Page MenuHomePhabricator

Get Oliver Keyes access to Google Webmaster Tools for all Wikimedia domains
Closed, DeclinedPublic

Description

@Ironholds needs access to Google Webmaster Tools, as he's the Data Analyst in the Search and Discovery Department and needs to look at the data that Google makes available to use regarding search.

@Tfinc, Oliver's manager, can vouch for this request.

Event Timeline

Deskana raised the priority of this task from to Needs Triage.
Deskana updated the task description. (Show Details)
Deskana subscribed.
Deskana renamed this task from Get Oliver access to Google Webmaster Tools to Get Oliver Keyes access to Google Webmaster Tools for all Wikimedia domains.Jun 3 2015, 1:14 PM
Deskana updated the task description. (Show Details)
Deskana set Security to None.
Deskana updated the task description. (Show Details)
chasemp triaged this task as Medium priority.Jun 3 2015, 1:42 PM

Hopefully @Dzahn can help clarify but my understanding is previous requests were more dialed down to specifics. There is something like 700 domains that have to be selected by hand (no api interaction).

@chasemp Yes, there are only 2 options, we prefer to delegate access to the needed domains, so that would need a specific list of sites and can't be just "all".

If that is not possible we have to share the noc@ account password. For that let me copy/paste the warning message from the relevant password file on iron:

Google account for Google Webmaster Tools

Make sure you know what you're doing when
using Google Webmaster Tools.

In order to have individual accountability,
*delegate* Google Webmaster Tools access
from the noc@wikimedia.org Google Webmaster
Tools console to an @wikimedia.org Google
Apps account, the person behind which is
a WMF employee or agent under NDA. Use that
delegated account to take Google Webmaster
Tools actions on sites defined under the
noc@wikimedia.org Google Webmaster Tools
profile. Define sites using the
noc@wikimedia.org account, but use the
delegated account for taking other actions
on the actual sites.

Only WMF employees or those with an NDA
may be delegated Google Webmaster Tools
access from the noc@wikimedia.org Google
Webmaster Tools console.

If you believe your account delegated
Google Webmaster Tools access has been
breached, contact ops immediately to have
delegation revoked while you restore
your access. Similar logic applies to
a computer breach involving a computer
that you use to login to @wikimedia.org
Google Apps.

# !!! DO NOT TURN ON 2-FACTOR AUTHENTICATION !!!
# !!! You may be prompted for a phone number for
# !!! an SMS as an anti-bruteforcing control,
# !!! and it's fine to use your own number there,
# !!! but do NOT turn on 2-factor authentication
# !!! if prompted with the option subsequently.
# !!! In case the account is inaccessible,
# !!! reach out to core ops to engage with
# !!! office IT for a password change.
# !!! Then set a strong random password and
# !!! document it here. The Mac utility Keychain
# !!! at max length with FIPS strength suffices.

Separately there is also an issue that we reached the Google limit of 1000 sites. We can't add any new ones currently.

Also see T98283 and T99132

We're concerned with search across all of our sites, so he does need access for all of them. Please action accordingly.

chasemp changed the task status from Open to Stalled.Jun 8 2015, 8:56 PM

I sent an email to most of the Search folks about decoupling this process from Ops access request process. Specifically, adding restricted users who need RO access to the data. Is this something you guys have time to discuss?

@chasemp Thanks so much for looking into this! I've been a bit backlogged for the past few days. Sorry about that. I'm hoping to respond to your email within the next few days.

@chasemp I responded to your email a while back and said your plan sounded good. Do you need anything else from me or the Discovery Department to proceed with this? Thanks!

@chasemp I responded to your email a while back and said your plan sounded good. Do you need anything else from me or the Discovery Department to proceed with this? Thanks!

moving to @chasemp

@Deskana, nope go ahead and use the credentials you have now to fulfill the agreed upon type of requests (Like this one) and I will make a ticket for transitioning to a SAD account and reclaiming noc@ for emergency / ops use.

Taking out of the sprint, because I'm clearly not finding time to get around to this.

This is actively blocking a quarterly goal. @Deskana could you carve out some time?

I plan to do this on Friday 6th November.

I'm pretty confident I have everything I need to do this now. Finally. I'll try to get it to tomorrow.

Given that Oliver no longer works for the Wikimedia Foundation, I don't see this happening. Heh.