Page MenuHomePhabricator

Possibly deny X-domain access to restbase instance in citoid?
Closed, DeclinedPublic

Description

As per our agreement with WorldCat, we may need to block X-domain requests between wikis and their respective restbase installation of citoid. However it is not clear from the text whether this is necessary or not.

Event Timeline

Mvolz updated the task description. (Show Details)

Hmm, maybe. Not sure this'll be needed?

Which cross-domain requests are you referring to? Citoid requests that go through RESTBase are on the same domain. Then, it is Citoid (from inside prod) that calls WorldCat.

Which cross-domain requests are you referring to? Citoid requests that go through RESTBase are on the same domain. Then, it is Citoid (from inside prod) that calls WorldCat.

This is about external (non-wiki) requests for the data.

Mvolz removed a project: WMF-Legal.