See security and admin tracking bug for the EducationProgram extension: T45975
Some of these issues also affect the Wiki Education Foundation's app, as it will be adapted to run on additional Wikimedia projects and WMF hosting.
See security and admin tracking bug for the EducationProgram extension: T45975
Some of these issues also affect the Wiki Education Foundation's app, as it will be adapted to run on additional Wikimedia projects and WMF hosting.
| Status | Subtype | Assigned | Task | ||
|---|---|---|---|---|---|
| Resolved | Ragesoss | T127803 Release Programs dashboard 1.0 | |||
| Invalid | None | T128250 Release Programs dashboard 1.0 beta | |||
| Open | None | T125433 [Epic] Open security and admin issues with the WMF wikiedu dashboard | |||
| Open | None | T126066 Edit history is not available to admins | |||
| Restricted Task |
Why has this task been added to WMF-NDA instead of setting the "Security" dropdown to "Software security bug"?
Warning: I'm making this task public again. Nothing confidential happened here, and I've converted it into an epic to gather together subtasks.
The thought behind starting in labs was that we've limited time/resources to get this up and running in the next month, but it was possibly a poor assumption on my part that doing so would mean substantially less coordination with ops/security around hardware procurement and initial review. Since we're already committing time to security review in this initial phase, would it make more sense to just go for broke and start the conversation with ops around 100% production-ization?
@Nemo_bis sent an essay that will help guide our work:
https://www.mediawiki.org/wiki/Everything_is_a_wiki_page
Maybe we should talk more about using Wikibase (not the Wikidata instance) as the data store rather than MySQL? This gives us all of the wiki goodness.
rm tag Security . imo that tag should probably not be used for tracking bugs unless the thing they are tracking is a specific issue