Namespace restriction for source= queries is inert: smwAskParserFunction/smwShowParserFunction hooks do not exist
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 45/100
Research direction
Start in src/HookRegistry.php and inspect the registered smwAskParserFunction and smwShowParserFunction handlers. Check whether a supported Semantic MediaWiki hook can inspect or override #ask and #show calls, then review HookRegistryTest.php. Done means the namespace restriction works through a supported path, or the dead handlers and documentation are updated, with regression coverage.
Written by the indexing model from the issue text.
Description
Summary
HookRegistry registers handlers for two hook names — smwAskParserFunction and smwShowParserFunction — that do not exist in Semantic MediaWiki. As a result, the feature they implement (restricting source= queries to $seqlgExternalQueryEnabledNamespaces) never runs.
Details
src/HookRegistry.php registers a handler under both names:
$this->handlers['smwAskParserFunction'] = $this->handlers['smwShowParserFunction'] = static function ( $parser, $frame, $args, &$override ) {
// ... sets:
// $override = 'Warning: source parameter is not allowed in the namespace!'
// when the page's namespace is not in $GLOBALS['seqlgExternalQueryEnabledNamespaces']
};
This only does anything if Semantic MediaWiki fires hooks literally named smwAskParserFunction / smwShowParserFunction. Those names appear nowhere in the Semantic MediaWiki source tree, nor anywhere in its Git history, so the handlers are never invoked. The #ask / #show execution path (AskParserFunction / ShowParserFunction) does not run a hook of that name.
Impact
The $seqlgExternalQueryEnabledNamespaces namespace restriction is silently inert: a {{#ask: … |source=… }} (or {{#show:}}) query is not blocked in disallowed namespaces, contrary to what the setting documents.
This is pre-existing (identical on the current released code and on the SMW 7.0 branch) and was discovered during the SMW 7.0 migration (#44). The test suite does not catch it because HookRegistryTest only asserts the InterwikiLoadPrefix handler is registered, not that the ask/show guard fires.
Suggested next steps
- Confirm whether Semantic MediaWiki exposes an equivalent hook in a supported version that allows inspecting/overriding
#ask/#showparser-function invocations, and rewire the namespace guard to it; or - If no such hook exists, remove the dead handlers and either implement the namespace restriction by another mechanism or update the
$seqlgExternalQueryEnabledNamespacesdocumentation accordingly. - Add test coverage for whichever path is chosen so the guard cannot silently regress again.
- Dominant language
- PHP
- Stars
- 9
- Forks
- 8
- PR merge metrics
- No merged PRs in 30d
Getting set up
This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from SemanticMediaWiki/SemanticExternalQueryLookup
-
Difficulty 5/5 Over a week Newbie friendliness 25/100
-
Difficulty 3/5 1-2 days Newbie friendliness 35/100
-
Difficulty 4/5 3-5 days Newbie friendliness 35/100
-
bug
Difficulty 3/5 1-2 days Newbie friendliness 45/100
SemanticMediaWiki/SemanticExternalQueryLookup#33 · 1 comment · 1 reaction ·
-
enhancement
Difficulty 4/5 3-5 days Newbie friendliness 35/100
SemanticMediaWiki/SemanticExternalQueryLookup#28 · 6 comments ·
All issues in SemanticMediaWiki/SemanticExternalQueryLookup
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
Maintainers usually reply within 3 days
-
Difficulty 1/5 Under an hour Newbie friendliness 90/100
Maintainers usually reply within 1 day
-
[Sync EN] Fix session read handler docs: false reports a failure, not a missing session (#5902)Opensync-en
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 1 day
-
[Sync EN] Fix session read handler docs: false reports a failure, not a missing session (#5902)Opensync-en
Difficulty 2/5 1-2 days Newbie friendliness 84/100
Maintainers usually reply within 2 days
-
feature-request needs-triage
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
aws/aws-sdk-php#3365 ·
Maintainers usually reply within 1 day