Page MenuHomePhabricator

Application Security Review Request : Citoid-Service adding pdf-parse and backing pdfjs-dist NodeJS dependencies
Open, Needs TriagePublic

Description

Project Information

Description of the tool/project:
WMDE's Technical Wishes team is currently looking into adding PDF support to the Citoid service. For that we're exploring how the service can read metadata properties from PDF files to allow users to create more valuable citations.
See T424982: Investigate feasibility of Citoid supporting PDF sources.

The POC patch linked above adds two new dependencies to the service that would be used to extract the needed information from the user provided PDF content. A quick exchange with Product Safety and Integrity brought us here to evaluate these dependencies before taking further steps.
See T430305: RfC: Citoid service performance assessment for PDF parsing feature

Description of how the tool will be used at WMF:
Used whenever users use an URI pointing to a PDF file in the automatic citaiton generation as part of the Citoid extension.

Dependencies

List dependencies, or upstream projects that this project relies on.

The dependencies that need to be checked would be
Primary

Secondary ( we're probably fine without that, it's just a wrapper for the former )

Has this project been reviewed before?

Please link to tasks or wiki pages of previous reviews.

Not clear to me

Working test environment

Please link or describe setup process for setting up a test environment.

See https://www.mediawiki.org/wiki/Citoid

Post-deployment

Name of team responsible for tool/project after deployment and primary contact.

WMDE-TechWish / https://meta.wikimedia.org/wiki/WMDE_Technical_Wishes

Details

Risk Rating
Low

Event Timeline

Just as a note: It's probably possible to cut down on the pdf-parse dependency here and use pdfjs directly, if that makes things easier.

The teams at WMDE and WMF have come to the conclusion to decline T431688: Look into alternatives to parse PDF metadata not using NodeJS and pursue the approach recommended by @Clement_Goubert here.

We would like to go ahead with this security review (outlined in the task above) and appreciate if the SRE team could give us an estimate on when this could be picked up so that we can plan next steps and deployment timelines with the community.

Thanks so much!

We would like to go ahead with this security review (outlined in the task above) and appreciate if the SRE team could give us an estimate on when this could be picked up so that we can plan next steps and deployment timelines with the community.

Hi @Lina_Farid_WMDE just to clarify, SRE needs to wait for the outcomes of the security team review.

Then based on the identified changes we can cost estimate and assess when works can be planned.

Hi @Rsilvola, what is the expected turnaround for the security review?
CC @Lina_Farid_WMDE

Hello! The team is currently at capacity and is working through other reviews. Once we have available capacity, we will get in touch with you. Thank you for your understanding.

Just to let you know, an engineer has been assigned for the review and is expected to get in touch with you in the coming weeks.