Last modified: 2014-10-29 18:34:08 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T74567, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 72567 - Need security review for WikiGrok extension
Need security review for WikiGrok extension
Status: RESOLVED FIXED
Product: Wikimedia
Classification: Unclassified
Extension setup (Other open bugs)
wmf-deployment
All All
: Unprioritized normal (vote)
: ---
Assigned To: Chris Steipp
:
Depends on:
Blocks: 72465
  Show dependency treegraph
 
Reported: 2014-10-27 17:38 UTC by Ryan Kaldari
Modified: 2014-10-29 18:34 UTC (History)
1 user (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description Ryan Kaldari 2014-10-27 17:38:00 UTC
Need to get a security review of the new WikiGrok extension so that it can be deployed to the cluster. This should be trivial as it's just a small API at this point.
Comment 2 Chris Steipp 2014-10-29 18:34:08 UTC
I talked through the dataflow and interfaces for this with Kaldari and Max. The mobile team should continue to review each other's code for basic security flaws, but nothing in the architecture really concerns me. 

One todo coming out of this is to invalidate the cache for fast campaigns when wikidata notifies of updates, so that deleted/suppressed wikidata items aren't displayed. But that doesn't need to block deployment.

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links