Page MenuHomePhabricator

Need security review for WikiGrok extension
Closed, ResolvedPublic

Description

Need to get a security review of the new WikiGrok extension so that it can be deployed to the cluster. This should be trivial as it's just a small API at this point.


Version: wmf-deployment
Severity: normal

Details

Reference
bz72567

Event Timeline

bzimport raised the priority of this task from to Needs Triage.Nov 22 2014, 3:53 AM
bzimport set Reference to bz72567.

I talked through the dataflow and interfaces for this with Kaldari and Max. The mobile team should continue to review each other's code for basic security flaws, but nothing in the architecture really concerns me.

One todo coming out of this is to invalidate the cache for fast campaigns when wikidata notifies of updates, so that deleted/suppressed wikidata items aren't displayed. But that doesn't need to block deployment.