Page MenuHomeMiraheze

Add "Scratch" to CSP whitelist
Closed, ResolvedPublic

Description

Add "scratch.mit.edu" to your CSP whitelist to allow Scratch projects to be embedded in "iframe".


  • Is the site equipped with a privacy policy? Yes
  • Does the site attempt to comply with the GDPR? Can European Union inhabitants invoke their individual rights? Yes, PP specifically mentions rights of users in the EEA
  • Does the site provide a list of personal data being collected by using the service? Yes
  • Is the website owner known to have a bad reputation regarding privacy? No
  • Will wikis stay usable, even if the visitor blocks the external resource by using an ad blocker? Yes
  • Is there a Data Protection Officer and/or Privacy Team that can be contacted by Miraheze? No but general help can be contacted help@scratch.mit.edu for GDPR enquires too
  • Is the site equipped with a security policy? No but part of PP
  • Does the site clarify their security measures to protect collected user data? Can the site assure measures are being taken to protect code injection into the loaded external resources? Somewhat, general assurances regarding security and some examples of measures
  • Is the website owner known to have a bad reputation regarding information security? No
  • Is there a Chief Information Security Officer and/or Security Team that can be contacted by Miraheze? No but general help can be contacted help@scratch.mit.edu

Event Timeline

Funa-enpitu updated the task description. (Show Details)
Funa-enpitu updated the task description. (Show Details)
Funa-enpitu updated the task description. (Show Details)
Reception123 added a project: Trust & Safety.
Reception123 added subscribers: Owen, Reception123.

Approved from my perspective, checklist is fulfilled and no concerns regarding privacy/security, especially since it's also part of MIT. Passing onto Trust & Safety for review.

The site is fully compliant with GDPR, has a good Privacy Policy, and fulfills all the requirements of the checklist so marking as approved from T&S' perspective.

OrangeStar renamed this task from Added "Scratch" to CSP whitelist to Add "Scratch" to CSP whitelist.Jan 20 2023, 17:24
John moved this task from DSRE Review to Completed on the CSP Review board.