Page MenuHomeMiraheze

CSP ReviewTag
ActivePublic

Members

  • This project does not have any members.
  • View All

Watchers (2)

Details

Description

This is a tag to track and monitor the progress of all tasks that relate to the Content Security Policy and reviews associated with the CSP Policy.

Recent Activity

Oct 24 2023

OrangeStar updated the task description for T11129: Add bandcamp.com to CSP.
Oct 24 2023, 19:07 · CSP Review, MediaWiki (SRE)
Pppery updated the task description for T11129: Add bandcamp.com to CSP.
Oct 24 2023, 03:44 · CSP Review, MediaWiki (SRE)

Oct 23 2023

RespectMat renamed T11129: Add bandcamp.com to CSP from Add bandcamp.com to CSP to YOUR TASK WILL NEVER BE DONE BECAUSE MIRAHEZE IS LYING TO ALL OF US. FIND A NEW HOST FAST.
Oct 23 2023, 10:26 · CSP Review, MediaWiki (SRE)

Oct 22 2023

LXanders added a comment to T11269: Allow google fonts in content security policy.

bump?

Oct 22 2023, 15:35 · Trust & Safety, CSP Review

Oct 19 2023

LC_Developer updated the task description for T10852: Custom fonts from typekit.net.
Oct 19 2023, 14:15 · CSP Review, MediaWiki (SRE)
LC_Developer renamed T10852: Custom fonts from typekit.net from WHOEVER IS RUNNING MIRAHEZE RIGHT NOW IS SO DISRESPECTFUL THEY TREAT US LIKE GARBAGE AND MAKE US WAIT MONTHS FOR TASKS AND THEY HAVE THE AUDACITY TO LIE TO US AND CLAIM THEY’RE WORKING SO HARD BUT IN FACT THEY’RE DOING NOTHING BECAUSE THEY DONT IN FACT CARE. MAYBE SOME DO BUT MOST DONT. MIRAHEZE IS DEAD AND NO ONE WANTS TO REVIVE IT. TO PEOPLE WHO WANT TO BE TREATED WITH RESPECT AND HAVE THEIR TASKS DONE MIRAHEZE IS NOT THE PLACE ANYMORE. I HAD A WIKI BUT AFTER THIS AWFUL TREATMENT I AM LEAVING AND GOING SOMEWHERE ELSE. LEAVE AND MOVE YOUR WIKI TO A BETTER PLACE BEFORE IT SHUTS DOWN ONE DAY AND YOUVE GOT NOTHING. I WISH I COULD TRUST CURRENT MANAGEMENT BUT I CANT THEY DONT REALLY CARE ABOUT US to Custom fonts from typekit.net.
Oct 19 2023, 14:15 · CSP Review, MediaWiki (SRE)
DontLetYourselfBeDisrespected renamed T10852: Custom fonts from typekit.net from Custom fonts from typekit.net to WHOEVER IS RUNNING MIRAHEZE RIGHT NOW IS SO DISRESPECTFUL THEY TREAT US LIKE GARBAGE AND MAKE US WAIT MONTHS FOR TASKS AND THEY HAVE THE AUDACITY TO LIE TO US AND CLAIM THEY’RE WORKING SO HARD BUT IN FACT THEY’RE DOING NOTHING BECAUSE THEY DONT IN FACT CARE. MAYBE SOME DO BUT MOST DONT. MIRAHEZE IS DEAD AND NO ONE WANTS TO REVIVE IT. TO PEOPLE WHO WANT TO BE TREATED WITH RESPECT AND HAVE THEIR TASKS DONE MIRAHEZE IS NOT THE PLACE ANYMORE. I HAD A WIKI BUT AFTER THIS AWFUL TREATMENT I AM LEAVING AND GOING SOMEWHERE ELSE. LEAVE AND MOVE YOUR WIKI TO A BETTER PLACE BEFORE IT SHUTS DOWN ONE DAY AND YOUVE GOT NOTHING. I WISH I COULD TRUST CURRENT MANAGEMENT BUT I CANT THEY DONT REALLY CARE ABOUT US.
Oct 19 2023, 14:03 · CSP Review, MediaWiki (SRE)

Oct 16 2023

LXanders added a comment to T11269: Allow google fonts in content security policy.

Don't know if it's policy to create separate issues on the same topic, but the csp also has two outdated urls for discord:
cdn.discordapp.com and discordapp.com have been changed to media.discordapp.net

Oct 16 2023, 15:39 · Trust & Safety, CSP Review

Oct 9 2023

Original_Authority added a comment to T11269: Allow google fonts in content security policy.

PR https://github.com/miraheze/puppet/pull/3444

Oct 9 2023, 21:49 · Trust & Safety, CSP Review

Oct 6 2023

Redmin edited projects for T11269: Allow google fonts in content security policy, added: CSP Review, Trust & Safety; removed MediaWiki (SRE), MediaWiki.
Oct 6 2023, 09:20 · Trust & Safety, CSP Review

Sep 13 2023

Redmin removed a project from T10852: Custom fonts from typekit.net: MediaWiki.
Sep 13 2023, 05:20 · CSP Review, MediaWiki (SRE)

Aug 7 2023

RhinosF1 updated the task description for T11129: Add bandcamp.com to CSP.
Aug 7 2023, 16:43 · CSP Review, MediaWiki (SRE)

Jun 4 2023

Agent_Isai closed T10577: Add naleksuh.com to CSP whitelist as Declined.

