun 29 - Jul 17)), MediaWiki-User-login-and-signup

Tue, Jul 7

dom_walden added a comment to T428892: Cannot login: incorrectly claims wrong username and password.

There are still some users I have not been able to successfully login as, even after filling in an hCaptcha challenge. I cannot know whether the password I used was actually incorrect (although I don't think they were) or if there is still a bug.

Tue, Jul 7, 12:23 PM · MW-1.47-notes (1.47.0-wmf.8; 2026-06-23), Essential-Work, Product Safety and Integrity (Sprint Venus Flytrap (Jun 29 - Jul 17)), MediaWiki-User-login-and-signup
dom_walden moved T425331: Scope hCaptcha captchaconsequence to the particular edit that triggered it from QA in Prod to Done on the Product Safety and Integrity (Sprint Venus Flytrap (Jun 29 - Jul 17)) board.

As part of testing other things I have noticed that I no longer have the 120s window after triggering AbuseFilter. I didn't see any negative consequences, so far.

Tue, Jul 7, 12:01 PM · Essential-Work, Product Safety and Integrity (Sprint Venus Flytrap (Jun 29 - Jul 17)), MW-1.47-notes (1.47.0-wmf.9; 2026-06-30), Bot detection and mitigation (WE4.10 hCaptcha)
dom_walden added a comment to T431299: badloginperuser does not inherit config from badlogin.

Fixed by this config change? I cannot reproduce this bug on testwiki nor locally after adding that line to my config.

Tue, Jul 7, 7:45 AM · Essential-Work, hCaptcha, ConfirmEdit (CAPTCHA extension), Product Safety and Integrity

Mon, Jul 6

dom_walden added a comment to T429902: ConfirmEdit 'badloginperuser' does not fallback to 'badlogin' CAPTCHA config.

If you are seeing FancyCaptcha with the above then it is likely a bug. Probably also if you see this when $wgCaptchaClass is not HCaptcha because the badloginperuser should always inherit from the badlogin config (even if the generic captcha class is different)

Mon, Jul 6, 1:29 PM · Bot detection and mitigation (WE4.10 hCaptcha), Essential-Work, Product Safety and Integrity (Sprint Venus Flytrap (Jun 29 - Jul 17)), MW-1.47-notes (1.47.0-wmf.7; 2026-06-16), ConfirmEdit (CAPTCHA extension), hCaptcha
dom_walden created T431299: badloginperuser does not inherit config from badlogin.
Mon, Jul 6, 1:29 PM · Essential-Work, hCaptcha, ConfirmEdit (CAPTCHA extension), Product Safety and Integrity
dom_walden created P94733 dom_walden local wiki hCaptcha config for reproduction of badloginperuser bug.
Mon, Jul 6, 1:28 PM
dom_walden added a comment to T430267: DiscussionTools: user not asked to resubmit form when triggering AbuseFilter as user with skipcaptcha.

MobileFrontend VE (ignore the black rectangle):

mfve_pls_resubmit.png (1,599×646 px, 60 KB)

Mon, Jul 6, 1:17 PM · Patch-For-Review, Essential-Work, Product Safety and Integrity (Sprint Venus Flytrap (Jun 29 - Jul 17)), DiscussionTools, ConfirmEdit (CAPTCHA extension), hCaptcha
dom_walden moved T429755: hCaptcha: Exclude self-identified crawlers from IP blocked edit notice risk score collection from QA in Prod to Done on the Product Safety and Integrity (Sprint Venus Flytrap (Jun 29 - Jul 17)) board.

I don't think there is anything for me to do here that would be of much value.

Mon, Jul 6, 12:57 PM · Essential-Work, Product Safety and Integrity (Sprint Venus Flytrap (Jun 29 - Jul 17)), MW-1.47-notes (1.47.0-wmf.9; 2026-06-30), Bot detection and mitigation (WE4.10 hCaptcha)
dom_walden moved T429875: hCaptcha: "Cannot find theme with name: custom" when switching to accessibility challenge in dark mode from QA in Prod to Done on the Product Safety and Integrity (Sprint Venus Flytrap (Jun 29 - Jul 17)) board.

I don't see this error anymore.

Mon, Jul 6, 12:32 PM · Essential-Work, Product Safety and Integrity (Sprint Venus Flytrap (Jun 29 - Jul 17)), MW-1.47-notes (1.47.0-wmf.9; 2026-06-30), Bot detection and mitigation (WE4.10 hCaptcha), hCaptcha
dom_walden moved T428652: Lots of "hCaptcha siteverify failed when collecting risk score for blocked user" errors from QA in Prod to Done on the Product Safety and Integrity (Sprint Venus Flytrap (Jun 29 - Jul 17)) board.

I don't think there is anything for me to test here.

Mon, Jul 6, 12:25 PM · Essential-Work, Product Safety and Integrity (Sprint Venus Flytrap (Jun 29 - Jul 17)), MW-1.47-notes (1.47.0-wmf.9; 2026-06-30), Bot detection and mitigation (WE4.10 hCaptcha), hCaptcha, ConfirmEdit (CAPTCHA extension)
dom_walden added a comment to T429902: ConfirmEdit 'badloginperuser' does not fallback to 'badlogin' CAPTCHA config.

