Page MenuHomePhabricator

dbtree.wikimedia.org uses CDN from Google and jQuery
Closed, DuplicatePublic

Description

<script type="text/javascript" src="https://code.jquery.com/jquery-1.9.1.js"></script>
<script type="text/javascript" src="https://www.google.com/jsapi"></script>
<script type="text/javascript" src='https://www.google.com/jsapi?autoload={"modules":[{"name":"visualization","version":"1","packages":["corechart","table","orgchart"]}]}'></script>

Wikimedia general practices frown upon code loaded from 3rd party, as it's as risk for man in the middle attack (there is not integrity hash here) and privacy.

Event Timeline

Dereckson created this task.Jul 8 2016, 3:50 PM
Restricted Application added subscribers: Zppix, Aklapper. · View Herald TranscriptJul 8 2016, 3:50 PM

Change 298011 had a related patch set uploaded (by Dereckson):
Serve jQuery locally

https://gerrit.wikimedia.org/r/298011

Aklapper renamed this task from dbtree.wikikimedia.org uses CDN from Google and jQuery to dbtree.wikimedia.org uses CDN from Google and jQuery.Jul 11 2016, 2:20 PM
ZhouZ added a subscriber: ZhouZ.
Restricted Application added a subscriber: JEumerus. · View Herald TranscriptJul 18 2016, 6:30 PM
ZhouZ moved this task from Backlog to Assigned on the WMF-Legal board.Jul 18 2016, 10:38 PM

Change 298011 abandoned by Dereckson:
Serve jQuery locally

Reason:
Done in d90f90b.

https://gerrit.wikimedia.org/r/298011