Page MenuHomePhabricator

Security Readiness Review for SD Image Recommendations UI
Closed, InvalidPublic

Description

Project Information

  • Name of tool/project: SDAW - ImageRecommendations
  • Project home page: TBD
  • Name of team requesting review: Structured Data
  • Primary contact: Carly Bogen
  • Target date for deployment: TBD, likely Q1 2021-2022
  • Link to code repository / patchset: TBD

Description of the tool/project:

The Structured Data team will be using the Image Recommendations API to build a new interface for helping experienced users add images to Wikipedia articles.

Description of how the tool will be used at WMF:

TBD

Dependencies

TBD

Has this project been reviewed before?

No

Working test environment

TBD

Post-deployment

Structured Data team: manager Mark Holmquist, tech lead Cormac Parle

Note

This is obviously very light in detail at the moment, but we are putting in the request so that we can get in the queue for a review.

Event Timeline

Restricted Application added a subscriber: Aklapper. · View Herald Transcript
sbassett changed the task status from Open to Stalled.Mar 23 2021, 8:49 PM
sbassett triaged this task as Lowest priority.
sbassett subscribed.

Backlogged and stalled to await completion of review template.

Backlogged and stalled to await completion of review template.

Does this mean we're no longer on track to be finished with the review by March 31?

Backlogged and stalled to await completion of review template.

Does this mean we're no longer on track to be finished with the review by March 31?

Nevermind, I thought this was a different task, sorry about that!

Nevermind, I thought this was a different task, sorry about that!

No problem. And yes, I hope to have T266513 completed by next Monday at the latest.

@CBogen is this planned to be deployed in the next quarter or two?

@Mstyles at the moment we're targeting deployment in Q2, yes.

@CBogen Q2 beginning in Oct 1 2021? If that's the case, we'll probably want to schedule the review closer to the deployment date.

@CBogen Q2 beginning in Oct 1 2021? If that's the case, we'll probably want to schedule the review closer to the deployment date.

Yep, things got a little delayed. That sounds good!

Hi @CBogen can we get an update on this project? Perhaps an updated description if this project is still slated to be deployed this quarter.

Hi @CBogen can we get an update on this project? Perhaps an updated description if this project is still slated to be deployed this quarter.

Sorry, we had a lot of team turnover and things got even more delayed. T292142 is the epic for this work - there's a lot more detail in the linked Product Requirements Document and subtasks. We're just now starting engineering work in the next few weeks. The only thing we're planning on releasing right now for a UI is notifications - does that require a security review?

@CBogen if the UI code is more than a couple of files, then a security review could be necessary. Do you have a link to the code?

@CBogen if the UI code is more than a couple of files, then a security review could be necessary. Do you have a link to the code?

The code doesn't exist yet - the team has only just started estimating tickets, etc. It'll be a few more weeks at minimum before we have any code. The UI would just be echo notifications.

@CBogen if it's just notifications, I don't think that needs a review. I'll put this ticket in Back Orders for now, and let us know if/when there's more code to be reviewed. Does that work?

@CBogen if it's just notifications, I don't think that needs a review. I'll put this ticket in Back Orders for now, and let us know if/when there's more code to be reviewed. Does that work?

Sounds good, thank you!

@CBogen - Hello. Just wondering if there were any updates on the status of this project and when it might be ready for security review. If the answer is "it's done" or "soon", we can likely still fit it into our accepted reviews for this quarter (Q3 2022, January to March 2022). Thanks.

It's just notifications for now so I think we can close this task! I'll open a new one if we end up working on a UI.

It's just notifications for now so I think we can close this task! I'll open a new one if we end up working on a UI.

Great, thanks.