From 4b5dbdabd8053b6be0124034cbf1b5e700106713 Mon Sep 17 00:00:00 2001
From: Chad Horohoe <chadh@wikimedia.org>
Date: Tue, 13 Mar 2018 18:43:30 +0000
Subject: [PATCH] SECURITY: Make 'newbie' limit in $wgRateLimits really
 override 'user' limit

The order of operations was incorrect.

Bug: T169545
Change-Id: Ia910aa2a494914d3b0017daac9ab294ea9fa8705
---
 RELEASE-NOTES-1.30     | 1 +
 includes/user/User.php | 9 +++++----
 2 files changed, 6 insertions(+), 4 deletions(-)

diff --git a/RELEASE-NOTES-1.30 b/RELEASE-NOTES-1.30
index bfbf1d2471..4cf34a3ef8 100644
--- a/RELEASE-NOTES-1.30
+++ b/RELEASE-NOTES-1.30
@@ -25,6 +25,7 @@ This is a security and maintenance release of the MediaWiki 1.30 branch.
 * (T193995) Fix undefined patchPath() method call in parser tests.
 * Special:BotPasswords now requires reauthentication.
 * (T191608, T187638) Add 'logid' parameter to Special:Log.
+* (T169545) $wgRateLimits entry for 'user' overrides that for 'newbie'.
 
 == MediaWiki 1.30 ==
 
diff --git a/includes/user/User.php b/includes/user/User.php
index 6115144d1b..9de3097940 100644
--- a/includes/user/User.php
+++ b/includes/user/User.php
@@ -1963,10 +1963,6 @@ class User implements IDBAccessObject {
 			if ( isset( $limits['user'] ) ) {
 				$userLimit = $limits['user'];
 			}
-			// limits for newbie logged-in users
-			if ( $isNewbie && isset( $limits['newbie'] ) ) {
-				$keys[$cache->makeKey( 'limiter', $action, 'user', $id )] = $limits['newbie'];
-			}
 		}
 
 		// limits for anons and for newbie logged-in users
@@ -1998,6 +1994,11 @@ class User implements IDBAccessObject {
 			}
 		}
 
+		// limits for newbie logged-in users (override all the normal user limits)
+		if ( $id !== 0 && $isNewbie && isset( $limits['newbie'] ) ) {
+			$userLimit = $limits['newbie'];
+		}
+
 		// Set the user limit key
 		if ( $userLimit !== false ) {
 			list( $max, $period ) = $userLimit;
-- 
2.17.1

