Page MenuHomePhabricator

Security review the Page Summary API in MCS
Closed, ResolvedPublic

Description

Ronseal.

Name of tool/project: Page Summary API
Description of the tool/project: The Page Summary API returns summaries of pages for Page-Previews, Android and iOS apps (near term), and the mobile web site (long term).
Description of how the tool will be used at WMF: See above.
Name of individual/group requesting review and primary contact: Sam Smith (Engineering Manager for Reading Web)
Name of individual/group responsible for tool/project after deployment and primary contact: See above.
Target date for deployment (or approximate date deployed if already in production or labs): 31st August, 2017
Information from any review of the tool that has already been conducted:

TBD

Working test environment:
Programming language(s) used: JavaScript (Node.js)
Source code repository location:: https://gerrit.wikimedia.org/r/#/admin/projects/mediawiki/services/mobileapps
WMF project home page (if applicable): https://wikitech.wikimedia.org/wiki/Mobileapps_(service)
Related Phabricator tickets: T168848: Bootstrap an initial version of the Page Summary API in MCS
Related patchset(s):

None… yet!

Event Timeline

Restricted Application added a subscriber: Aklapper. · View Herald Transcript

@Fjalapeno / @phuedx : Do you mind filling including in the summary the info requested at https://www.mediawiki.org/wiki/Wikimedia_Security_Team/Security_reviews#Requesting_a_review (In particular what's the gerrit project name for the code in question)

phuedx renamed this task from Security review the Page Preview API in MCS to Security review the Page Summary API in MCS.Jul 17 2017, 12:29 PM
phuedx updated the task description. (Show Details)

OK. I've filled out the template. I'll be responsible for making sure you're notified promptly when patchsets become available for review @Bawolff.

phuedx added a subscriber: bearND.

OK. I've filled out the template. I'll be responsible for making sure you're notified promptly when patchsets become available for review @Bawolff.

Sorry for not updating this task as promised when Readers Infra picked up building the service. @bearND let me know that security review of the Page Summary API is tracked in T182130. I'll be bold and close this task.