Locally I have the following config that is probably relevant to this:

Mon, Jul 6, 11:49 AM · Bot detection and mitigation (WE4.10 hCaptcha), Essential-Work, Product Safety and Integrity (Sprint Venus Flytrap (Jun 29 - Jul 17)), MW-1.47-notes (1.47.0-wmf.7; 2026-06-16), ConfirmEdit (CAPTCHA extension), hCaptcha
dom_walden moved T429782: hCaptcha shouldn't load at same time as first view of privacy policy from QA in Prod to Done on the Product Safety and Integrity (Sprint Venus Flytrap (Jun 29 - Jul 17)) board.

I didn't notice any case where I saw the hCaptcha without seeing the privacy policy while testing T402595. I addition, I also did some state testing (going backward and forward, interrupting, retrying, switching between editors, etc.) of the different editors to see if I could find any edge cases. Apart from T430681, I did not notice any others.

Mon, Jul 6, 10:16 AM · Essential-Work, Product Safety and Integrity (Sprint Venus Flytrap (Jun 29 - Jul 17)), MW-1.47-notes (1.47.0-wmf.8; 2026-06-23), Bot detection and mitigation (WE4.10 hCaptcha)
dom_walden moved T402595: Allow AbuseFilter CAPTCHA actions to apply to users with skipcaptcha right from QA in Prod to Done on the Product Safety and Integrity (Sprint Venus Flytrap (Jun 29 - Jul 17)) board.

I have retested editors (WikiEditor, VE, MobileFrontend VE and SE, DiscussionTools desktop and mobile, Android App, API), Special:UserLogin, Special:UploadWizard and Special:CreateAccount as both a user with skipcaptcha and a user without, both triggering and not triggering AbuseFilter.

Mon, Jul 6, 10:05 AM · User-notice-archive, MW-1.47-notes (1.47.0-wmf.9; 2026-06-30), Essential-Work, Product Safety and Integrity (Sprint Venus Flytrap (Jun 29 - Jul 17)), Bot detection and mitigation (WE4.10 hCaptcha), ConfirmEdit (CAPTCHA extension), AbuseFilter

Thu, Jul 2

dom_walden moved T430518: MobileFrontend Source Editor: Cannot publish or go back after triggering AbuseFilter warning consequence from QA in Prod to Done on the Product Safety and Integrity (Sprint Venus Flytrap (Jun 29 - Jul 17)) board.

I have triggered a warning on all the interfaces (WikiEditor, VE, MobileFrontend, DiscussionTools) as a skipcaptcha and temp user on testwiki.

Thu, Jul 2, 10:46 AM · MW-1.47-notes (1.47.0-wmf.9; 2026-06-30), MobileFrontend (MobileFrontend (Editor)), Essential-Work, Product Safety and Integrity (Sprint Venus Flytrap (Jun 29 - Jul 17)), AbuseFilter
dom_walden added a comment to T429902: ConfirmEdit 'badloginperuser' does not fallback to 'badlogin' CAPTCHA config.

Sorry for the slow reply, this won't fix that issue. This ticket fixes the hCaptcha config not being copied

Thu, Jul 2, 7:42 AM · Bot detection and mitigation (WE4.10 hCaptcha), Essential-Work, Product Safety and Integrity (Sprint Venus Flytrap (Jun 29 - Jul 17)), MW-1.47-notes (1.47.0-wmf.7; 2026-06-16), ConfirmEdit (CAPTCHA extension), hCaptcha

Wed, Jul 1

dom_walden moved T430260: Challenge not shown when triggering AbuseFilter on an edit which creates a page from QA in Prod to Done on the Product Safety and Integrity (Sprint Venus Flytrap (Jun 29 - Jul 17)) board.

I retested this on testwiki for WikiEditor, VE, MobileFrontend Source and Visual, DiscussionTools (desktop and mobile) and via the API. I did it as users who did and did not have skipcaptcha rights.

Wed, Jul 1, 12:28 PM · Essential-Work, Product Safety and Integrity (Sprint Venus Flytrap (Jun 29 - Jul 17)), MW-1.47-notes (1.47.0-wmf.9; 2026-06-30), Bot detection and mitigation (WE4.10 hCaptcha), hCaptcha, ConfirmEdit (CAPTCHA extension)
dom_walden added a comment to T428892: Cannot login: incorrectly claims wrong username and password.

This also seems to affect the Apps T430799.

Wed, Jul 1, 10:54 AM · MW-1.47-notes (1.47.0-wmf.8; 2026-06-23), Essential-Work, Product Safety and Integrity (Sprint Venus Flytrap (Jun 29 - Jul 17)), MediaWiki-User-login-and-signup

Tue, Jun 30

dom_walden added a comment to T429782: hCaptcha shouldn't load at same time as first view of privacy policy.

Would you mind? 🙇

Tue, Jun 30, 2:48 PM · Essential-Work, Product Safety and Integrity (Sprint Venus Flytrap (Jun 29 - Jul 17)), MW-1.47-notes (1.47.0-wmf.8; 2026-06-23), Bot detection and mitigation (WE4.10 hCaptcha)
dom_walden created T430681: MobileFrontend Source Editor: hCaptcha loading without seeing privacy policy.
Tue, Jun 30, 2:47 PM · MobileFrontend (MobileFrontend (Editor)), hCaptcha, ConfirmEdit (CAPTCHA extension), Product Safety and Integrity (Sprint Venus Flytrap (Jun 29 - Jul 17))
dom_walden added a comment to T429782: hCaptcha shouldn't load at same time as first view of privacy policy.

