Page MenuHomeMiraheze

CSP review: wiki.hausos.co
Closed, ResolvedPublic

Description

wiki.hausos.co - CSP domain addition please.

Hiya. Could we add *.gofundme.com (specifically for https://www.gofundme.com/static/js/embed.js?_=1630651456131) to the script-src CSP list please.

Thank you so much.

J.


CSP REVIEW

  • Is the site equipped with a privacy policy? https://www.gofundme.com/privacy#contact
  • Does the site attempt to comply with the GDPR? Can European Union inhabitants invoke their individual rights? DP Team contactable by General Support
  • Does the site provide a list of personal data being collected by using the service? Yes, very detailed
  • Is the website owner known to have a bad reputation regarding privacy? No indication on google
  • Can wikis use the external service, even if the visitor wants to deny any cookies or other form of tracking? May prevent use of the site
  • Will wikis stay usable, even if the visitor blocks the external resource by using an ad blocker?
  • Is there a Data Protection Officer and/or Privacy Team that can be contacted by Miraheze? Via general support, address given
  • Is the site equipped with a security policy? https://www.gofundme.com/c/security
  • Does the site clarify their security measures to protect collected user data? Can the site assure measures are being taken to protect code injection into the loaded external resources? Looks like it, mentions protecting user data
  • Is the website owner known to have a bad reputation regarding information security? No obvious issues
  • Is there a Chief Information Security Officer and/or Security Team that can be contacted by Miraheze? Bugcrowd form for reporting issues, otherwise no

Event Timeline

Unknown Object (User) triaged this task as Normal priority.Sep 3 2021, 07:24
Unknown Object (User) updated the task description. (Show Details)

Hi @Universal_Omega

Forgive me if I misunderstand - would you like me to run through that checklist and fill it in... (happy to do so, obs) and if so, when it talks about "site", presumably you're referring to gofundme.com?

No a member of SRE has to complete it

RhinosF1 updated the task description. (Show Details)
RhinosF1 moved this task from SRE Review to T&S Review on the CSP Review board.

I can't see any issues. I'd rather just whitelist www. Than * though.

Passing to T&S

Unknown Object (User) added a comment.Sep 3 2021, 08:00

I can't see any issues. I'd rather just whitelist www. Than * though.

Passing to T&S

Yes I agree, we shouldn't whitelist wildcards unless absolutely necessary in my opinion.

In T7962#160499, @Universal_Omega wrote:

I can't see any issues. I'd rather just whitelist www. Than * though.

Passing to T&S

Yes I agree, we shouldn't whitelist wildcards unless absolutely necessary in my opinion.

For as small of a bit of JS, it could probably be copied straight on wiki in all honesty.

Jim: Could you see if that's possible?

Surely that will just hit a different (iframe - looking at the code) CSP when it makes an API request? (It's a "woo, we've raised $3 in six months" widget..)

I'll give it a whiz anyway.

Reception123 renamed this task from New domain for CSP to CSP review: wiki.hausos.co .Sep 3 2021, 08:13

So... no dice.

Good news - the javascript is nonsense.. it just writes an <iframe> 🤦‍♂️

Bad news - that just hits the default-src CSP (there doesn't seem to be a frame-src CSP)

... so I'm going to have to ask for the CSP change anyway, if that's okay?

I think that will be fine, yes, thanks. Looking at the iFrame's requests they're all www.

Hi @RhinosF1 - do we know when this can be looked at? Is it quite an intricate thing to implement?

Just trying to plan some social activity for today and will push people elsewhere if the banner won't be ready/available.

Hi @RhinosF1 - do we know when this can be looked at? Is it quite an intricate thing to implement?

Just trying to plan some social activity for today and will push people elsewhere if the banner won't be ready/available.

Sorry about the delay, this is currently waiting on our Trust & Safety team to review.

No worries. Know everyone's volunteering their time and not familiar with the protocols yet 🙌 ...

Owen subscribed.

I agree with the assessment above.

Awesome. thanks. Does this mean that it can now be added? Does anyone need anything further from me at this point?

@jimbomorrison There's nothing left for you to do, it still needs an approval from @John (the other EM) and then it can be added.

John claimed this task.
John moved this task from EM Review to Completed on the CSP Review board.