Form has not been filled out. Please reopen once the form has been filled out in its entirety with all questions on the form answered completely. Thanks.

Jun 4 2023, 20:37 · CSP Review, MediaWiki (SRE), Trust & Safety

May 21 2023

BestSpyBoy added a comment to T10852: Custom fonts from typekit.net.

That sounds good, I'll see if I can download the font later. Thanks! 👍

May 21 2023, 11:36 · CSP Review, MediaWiki (SRE)
Agent_Isai added a comment to T10852: Custom fonts from typekit.net.

As a quickfix, why not upload the font onto your wiki in the meanwhile (of course, making sure to attribute copyright to Adobe)?

May 21 2023, 05:35 · CSP Review, MediaWiki (SRE)

May 20 2023

BestSpyBoy added a comment to T10852: Custom fonts from typekit.net.

Can I fill this in? If so:

May 20 2023, 15:16 · CSP Review, MediaWiki (SRE)
Reception123 updated the task description for T10852: Custom fonts from typekit.net.
May 20 2023, 14:55 · CSP Review, MediaWiki (SRE)

May 8 2023

Reception123 added a comment to T10577: Add naleksuh.com to CSP whitelist.

Let's not start here please. What I would say though is that users themselves should decide whether they subscribe to a task, others shouldn't need to decide for them.

May 8 2023, 16:25 · CSP Review, MediaWiki (SRE), Trust & Safety
BrandonWM added a comment to T10577: Add naleksuh.com to CSP whitelist.

Why was OrangeStar removed as a subscriber? Seeing they have been re-added, so that's good, just was confused as they're a MediaWiki Engineer.

Are you for real? Take a look at Meta's RC and Phab's latest changes

May 8 2023, 16:25 · CSP Review, MediaWiki (SRE), Trust & Safety
OrangeStar added a comment to T10577: Add naleksuh.com to CSP whitelist.

Why was OrangeStar removed as a subscriber? Seeing they have been re-added, so that's good, just was confused as they're a MediaWiki Engineer.

May 8 2023, 16:21 · CSP Review, MediaWiki (SRE), Trust & Safety
BrandonWM added a comment to T10577: Add naleksuh.com to CSP whitelist.

Why was OrangeStar removed as a subscriber? Seeing they have been re-added, so that's good, just was confused as they're a MediaWiki Engineer.

May 8 2023, 16:20 · CSP Review, MediaWiki (SRE), Trust & Safety
Naleksuh updated the task description for T10577: Add naleksuh.com to CSP whitelist.
May 8 2023, 16:12 · CSP Review, MediaWiki (SRE), Trust & Safety
Naleksuh added a comment to T10577: Add naleksuh.com to CSP whitelist.

OK, well, I have explained it now. Sorry for not catching you before.

May 8 2023, 16:12 · CSP Review, MediaWiki (SRE), Trust & Safety
Agent_Isai added a comment to T10577: Add naleksuh.com to CSP whitelist.

@Agent_Isai This form is inapplicable. For example, one of the forms asks about "user data" even though there is no user data anywhere there. It is a static site

May 8 2023, 16:10 · CSP Review, MediaWiki (SRE), Trust & Safety
OrangeStar added a comment to T10577: Add naleksuh.com to CSP whitelist.

Removing me from subscribers? Pretty funny.

May 8 2023, 16:09 · CSP Review, MediaWiki (SRE), Trust & Safety
Naleksuh updated the task description for T10577: Add naleksuh.com to CSP whitelist.
May 8 2023, 15:58 · CSP Review, MediaWiki (SRE), Trust & Safety
Naleksuh reopened T10577: Add naleksuh.com to CSP whitelist as "Open".
May 8 2023, 15:57 · CSP Review, MediaWiki (SRE), Trust & Safety
Naleksuh added a comment to T10577: Add naleksuh.com to CSP whitelist.

@Agent_Isai This form is inapplicable. For example, one of the forms asks about "user data" even though there is no user data anywhere there. It is a static site

May 8 2023, 15:57 · CSP Review, MediaWiki (SRE), Trust & Safety
Agent_Isai closed T10577: Add naleksuh.com to CSP whitelist as Declined.

No response. Please reopen once details are filled in.

May 8 2023, 15:30 · CSP Review, MediaWiki (SRE), Trust & Safety

Apr 29 2023

Agent_Isai added a comment to T10577: Add naleksuh.com to CSP whitelist.

@Naleksuh Please fill out the form in this task. Thanks.

Apr 29 2023, 19:01 · CSP Review, MediaWiki (SRE), Trust & Safety
Agent_Isai updated the task description for T10577: Add naleksuh.com to CSP whitelist.
Apr 29 2023, 19:01 · CSP Review, MediaWiki (SRE), Trust & Safety

Mar 7 2023

Naleksuh added a comment to T10577: Add naleksuh.com to CSP whitelist.

