Its been suggested we should make an abusefilter banning adding external scripts to foundationwiki to prevent employees from accidentally violating privacy policy.
Other alternatives is enabling CSP whenever that becomes ready.
Its been suggested we should make an abusefilter banning adding external scripts to foundationwiki to prevent employees from accidentally violating privacy policy.
Other alternatives is enabling CSP whenever that becomes ready.
| Subject | Author | Repo | Branch | Lines +/- | |
|---|---|---|---|---|---|
| Add a CSP policy to foundationwiki to prevent privacy breach | Brian Wolff | operations/mediawiki-config | master | +12 -0 |
Change 341259 had a related patch set uploaded (by bawolff):
[operations/mediawiki-config] Add a CSP policy to foundationwiki to prevent privacy breach
Sometimes a close tag is missing before the next open tag. I don't care too much one way or the other though.
Change 341259 merged by jenkins-bot:
[operations/mediawiki-config] Add a CSP policy to foundationwiki to prevent privacy breach
Mentioned in SAL (#wikimedia-operations) [2017-03-06T14:37:16Z] <addshore@tin> Synchronized wmf-config/CommonSettings.php: SWAT: [[gerrit:341259|Add a CSP policy to foundationwiki to prevent privacy breach]] T159386 (duration: 00m 39s)
Hmm. Looks like the testing CSP policy would block the mobile tracking beacon since wikimediafoundation.org is not a valid img-src when viewing from m.wikimediafoundation.org [Or what I'm assuming is the beacon, could be something else]