Page MenuHomePhabricator

FRUP: Add Applepay verification code to donate wiki
Closed, ResolvedPublicSecurity

Description

For the FRUP integration, we need to add this file to https://donate.wikipedia.org/.well-known/apple-developer-merchantid-domain-association

Event Timeline

RhinosF1 subscribed.

Per #-sre, serviceops own the config to power this

RhinosF1 set Security to Software security bug.Sep 11 2023, 3:48 PM
RhinosF1 added projects: Security, Security-Team.
RhinosF1 changed the visibility from "Public (No Login Required)" to "Custom Policy".
RhinosF1 changed the subtype of this task from "Task" to "Security Issue".

Per the few failed attempts

@sbassett: can you make public?

I've discussed with @Damilare on IRC and there was no reason for this ever to be private. I've also explained how weirdly phab handles permissions.

Thanks @RhinosF1 and apologies for the escalation everyone. Like I mentioned in our chat, I wanted to keep the file private till I had confirmation about what the right visibility should be. A case of erring on the side of caution I guess.

sbassett changed Author Affiliation from N/A to WMF Advancement.
sbassett changed the visibility from "Custom Policy" to "Public (No Login Required)".
sbassett changed Risk Rating from N/A to Low.
sbassett edited projects, added SecTeam-Processed; removed Security-Team, Security.

A case of erring on the side of caution I guess.

The Security-Team is always fine with this approach :)

greg raised the priority of this task from Low to Needs Triage.Sep 13 2023, 4:43 PM
greg subscribed.

(resetting prio, looks like a mistake given security is done with this right now)

(resetting prio, looks like a mistake given security is done with this right now)

Whoops, yes, sorry!

Change 957744 had a related patch set uploaded (by Alexandros Kosiaris; author: Alexandros Kosiaris):

[operations/mediawiki-config@master] Add /.well-known/apple-developer-merchantid-domain-association

https://gerrit.wikimedia.org/r/957744

Change 957750 had a related patch set uploaded (by Alexandros Kosiaris; author: Alexandros Kosiaris):

[operations/puppet@production] donate: Move into dedicated docroot

https://gerrit.wikimedia.org/r/957750

Thanks @akosiaris, please let me know if there's anything I can do to help with this also.

Change 957744 merged by jenkins-bot:

[operations/mediawiki-config@master] Add /.well-known/apple-developer-merchantid-domain-association

https://gerrit.wikimedia.org/r/957744

Change 957750 merged by Alexandros Kosiaris:

[operations/puppet@production] donate: Move into dedicated docroot

https://gerrit.wikimedia.org/r/957750

akosiaris claimed this task.

https://donate.wikipedia.org/.well-known/apple-developer-merchantid-domain-association now, in my checks, returns the contents of the file in this task. It might take a bit more (up to 30 minutes) to propagate everywhere. I am resolving this task, feel free to reopen to report issues.

Thanks @akosiaris, I can also confirm that the content of the file is now being displayed in that directory.