For anything that needs to load hCaptcha post-page load (VE), as long as it's not attempting to run hCaptcha's challenge before the privacy policy can be acknowledged, this is expected behavior since that code has to exist to be callable when the first POST fails.

Tue, Jun 30, 1:31 PM · Essential-Work, Product Safety and Integrity (Sprint Venus Flytrap (Jun 29 - Jul 17)), MW-1.47-notes (1.47.0-wmf.8; 2026-06-23), Bot detection and mitigation (WE4.10 hCaptcha)
dom_walden added a comment to T429569: When AbuseFilter has both warn and showcaptcha consequences, see warning and hCaptcha challenge twice.

When you try to do it on MobileFrontend Source Editor, after the second time I have seen the warning, when I click "Publish" nothing appears to happen. It can also happen after the first time you see the warning if you have already been shown the hCaptcha challenge.

Tue, Jun 30, 8:31 AM · Essential-Work, Patch-For-Review, Product Safety and Integrity (Sprint Venus Flytrap (Jun 29 - Jul 17)), WikiEditor (2010), ConfirmEdit (CAPTCHA extension), hCaptcha
dom_walden added a comment to T429569: When AbuseFilter has both warn and showcaptcha consequences, see warning and hCaptcha challenge twice.

As of yesterday on my local wiki and this morning on testwiki, I am not just seeing warning and showcaptcha twice, I am seeing them (possibly) indefinitely (so far about five times in a row on WikiEditor on testwiki).

Tue, Jun 30, 7:31 AM · Essential-Work, Patch-For-Review, Product Safety and Integrity (Sprint Venus Flytrap (Jun 29 - Jul 17)), WikiEditor (2010), ConfirmEdit (CAPTCHA extension), hCaptcha

Mon, Jun 29

dom_walden created T430518: MobileFrontend Source Editor: Cannot publish or go back after triggering AbuseFilter warning consequence.
Mon, Jun 29, 12:48 PM · MW-1.47-notes (1.47.0-wmf.9; 2026-06-30), MobileFrontend (MobileFrontend (Editor)), Essential-Work, Product Safety and Integrity (Sprint Venus Flytrap (Jun 29 - Jul 17)), AbuseFilter
dom_walden added a comment to T430256: DiscussionTools: "Uncaught (in promise) Error: Global timeout" completing challenge.

Even then I suspect this is an Upstream problem with hCaptcha. Do you see this error when you are using other interfaces?

Mon, Jun 29, 7:01 AM · Product Safety and Integrity, ConfirmEdit (CAPTCHA extension), DiscussionTools, hCaptcha
dom_walden added a comment to T429782: hCaptcha shouldn't load at same time as first view of privacy policy.

If you are logged into an account with skipcaptcha and then logging into an another account, then perhaps you shouldn't see the badlogin CAPTCHA but maybe I'd say you should (to avoid one account compromise making compromising other accounts easier)

Mon, Jun 29, 6:57 AM · Essential-Work, Product Safety and Integrity (Sprint Venus Flytrap (Jun 29 - Jul 17)), MW-1.47-notes (1.47.0-wmf.8; 2026-06-23), Bot detection and mitigation (WE4.10 hCaptcha)

Fri, Jun 26

dom_walden added a comment to T429782: hCaptcha shouldn't load at same time as first view of privacy policy.

@STran I am seeing hCaptcha on badlogin for a user with skipcaptcha. Is this expected, a bug or is my local environment incorrectly configured?

Fri, Jun 26, 9:52 AM · Essential-Work, Product Safety and Integrity (Sprint Venus Flytrap (Jun 29 - Jul 17)), MW-1.47-notes (1.47.0-wmf.8; 2026-06-23), Bot detection and mitigation (WE4.10 hCaptcha)
dom_walden created T430267: DiscussionTools: user not asked to resubmit form when triggering AbuseFilter as user with skipcaptcha.
Fri, Jun 26, 7:58 AM · Patch-For-Review, Essential-Work, Product Safety and Integrity (Sprint Venus Flytrap (Jun 29 - Jul 17)), DiscussionTools, ConfirmEdit (CAPTCHA extension), hCaptcha
dom_walden created T430260: Challenge not shown when triggering AbuseFilter on an edit which creates a page.
Fri, Jun 26, 7:28 AM · Essential-Work, Product Safety and Integrity (Sprint Venus Flytrap (Jun 29 - Jul 17)), MW-1.47-notes (1.47.0-wmf.9; 2026-06-30), Bot detection and mitigation (WE4.10 hCaptcha), hCaptcha, ConfirmEdit (CAPTCHA extension)
dom_walden created T430256: DiscussionTools: "Uncaught (in promise) Error: Global timeout" completing challenge.
Fri, Jun 26, 6:32 AM · Product Safety and Integrity, ConfirmEdit (CAPTCHA extension), DiscussionTools, hCaptcha

Thu, Jun 25

dom_walden added a comment to T429820: Investigate testing upload API.

The test you wrote (Upload stash) did run for the patch you have pushed. Was the test supposed to pass or fail without UploadWizard? (It passed.)

Thu, Jun 25, 10:54 AM · Patch-For-Review, api-testing-tool, QS-Test-Automation
dom_walden added a comment to T429924: "Error, edit not published" attempting to load hCaptcha on mobile source editor.

The siteverify request is made server side, so if it fails you'd see an error in the mw-debug.log for local wikis and logstash for prod

Thu, Jun 25, 9:37 AM · MobileFrontend (MobileFrontend (Editor)), ConfirmEdit (CAPTCHA extension), Product Safety and Integrity, hCaptcha
dom_walden added a comment to T429782: hCaptcha shouldn't load at same time as first view of privacy policy.

