Page MenuHomeMiraheze

CSP related issue for geohack.toolforge.com on FAMEPedia
Closed, DeclinedPublic

Description

Per subject, taking this page for an example, on clicking the globe-with-arrow it shows content blocked, so it seems like it's a csp issue.


CSP REVIEW

  • Is the site equipped with a privacy policy? https://wikitech.wikimedia.org/wiki/Wikitech:Cloud_Services_Terms_of_use#What_can_and_can%E2%80%99t_be_done_with_user_information?
  • Does the site attempt to comply with the GDPR? Can European Union inhabitants invoke their individual rights? Not applicable so not required as no PII should be stored long enough
  • Does the site provide a list of personal data being collected by using the service? In theory none but it depends on the tool so not properly
  • Is the website owner known to have a bad reputation regarding privacy? WMCS, no. Individual maintainers could and can change easily.
  • Can wikis use the external service, even if the visitor wants to deny any cookies or other form of tracking? Very likely but depends on tool.
  • Will wikis stay usable, even if the visitor blocks the external resource by using an ad blocker? Yes
  • Is there a Data Protection Officer and/or Privacy Team that can be contacted by Miraheze? Same as Wikimedia to a degree
  • Is the site equipped with a security policy? Covered by WMF Security team/Policies & WMCS Staff/Volunteers
  • Does the site clarify their security measures to protect collected user data? Can the site assure measures are being taken to protect code injection into the loaded external resources? Yes some cloud wide policies are enforce but very little guarntee of proper code practice so some issues more likely
  • Is the website owner known to have a bad reputation regarding information security? WMF/WMCS: no, Indivdual maintainers could
  • Is there a Chief Information Security Officer and/or Security Team that can be contacted by Miraheze? WMF Security & WMCS admins

Event Timeline

Excelsis triaged this task as Normal priority.Oct 9 2021, 18:33
Excelsis created this task.

Can confirm, gets

ERR_BLOCKED_BY_CSP

upon click.

Used in English Wikipedia, iirc.

RhinosF1 moved this task from SRE Review to T&S Review on the CSP Review board.
RhinosF1 added a subscriber: Owen.

Passing to @Owen but it's not recommended by WMF sysadmins for their production so us poses same risks

Bukkit closed this task as Declined.EditedOct 9 2021, 19:54

Per -offtopic

"If it’s not passing at SRE stage, there’s no point sending it across for T&S review as SRE are in policy as having ‘final’ say"

This, AFAIK, is supposed to pass this review..... Even from SRE

Unknown Object (User) moved this task from T&S Review to SRE Review on the CSP Review board.Oct 10 2021, 05:40

If it doesn't pass SRE review it probably shouldn't be moved to T&S review.

Unknown Object (User) added a comment.EditedOct 10 2021, 05:40

I don't personally agree this should be approved though. I'm not even sure the usecase is necessary here, there may be a way around it.

RhinosF1 claimed this task.

We've said we're not happy with it.

💔💔So what about Google, Bing or OpenStreet Maps?

In T8131#164010, @Ugochimobi wrote:

💔💔So what about Google, Bing or OpenStreet Maps?

They can be reviewed if needed. They're far better than toolforge.