Page MenuHomePhabricator

outreachdashboard.wmflabs.org violates Labs ToS
Closed, ResolvedPublic

Description

Going to https://outreachdashboard.wmflabs.org/training loads

https://fonts.googleapis.com/css?family=Source+Sans+Pro:300,400,600
https://fonts.googleapis.com/css?family=Open+Sans:300,400,600,700
https://fonts.gstatic.com/s/opensans/v15/mem5YaGs126MiZpBA-UNirkOUuhp.woff2
https://fonts.gstatic.com/s/sourcesanspro/v11/6xK3dSBYKcSV-LCoeQqfX1RYOo3qOK7l.woff2
https://fonts.gstatic.com/s/sourcesanspro/v11/6xKydSBYKcSV-LCoeQqfX1RYOo3ik4zwlxdu.woff2
https://fonts.gstatic.com/s/sourcesanspro/v11/6xKydSBYKcSV-LCoeQqfX1RYOo3i54rwlxdu.woff2
https://fonts.gstatic.com/s/opensans/v15/mem8YaGs126MiZpBA-UFVZ0b.woff2
https://fonts.gstatic.com/s/opensans/v15/mem5YaGs126MiZpBA-UNirkOUuhp.woff2
https://cdn.tinymce.com/4/tinymce.min.js
https://wikiedu.org/analytics/piwik.js

By doing so it violates https://wikitech.wikimedia.org/wiki/Wikitech:Cloud_Services_Terms_of_use, in particular point #6 of What can and can’t be done with user information?: "Not share any Private Information outside of your Cloud Services Project", but also point #3 "Get express authorization from the End Users for the collection", #1 and #2, and probably others.
See J65 and T172065.

Related Objects

StatusSubtypeAssignedTask
OpenNone
OpenNone
OpenNone
OpenNone
ResolvedKenrick95
ResolvedDanmichaelo
OpenNone
ResolvedAsh_Crow
ResolvedKrinkle
OpenNone
ResolvedJarry1250
ResolvedAddshore
ResolvedSurlycyborg
OpenNone
ResolvedYarl
ResolvedBeta16
Resolvedferveo
ResolvedTheresNoTime
ResolvedEmijrp
ResolvedMyst
ResolvedEarwig
OpenNone
ResolvedFnielsen
OpenNone
ResolvedNone
ResolvedRicordisamoa
OpenNone
ResolvedRanjithsiji
OpenNone
ResolvedEpantaleo
OpenNone
ResolvedFastily
InvalidNone
OpenNone
OpenNone
Resolvedvalhallasw
ResolvedFramawiki
Declinedbd808
ResolvedCyberpower678
ResolvedSymac
ResolvedNone
ResolvedxSavitar
ResolvedTheresNoTime
ResolvedAhecht
ResolvedJackPotte
ResolvedAviator
OpenNone
OpenNone
OpenNone
OpenNone
ResolvedKrinkle
ResolvedTheDJ
Resolvedyuvipanda
ResolvedMatthewrbowker
Resolvedjrbs
ResolvedSamwilson
OpenNone
ResolvedMusikAnimal
ResolvedMooeypoo
ResolvedTheresNoTime
OpenNone
ResolvedPintoch
ResolvedFramawiki
ResolvedMaxSem
OpenNone
ResolvedSlashme
ResolvedIncola
OpenNone
ResolvedKenrick95
ResolvedTgr
ResolvedBenjavalero
ResolvedRicordisamoa
ResolvedFramawiki
OpenNone
ResolvedMmarx
Resolved Prtksxna
ResolvedArlolra
ResolvedFastily
ResolvedSuperHamster
ResolvedFramawiki
ResolvedIjon
ResolvedSmalyshev
ResolvedFnielsen
ResolvedFramawiki
OpenNone
OpenNone
Resolvedcdrini
ResolvedTarrow
ResolvedDB111
ResolvedRicordisamoa
OpenNone
ResolvedxSavitar
OpenNone
OpenNone
OpenNone
ResolvedRLuts
ResolvedEmijrp
ResolvedSamwilson
Resolved jmatazzoni
ResolvedSamwalton9-WMF
Resolveddbarratt
ResolvedLegoktm
ResolvedHusky
ResolvedMagnus
ResolvedKolossos
ResolvedLokal_Profil
OpenNone
ResolvedFramawiki
Resolvedsamuelguebo
ResolvedRagesoss
OpenNone
ResolvedRammanojpotla
ResolvedRagesoss
OpenNone
Resolvedthcipriani
Resolvedsrishakatux
ResolvedPremeditated
ResolvedWMDE-leszek
OpenNone
ResolvedDanilo
ResolvedDineshkarthik
Resolvedsimon04
OpenNone
ResolvedEderporto
OpenNone
OpenNone
OpenNone
OpenNone
OpenEugene233
OpenNone

Event Timeline

Restricted Application added a subscriber: Base. · View Herald TranscriptDec 2 2018, 3:37 PM
Aklapper added a subscriber: Krenair.

@Krenair: I don't see why this should be tagged WMF-Legal or cloud-services-team. It's up to maintainers of that instance and the Toolforge-standards-committee which are already on the parent task of https://phabricator.wikimedia.org/maniphest/?parentIDs=172065 .

As far as I know Toolforge-standards-committee is unrelated, this is not tools.wmflabs.org. Seeing as this task is asserting that a project is violating the WMCS ToU, cloud-services-team and WMF-Legal are definitely relevant.

Thanks for identifying these problems!

I've got a set of patches in progress that should get rid of all these cases of loading assets from 3rd parties: https://github.com/WikiEducationFoundation/WikiEduDashboard/pull/2271

I'm hoping to deploy it later today.

I've deployed those changes, and I think it takes care of all those cases.

Aklapper assigned this task to Ragesoss.

Yes, this all looks good to me. Thanks for the quick reply and action!

sbassett triaged this task as Medium priority.Oct 16 2019, 4:38 PM
sbassett moved this task from Intake to Done on the Privacy board.