@STran On VE as a user with skipcaptcha, when I trigger AbuseFilter and see the Please resubmit the form to save your edit, I notice that we are making requests to hCaptcha before we have resubmitted the form. This includes loading secure-api.js, hcaptcha-enclave.html and /checksiteconfig.

Thu, Jun 25, 8:12 AM · Essential-Work, Product Safety and Integrity (Sprint Venus Flytrap (Jun 29 - Jul 17)), MW-1.47-notes (1.47.0-wmf.8; 2026-06-23), Bot detection and mitigation (WE4.10 hCaptcha)

Wed, Jun 24

dom_walden added a comment to T429902: ConfirmEdit 'badloginperuser' does not fallback to 'badlogin' CAPTCHA config.

Might this fix this behaviour I just saw, after trying many failed login attempts?

Wed, Jun 24, 8:08 AM · Bot detection and mitigation (WE4.10 hCaptcha), Essential-Work, Product Safety and Integrity (Sprint Venus Flytrap (Jun 29 - Jul 17)), MW-1.47-notes (1.47.0-wmf.7; 2026-06-16), ConfirmEdit (CAPTCHA extension), hCaptcha
dom_walden moved T399491: ConfirmEdit hCaptcha: Set `hl` parameter to an acceptable fallback when hCaptcha does not natively support the language from QA in Prod to Done on the Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)) board.

Thanks. I see uselang=pt-BR opens the hCaptcha challenge with "Portuguese (Brazil)".

Wed, Jun 24, 8:07 AM · MW-1.47-notes (1.47.0-wmf.8; 2026-06-23), Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)), Bot detection and mitigation (WE4.10 hCaptcha), I18n, ConfirmEdit (CAPTCHA extension)
dom_walden moved T429705: hCaptcha: Bad login CAPTCHA on second or more attempts shows every other submission from QA in Prod to Done on the Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)) board.

I can no longer reproduce this when trying many failed login attempts in a row on testwiki.

Wed, Jun 24, 8:00 AM · MW-1.47-notes (1.47.0-wmf.7; 2026-06-16), Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)), Bot detection and mitigation (WE4.10 hCaptcha), ConfirmEdit (CAPTCHA extension), hCaptcha
dom_walden moved T429611: hCaptcha should not reenable the submit button on the account creation form after a successful test from QA in Prod to Done on the Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)) board.

I see the "Create account" button being disabled when submitting the Special:CreateAccount form.

Wed, Jun 24, 7:15 AM · MW-1.47-notes (1.47.0-wmf.8; 2026-06-23), ConfirmEdit (CAPTCHA extension), Bot detection and mitigation (WE4.10 hCaptcha), Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)), hCaptcha
dom_walden moved T428233: "Incorrect or missing CAPTCHA" when resubmitting edit which triggers AbuseFilter disallow consequence from QA in Prod to Done on the Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)) board.

I can no longer reproduce this on test.wikipedia.org. I wonder if we fixed this in other tickets?

Wed, Jun 24, 5:26 AM · Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)), ConfirmEdit (CAPTCHA extension), Bot detection and mitigation (WE4.10 hCaptcha), hCaptcha, AbuseFilter
dom_walden added a comment to T429924: "Error, edit not published" attempting to load hCaptcha on mobile source editor.

It suggests maybe you were seeing a hcaptcha-api error which would be the siteverify API call failing

Wed, Jun 24, 5:19 AM · MobileFrontend (MobileFrontend (Editor)), ConfirmEdit (CAPTCHA extension), Product Safety and Integrity, hCaptcha
dom_walden added a comment to T429924: "Error, edit not published" attempting to load hCaptcha on mobile source editor.

Perhaps we need to disable the publish button when that happens to make it clear? Though that won't fix the root cause

Wed, Jun 24, 5:17 AM · MobileFrontend (MobileFrontend (Editor)), ConfirmEdit (CAPTCHA extension), Product Safety and Integrity, hCaptcha

Tue, Jun 23

dom_walden created T429924: "Error, edit not published" attempting to load hCaptcha on mobile source editor.
Tue, Jun 23, 2:17 PM · MobileFrontend (MobileFrontend (Editor)), ConfirmEdit (CAPTCHA extension), Product Safety and Integrity, hCaptcha
dom_walden moved T408795: hCaptcha: when challenge triggered makes entire screen white in Dark mode from QA in Prod to Done on the Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)) board.

I can no longer reproduce.

Tue, Jun 23, 8:31 AM · MW-1.47-notes (1.47.0-wmf.8; 2026-06-23), Bot detection and mitigation (WE4.10 hCaptcha), Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)), ConfirmEdit (CAPTCHA extension)
dom_walden moved T394872: hCaptcha dark mode from QA in Prod to Done on the Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)) board.

MobileFrontend VisualEditor:

dark_mode_mfve.png (1,043×719 px, 49 KB)

Tue, Jun 23, 8:30 AM · Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)), dark-mode, ConfirmEdit (CAPTCHA extension)
dom_walden created T429875: hCaptcha: "Cannot find theme with name: custom" when switching to accessibility challenge in dark mode.
Tue, Jun 23, 8:19 AM · Essential-Work, Product Safety and Integrity (Sprint Venus Flytrap (Jun 29 - Jul 17)), MW-1.47-notes (1.47.0-wmf.9; 2026-06-30), Bot detection and mitigation (WE4.10 hCaptcha), hCaptcha
dom_walden moved T428871: Uncaught TypeError: Cannot read properties of undefined (reading 'find') from QA in Prod to Done on the Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)) board.

