Page MenuHomePhabricator

Application Security Review Request : Extension:IPReputation
Open, Needs TriagePublic

Description

Project Information

Description of the tool/project: Provide access for fetching, logging, and acting on IP reputation data.

Description of how the tool will be used at WMF: Enrich event logging events with IP reputation metadata; provide a low-level interface for other callers to the IP reputation database; provide IP reptuation as a signal to other tools like AbuseFilter; be a potential place where mitigations on bad actors based on IP reputation could be enacted.

Dependencies

List dependencies, or upstream projects that this project relies on.

iPoid-Service

Has this project been reviewed before?

Please link to tasks or wiki pages of previous reviews.

The extension is currently https://gerrit.wikimedia.org/r/c/mediawiki/extensions/IPReputation/+/1010522 which is already deployed in production code (in CentralAuth) which was reviewed by other engineers at WMF already.

Working test environment

Please link or describe setup process for setting up a test environment.

Enable the extension, and set up an SSH tunnel to a deployment server (queries to ipoid should just work as the default URL config uses localhost:6035)

Post-deployment

Name of team responsible for tool/project after deployment and primary contact.

@kostajh and Trust and Safety Product Team

Details

Risk Rating
Low

Event Timeline

Hey @kostajh - Just wanted to check in and see if ext:IPReputation is ready for review or if you're planning any large, meaningful development cycles soon (and I should wait a bit). Thanks.

Hey @kostajh - Just wanted to check in and see if ext:IPReputation is ready for review or if you're planning any large, meaningful development cycles soon (and I should wait a bit). Thanks.

I think it is ready for review as is. Thanks!