Mon, Nov 7
Hey @Reedy, is it possible to get an estimate on which week in the quarter the review will be done?
Nov 4 2022
@sbassett, we'd like security's conceptual input and sign off on this task. We're implementing a Thanks Count dialog and we're considering querying the log_search table for ls_field => 'thankid', and use the ls_value column to get the information we need. As stated by Kosta, for privacy purposes, we're restricting access to current logged-in users only we users can only query results for themselves.
Oct 26 2022
Oct 17 2022
Yes and no. I'm not seeing any recent, formal security review for d3js, so we'd certainly need to perform some kind of review, especially if we're looking at d3js's main branch, as this request seems to possibly imply? That being said, we can't perform a line-by-line audit of d3js - that just isn't feasible for our team. So what would likely be performed is a vendor review with some additional layers of high-level pentesting and similar assessments. Some recent examples of these types of reviews can be found at T288768#7551991 and T262963#6668136.
@sbassett I'm okay with a medium risk assessment on beta deployments using this library, given that we want the feature to go live in the next weeks.
Aug 11 2022
Aug 3 2022
@Sgs: Just saw that IE 11 doesn't support this API: Intl.NumberFormat. Will that be something to worry about incase we decide to adopt the shortening?
Jul 25 2022
No problem, I just saw this: https://phabricator.wikimedia.org/T313393
@kostajh: Will we need any DBA help on this?
Jul 21 2022
Growth team won't be able to get to it immediately as we're short on capacity and may be so for the next Quarters. We'll save it in our maintenance epic so that it remains visible for action when capacity is available.
Jun 23 2022
May 16 2022
@Aklapper I was directed to the creation of URL forms and that worked for my use case. Thanks for following up.
May 12 2022
Apr 4 2022
Mar 30 2022
This is early on but the stakeholders would expect a CMS style or configurable landing page which can accommodate a couple of base templates to choose from given the work done in the past. This would allow them to generate their own landing page instead of having it hard coded every time there's an event. This idea would avoid bloating up the code base with a lot of temporary work and increase maintenance.
- Are there any stakeholders currently awaiting any new work/releases/bug fixes on this feature? The Campaigns team is pretty busy now, and we don't have any capacity to take on any more feature work in our current roadmap (and that won't change for a while).
- Is there any urgency regarding when we provide a response?
Mar 29 2022
Mar 23 2022
Mar 22 2022
I approve the request.
Nov 29 2021
@Tgr Can this be moved to Triaged? It appears no commitment is being made to it
Nov 8 2021
Sep 17 2021
Aug 30 2021
Aug 5 2021
Jul 28 2021
@Etonkovidova Thanks for the additional tests. I appreciate your effort and diligence in digging into this. Given that the Timeless skin is more likely to be used, we can schedule it for a bug fix for it.