I can no longer reproduce this on testwiki.

Tue, Jun 23, 7:53 AM · MW-1.47-notes (1.47.0-wmf.8; 2026-06-23), Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)), MobileFrontend, ConfirmEdit (CAPTCHA extension), Bot detection and mitigation (WE4.10 hCaptcha), hCaptcha
dom_walden moved T426875: hCaptcha: Support usage in "always challenge" SiteKey for badlogin from QA in Prod to Done on the Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)) board.

I have tested this on testwiki.

Tue, Jun 23, 7:46 AM · Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)), MW-1.47-notes (1.47.0-wmf.4; 2026-05-26), Patch-For-Review, Bot detection and mitigation (WE4.10 hCaptcha), hCaptcha
dom_walden moved T427612: hCaptcha: mcrundo cannot be used when hCaptcha is enabled for editing from QA in Prod to Done on the Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)) board.

Done with T416453.

Tue, Jun 23, 7:31 AM · Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)), MW-1.47-notes (1.47.0-wmf.7; 2026-06-16), Multi-Content-Revisions, Bot detection and mitigation (WE4.10 hCaptcha), hCaptcha
dom_walden moved T416453: hCaptcha: Add support for McrUndo/McrRestore actions from QA in Prod to Done on the Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)) board.

I have tested this on Commons. I have been able to publish with mcrundo.

Tue, Jun 23, 7:31 AM · MW-1.47-notes (1.47.0-wmf.8; 2026-06-23), Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)), Patch-For-Review, hCaptcha, ConfirmEdit (CAPTCHA extension)

Mon, Jun 22

dom_walden updated the task description for T429820: Investigate testing upload API.
Mon, Jun 22, 4:27 PM · Patch-For-Review, api-testing-tool, QS-Test-Automation
dom_walden updated the task description for T429820: Investigate testing upload API.
Mon, Jun 22, 4:25 PM · Patch-For-Review, api-testing-tool, QS-Test-Automation
dom_walden created T429820: Investigate testing upload API.
Mon, Jun 22, 4:18 PM · Patch-For-Review, api-testing-tool, QS-Test-Automation

Jun 19 2026

dom_walden moved T429481: hCaptcha: Fix logging of risk scores for edits from QA in Prod to Done on the Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)) board.

Yes, that is OK.

Jun 19 2026, 10:20 AM · MW-1.47-notes (1.47.0-wmf.6; 2026-06-09), Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)), Bot detection and mitigation (WE4.10 hCaptcha), hCaptcha
dom_walden moved T428287: hCaptcha MobileFrontend: Indefinite loop of save requests if request always fails with "known" error from QA in Prod to Done on the Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)) board.

With the reproduction steps in the description, I do not see a loop. Instead, it fails with error:

Error, edit not published.
There was an error while loading the form. To continue, you will need to reload the page.
Jun 19 2026, 8:57 AM · MW-1.47-notes (1.47.0-wmf.6; 2026-06-09), Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)), MobileFrontend, ConfirmEdit (CAPTCHA extension), hCaptcha
dom_walden added a comment to T429481: hCaptcha: Fix logging of risk scores for edits.

@kostajh Testing locally, when I trigger an AbuseFilter with my edit I get two events recorded, the first with action=failed_edit the second with action=edit. I have seen this on WikiEditor, VE and MobileFrontend. Is this OK?

Jun 19 2026, 8:46 AM · MW-1.47-notes (1.47.0-wmf.6; 2026-06-09), Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)), Bot detection and mitigation (WE4.10 hCaptcha), hCaptcha

Jun 18 2026

dom_walden moved T426973: Support a configurable minimum edit count requirement before `skipcaptcha` right will take effect from QA in Prod to Done on the Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)) board.

Setting $wgSkipCaptchaMinimumEditCount locally, I have checked that an autoconfirmed user with less than the required number of edits still sees hCaptcha challenges on normal and AbuseFilter edits. With more than the required number of edits, they do not see the challenge on normal or AF edits. I have only tested WikiEditor, as I assume the editing interface will make no difference.

Jun 18 2026, 12:58 PM · hCaptcha, Essential-Work, Product Safety and Integrity (Sprint Venus Flytrap (Jun 29 - Jul 17))
dom_walden moved T427784: hCaptcha risk scores for blocked account creations from QA in Prod to Done on the Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)) board.

Locally, I can see events being recorded in the event log when I attempt to login while blocked. I tested both global and local blocks.

Jun 18 2026, 12:34 PM · Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)), Bot detection and mitigation (WE4.10 hCaptcha)
dom_walden moved T426126: Implement CAPTCHA support in the Upload Wizard from QA in Prod to Done on the Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)) board.

I have done a certain amount of testing of Special:UploadWizard on testwiki. I will move this along.

Jun 18 2026, 9:31 AM · Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)), MW-1.47-notes (1.47.0-wmf.6; 2026-06-09), Patch-For-Review, ConfirmEdit (CAPTCHA extension), Epic, Bot detection and mitigation (WE4.10 hCaptcha), hCaptcha, UploadWizard
dom_walden moved T428437: hCaptcha widget not rendering after "warn" AbuseFilter consequence on desktop wikitext editor from QA in Prod to Done on the Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)) board.

