Page MenuHomeMiraheze

Whitelist GoogleAPIs
Closed, ResolvedPublic

Description

Apparently storage.googleapis.com (and possibly other googleapis.com domains) were whitelisted before, but I only noticed now with a specific project I made on my wiki. Would be possible to add at least the storage... to the whitelist?

Thanks.


CSP REVIEW

  • Is the site equipped with a privacy policy?
  • Does the site attempt to comply with the GDPR? Can European Union inhabitants invoke their individual rights?
  • Does the site provide a list of personal data being collected by using the service?
  • Is the website owner known to have a bad reputation regarding privacy?
  • Can wikis use the external service, even if the visitor wants to deny any cookies or other form of tracking?
  • Will wikis stay usable, even if the visitor blocks the external resource by using an ad blocker?
  • Is there a Data Protection Officer and/or Privacy Team that can be contacted by Miraheze?
  • Is the site equipped with a security policy?
  • Does the site clarify their security measures to protect collected user data? Can the site assure measures are being taken to protect code injection into the loaded external resources?
  • Is the website owner known to have a bad reputation regarding information security?
  • Is there a Chief Information Security Officer and/or Security Team that can be contacted by Miraheze?

Event Timeline

Bukkit updated the task description. (Show Details)
Unknown Object (User) added a project: MediaWiki (SRE).Oct 14 2021, 20:39
John claimed this task.
John moved this task from Pending Addition to Completed on the CSP Review board.

Coming back to this, while it has been marked as "resolved", CSP still blocks the domain (and also others, such as cdn.jsdelivr.com). Not sure why.