I can no longer reproduce the bug in the description. I have raised T429569 for the bug described in T428437#12004543.

Jun 18 2026, 8:18 AM · Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)), MW-1.47-notes (1.47.0-wmf.5; 2026-06-02), Bot detection and mitigation (WE4.10 hCaptcha)
dom_walden created T429569: When AbuseFilter has both warn and showcaptcha consequences, see warning and hCaptcha challenge twice.
Jun 18 2026, 8:18 AM · Essential-Work, Patch-For-Review, Product Safety and Integrity (Sprint Venus Flytrap (Jun 29 - Jul 17)), WikiEditor (2010), ConfirmEdit (CAPTCHA extension), hCaptcha
dom_walden moved T429322: hCaptcha UploadWizard: UploadWizard hook fires for all uploads, not just those performed by the upload wizard from QA in Prod to Done on the Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)) board.

I was successfully able to upload an image via the API using the stash process on testwiki.

Jun 18 2026, 8:06 AM · MW-1.47-notes (1.47.0-wmf.6; 2026-06-09), Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)), UploadWizard, Bot detection and mitigation (WE4.10 hCaptcha), ConfirmEdit (CAPTCHA extension)
dom_walden moved T429287: UploadWizard: "Uncaught (in promise) Error: captcha-cancelled" when dismissing challenge from QA in Prod to Done on the Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)) board.

I cannot reproduce this error locally.

Jun 18 2026, 7:55 AM · MW-1.47-notes (1.47.0-wmf.8; 2026-06-23), Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)), UploadWizard, ConfirmEdit (CAPTCHA extension), Bot detection and mitigation (WE4.10 hCaptcha), hCaptcha
dom_walden moved T424636: Blue loading spinner not always shown when hCaptcha loading on mobile source editor from QA in Prod to Done on the Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)) board.

I can no longer reproduce.

Jun 18 2026, 7:43 AM · Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)), MW-1.47-notes (1.47.0-wmf.7; 2026-06-16), MobileFrontend, ConfirmEdit (CAPTCHA extension), Bot detection and mitigation (WE4.10 hCaptcha)
dom_walden moved T427608: hCaptcha: Edits made via the API on WMF wikis that trigger AbuseFilter still require hCaptcha completion from QA in Prod to Done on the Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)) board.

I was successfully able to use the API to make an edit which triggered AbuseFilter. I was given a URL for a FancyCaptcha image, entered the word into captchaword and resubmitted.

Jun 18 2026, 7:37 AM · Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)), MW-1.47-notes (1.47.0-wmf.5; 2026-06-02), WikibaseMediaInfo, ConfirmEdit (CAPTCHA extension), Bot detection and mitigation (WE4.10 hCaptcha), hCaptcha

Jun 17 2026

dom_walden added a comment to T399491: ConfirmEdit hCaptcha: Set `hl` parameter to an acceptable fallback when hCaptcha does not natively support the language.

@Dreamy_Jazz I notice we are missing a couple of languages from LANGUAGES_SUPPORTED_BY_HCAPTCHA which hCaptcha does support:

  • pt-BR (not listed in their doc but included in the language selector in the challenge)
  • zh-CN
  • zh-TW
Jun 17 2026, 3:00 PM · MW-1.47-notes (1.47.0-wmf.8; 2026-06-23), Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)), Bot detection and mitigation (WE4.10 hCaptcha), I18n, ConfirmEdit (CAPTCHA extension)
dom_walden moved T403829: hCaptcha: Self-host secure-api.js code in /static directory from QA in Prod to Done on the Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)) board.

@dom_walden I think this one could skip QA, but I will leave it for you to review.

Jun 17 2026, 1:29 PM · Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)), Bot detection and mitigation (WE4.10 hCaptcha), Patch-For-Review, ConfirmEdit (CAPTCHA extension)
dom_walden moved T424597: Make use of the mw.libs.confirmEdit.CaptchaWidget in DiscussionTools instead of CaptchaInputWidget from QA in Prod to Done on the Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)) board.

I have tested Discussion Tools.

Jun 17 2026, 1:29 PM · Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)), MW-1.47-notes (1.47.0-wmf.3; 2026-05-19), Bot detection and mitigation (WE4.10 hCaptcha), hCaptcha, ConfirmEdit (CAPTCHA extension), DiscussionTools
dom_walden moved T425955: DiscussionTools hCaptcha: Show hCaptcha widget before first reply attempt from QA in Prod to Done on the Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)) board.

I have done a certain amount of testing of Discussion Tools. Moving along.

Jun 17 2026, 1:28 PM · Bot detection and mitigation (WE4.10 hCaptcha), Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)), MW-1.47-notes (1.47.0-wmf.2; 2026-05-12), hCaptcha, ConfirmEdit (CAPTCHA extension), DiscussionTools
dom_walden moved T426056: hCaptcha: SiteVerify responses with 'already-seen-response' during standard editing flow from QA in Prod to Done on the Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)) board.

I do not remember seeing this problem since, although I cannot remember exactly how to trigger this bug.

Jun 17 2026, 1:27 PM · Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)), MW-1.47-notes (1.47.0-wmf.4; 2026-05-26), Bot detection and mitigation (WE4.10 hCaptcha), ConfirmEdit (CAPTCHA extension), hCaptcha
dom_walden moved T426068: hCaptcha risk scores: New API endpoint for collecting risk scores from QA in Prod to Done on the Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)) board.

I have done a certain amount of testing of this. More will be done after T428394.

Jun 17 2026, 1:27 PM · Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)), hCaptcha, ConfirmEdit (CAPTCHA extension), Bot detection and mitigation (WE4.10 hCaptcha)
dom_walden moved T426476: DiscussionTools hCaptcha: When user encounters AbuseFilter hCaptcha challenge no indication is shown they need to resubmit their edit from QA in Prod to Done on the Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)) board.

I no longer see this problem. Resubmit is now automatic.

Jun 17 2026, 1:26 PM · Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)), MW-1.47-notes (1.47.0-wmf.5; 2026-06-02), Bot detection and mitigation (WE4.10 hCaptcha), DiscussionTools, hCaptcha, ConfirmEdit (CAPTCHA extension)
dom_walden moved T427067: hCaptcha risk scores (MobileFrontend): Collect and submit risk scores when showing a blocked edit notice in the MobileFrontend from QA in Prod to Done on the Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)) board.

I have done a certain amount of testing of this. Moving along.

Jun 17 2026, 1:24 PM · Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)), Bot detection and mitigation (WE4.10 hCaptcha), ConfirmEdit (CAPTCHA extension), MobileFrontend (MobileFrontend (Editor))
dom_walden moved T427904: DiscussionTools: Improve error message when hCaptcha challenge dismissed from QA in Prod to Done on the Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)) board.

I now see more useful error messages.

Jun 17 2026, 1:23 PM · Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)), MW-1.47-notes (1.47.0-wmf.6; 2026-06-09), Bot detection and mitigation (WE4.10 hCaptcha), hCaptcha, ConfirmEdit (CAPTCHA extension), DiscussionTools
dom_walden moved T427816: hCaptcha: Wikitext source editor always fails with incorrect CAPTCHA error when in mobile mode on vector from QA in Prod to Done on the Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)) board.

Following the reproduction steps, I was successfully able to publish an edit.

Jun 17 2026, 1:20 PM · Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)), MW-1.47-notes (1.47.0-wmf.6; 2026-06-09), Bot detection and mitigation (WE4.10 hCaptcha), ConfirmEdit (CAPTCHA extension), hCaptcha

Jun 16 2026

dom_walden created T429293: UploadWizard: No indication that hCaptcha is loading.
Jun 16 2026, 8:41 AM · MW-1.47-notes (1.47.0-wmf.8; 2026-06-23), Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)), UploadWizard, ConfirmEdit (CAPTCHA extension), Bot detection and mitigation (WE4.10 hCaptcha), hCaptcha
dom_walden renamed T429287: UploadWizard: "Uncaught (in promise) Error: captcha-cancelled" when dismissing challenge from "Uncaught (in promise) Error: captcha-cancelled" when dismissing challenge to UploadWizard: "Uncaught (in promise) Error: captcha-cancelled" when dismissing challenge.
Jun 16 2026, 7:47 AM · MW-1.47-notes (1.47.0-wmf.8; 2026-06-23), Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)), UploadWizard, ConfirmEdit (CAPTCHA extension), Bot detection and mitigation (WE4.10 hCaptcha), hCaptcha
dom_walden created T429287: UploadWizard: "Uncaught (in promise) Error: captcha-cancelled" when dismissing challenge.
Jun 16 2026, 7:47 AM · MW-1.47-notes (1.47.0-wmf.8; 2026-06-23), Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)), UploadWizard, ConfirmEdit (CAPTCHA extension), Bot detection and mitigation (WE4.10 hCaptcha), hCaptcha

Jun 12 2026

dom_walden added a comment to T423287: hCaptcha not loading on iOS 12, cannot make a mobile source edit or create account.

@kostajh I just tested this again, and I still cannot edit on testwiki on iOS 12.

Jun 12 2026, 12:38 PM · Essential-Work, Product Safety and Integrity (Sprint Venus Flytrap (Jun 29 - Jul 17)), Bot detection and mitigation (WE4.10 hCaptcha), MW-1.47-notes (1.47.0-wmf.4; 2026-05-26), Test Kitchen, MobileFrontend (MobileFrontend (Editor)), ConfirmEdit (CAPTCHA extension)
dom_walden moved T422222: Unable to submit edit in Basic mode from QA in Prod to Done on the Product Safety and Integrity (Sprint Iris (May 25 - Jun 12)) board.

Sorry, I let this slip off my radar. Testing just now on testwiki:

BrowserOSEditCreate account
Firefox 49Windows 8.1WorkingWorking
Firefox 50Windows 8.1WorkingWorking
Chrome 49Mac SierraWorkingWorking
Chrome 50Mac High SierraWorkingWorking
Safari 10.1Mac SierraWorkingWorking
Jun 12 2026, 8:33 AM · Product Safety and Integrity (Sprint Iris (May 25 - Jun 12)), MW-1.47-notes (1.47.0-wmf.4; 2026-05-26), MediaWiki-Core-Platform-Team (Radar), ConfirmEdit (CAPTCHA extension), Bot detection and mitigation (WE4.2 hCaptcha editing trial)

Jun 11 2026

dom_walden updated the task description for T428892: Cannot login: incorrectly claims wrong username and password.
Jun 11 2026, 12:47 PM · MW-1.47-notes (1.47.0-wmf.8; 2026-06-23), Essential-Work, Product Safety and Integrity (Sprint Venus Flytrap (Jun 29 - Jul 17)), MediaWiki-User-login-and-signup
dom_walden updated the task description for T428892: Cannot login: incorrectly claims wrong username and password.
Jun 11 2026, 12:46 PM · MW-1.47-notes (1.47.0-wmf.8; 2026-06-23), Essential-Work, Product Safety and Integrity (Sprint Venus Flytrap (Jun 29 - Jul 17)), MediaWiki-User-login-and-signup
dom_walden created T428892: Cannot login: incorrectly claims wrong username and password.
Jun 11 2026, 12:25 PM · MW-1.47-notes (1.47.0-wmf.8; 2026-06-23), Essential-Work, Product Safety and Integrity (Sprint Venus Flytrap (Jun 29 - Jul 17)), MediaWiki-User-login-and-signup
dom_walden created T428871: Uncaught TypeError: Cannot read properties of undefined (reading 'find').
Jun 11 2026, 9:20 AM · MW-1.47-notes (1.47.0-wmf.8; 2026-06-23), Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)), MobileFrontend, ConfirmEdit (CAPTCHA extension), Bot detection and mitigation (WE4.10 hCaptcha), hCaptcha
dom_walden updated the title for P94061 NodeJS script to launch a Chromium browser which is suspect to hCaptcha from untitled to NodeJS script to launch a Chromium browser which is suspect to hCaptcha.
Jun 11 2026, 9:11 AM
dom_walden created P94061 NodeJS script to launch a Chromium browser which is suspect to hCaptcha.
Jun 11 2026, 9:10 AM
dom_walden added a comment to T425929: Cannot publish after dismissing hCaptcha challenge triggered by AbuseFilter on mobile source editor.

Is it intentional that, after dismissing and attempting clicking Publish again, we don't go to the third page (whatever that is called) but stay on the preview page but without any loading indicator?

Jun 11 2026, 8:12 AM · MobileFrontend (MobileFrontend (Editor)), Product Safety and Integrity, MW-1.47-notes (1.47.0-wmf.8; 2026-06-23), hCaptcha, ConfirmEdit (CAPTCHA extension)

Jun 10 2026

dom_walden added a comment to T425929: Cannot publish after dismissing hCaptcha challenge triggered by AbuseFilter on mobile source editor.

@Dreamy_Jazz If I dismiss the challenge and go back to the editor page, when I try to submit again the challenge does not appear and I am stuck on the preview page. Reproduced on iPhone 17 Safari and Galaxy S10 and S25 Chrome, but not on my desktop Chromium.

Jun 10 2026, 1:52 PM · MobileFrontend (MobileFrontend (Editor)), Product Safety and Integrity, MW-1.47-notes (1.47.0-wmf.8; 2026-06-23), hCaptcha, ConfirmEdit (CAPTCHA extension)
dom_walden added a comment to T428437: hCaptcha widget not rendering after "warn" AbuseFilter consequence on desktop wikitext editor.

@kostajh One thing I notice is that if I trigger an AbuseFilter which has both the warn and showcaptcha consequences, I am shown the warning twice and have to fill in the hCaptcha challenge twice.

Jun 10 2026, 12:38 PM · Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)), MW-1.47-notes (1.47.0-wmf.5; 2026-06-02), Bot detection and mitigation (WE4.10 hCaptcha)
dom_walden added a comment to T427067: hCaptcha risk scores (MobileFrontend): Collect and submit risk scores when showing a blocked edit notice in the MobileFrontend.

I also note that I don't see it working on desktop WikiEditor on Firefox 57 and below and Chrome 62 and below, presumably for the same reason as T422222. Should we have a separate ticket for Basic support?

Jun 10 2026, 10:32 AM · Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)), Bot detection and mitigation (WE4.10 hCaptcha), ConfirmEdit (CAPTCHA extension), MobileFrontend (MobileFrontend (Editor))
dom_walden added a comment to T427784: hCaptcha risk scores for blocked account creations.

@kostajh How can I see this working? Should I see anything on the browser-side or is it all server-side?

Jun 10 2026, 10:28 AM · Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)), Bot detection and mitigation (WE4.10 hCaptcha)
dom_walden updated subscribers of T427067: hCaptcha risk scores (MobileFrontend): Collect and submit risk scores when showing a blocked edit notice in the MobileFrontend.

@Dreamy_Jazz @kostajh I haven't had much success so far getting this working on iOS or Android. So far, I have only seen it working on Galaxy S10 Android 9 Chrome. I have tried

  • Lots of iPhones including iPhone 17 iOS 26.5 Safari and Chrome
  • Samsung Galaxy S20 and S22 Chrome
Jun 10 2026, 10:11 AM · Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)), Bot detection and mitigation (WE4.10 hCaptcha), ConfirmEdit (CAPTCHA extension), MobileFrontend (MobileFrontend (Editor))

Jun 9 2026

dom_walden added a comment to T426476: DiscussionTools hCaptcha: When user encounters AbuseFilter hCaptcha challenge no indication is shown they need to resubmit their edit.

@Dreamy_Jazz I am finding on testwiki that if I have triggered an AbuseFilter, if I make another reply after (within 120s?), regardless of whether it triggers an AbuseFilter, I have to submit the form twice, and the second time I am not given an indication I need to resubmit.

Jun 9 2026, 1:10 PM · Product Safety and Integrity (Sprint Rose (Jun 15 - Jun 26)), MW-1.47-notes (1.47.0-wmf.5; 2026-06-02), Bot detection and mitigation (WE4.10 hCaptcha), DiscussionTools, hCaptcha, ConfirmEdit (CAPTCHA extension)