@Reception123 For the root domain naleksuh.com, yes, no-one but me can upload any files there. Some of the subdomains and other domains I have do contain wikis and such that anyone can write to. But I am only asking for naleksuh.com right now

Mar 7 2023, 18:16 · CSP Review, MediaWiki (SRE), Trust & Safety
Reception123 triaged T10577: Add naleksuh.com to CSP whitelist as Normal priority.

Are you able to give assurances that your website does not and will never collect any kind of personal data that would be covered by the GDPR?

Mar 7 2023, 10:09 · CSP Review, MediaWiki (SRE), Trust & Safety

Feb 28 2023

Bukkit moved T5869: Whitelist postimages.org & imgbb.com (& their domains) for image display from Working On to Resolved on the Bukkit board.
Feb 28 2023, 01:05 · Bukkit, Trust & Safety, CSP Review, MediaWiki (SRE)

Feb 27 2023

Reception123 closed T5869: Whitelist postimages.org & imgbb.com (& their domains) for image display as Resolved.
Feb 27 2023, 20:32 · Bukkit, Trust & Safety, CSP Review, MediaWiki (SRE)

Feb 25 2023

Bukkit moved T5869: Whitelist postimages.org & imgbb.com (& their domains) for image display from Radar to Working On on the Bukkit board.
Feb 25 2023, 23:41 · Bukkit, Trust & Safety, CSP Review, MediaWiki (SRE)
Bukkit added a project to T5869: Whitelist postimages.org & imgbb.com (& their domains) for image display: Bukkit.
Feb 25 2023, 23:41 · Bukkit, Trust & Safety, CSP Review, MediaWiki (SRE)

Feb 24 2023

Bukkit added a comment to T5869: Whitelist postimages.org & imgbb.com (& their domains) for image display.

There are still issues which prevent many images from showing.

Currently only their main domains are whitelisted:

'imgbb.com'
'postimages.org'

However those 2 sites use multiple (sub-)domains to store the images, more (sub-)domains have to be whitelisted.

Regarding imgbb.com, those additional lines are required:

'*.imgbb.com'
'simgbb.com'
'*.simgbb.com'
'ibb.co'
'*.ibb.co'

Regarding postimages.org, those additional lines are required:

'*.postimages.org'
'postimgs.org'
'*.postimgs.org'
'postimg.cc'
'*.postimg.cc'

Thank you.

Feb 24 2023, 23:00 · Bukkit, Trust & Safety, CSP Review, MediaWiki (SRE)

Feb 19 2023

Reception123 closed T10521: Request CSP Approval for reftoolbar.toolforge.org as Declined.

Per @OrangeStar and T9457#194407, unless that changes we can't accept this.

Feb 19 2023, 12:39 · MediaWiki (SRE), CSP Review
OrangeStar triaged T10521: Request CSP Approval for reftoolbar.toolforge.org as Normal priority.
Feb 19 2023, 11:06 · MediaWiki (SRE), CSP Review
OrangeStar added projects to T10521: Request CSP Approval for reftoolbar.toolforge.org: CSP Review, MediaWiki (SRE).

Just noting that toolforge hasn't had much luck in CSP reviews (T8131, T9457), and this is unlikely to be an exception.

Feb 19 2023, 11:03 · MediaWiki (SRE), CSP Review

Feb 13 2023

Reception123 closed T9953: player.bilibili.com (and sites related to it) CSP whitelist as Declined.

This task has generated a lot of debate and both sides have been considered, as well as observations by the T&S team in the T9252 task. Unfortunately, I have come to the conclusion that the different concerns expressed by T&S in that previous task have not been sufficiently addressed and the circumstances mentioned haven't changed since then. In addition, a CSP whitelist addition requiring so much debate and back and forth is in itself an indication that there are concerns to be had.

Feb 13 2023, 14:57 · MediaWiki (SRE), CSP Review, Trust & Safety

Feb 10 2023

Revival reopened T5869: Whitelist postimages.org & imgbb.com (& their domains) for image display as "Open".

There are still issues which prevent many images from showing.

Feb 10 2023, 20:02 · Bukkit, Trust & Safety, CSP Review, MediaWiki (SRE)

Feb 8 2023

Dimpizzy added a comment to T10454: Request: Add i.ytimg.com to CSP.

It works, thank you very much.

Feb 8 2023, 13:05 · CSP Review, MediaWiki (SRE)
Unknown Object (User) closed T10454: Request: Add i.ytimg.com to CSP as Resolved.
Feb 8 2023, 08:48 · CSP Review, MediaWiki (SRE)
Unknown Object (User) added a comment to T10454: Request: Add i.ytimg.com to CSP.

I have now moved it to img-src. It may take a few minutes to start working though.

Feb 8 2023, 08:32 · CSP Review, MediaWiki (SRE)
Dimpizzy reopened T10454: Request: Add i.ytimg.com to CSP as "Open".

It looks like it needs to be added to img-src, as it's still not working:

Feb 8 2023, 08:29 · CSP Review, MediaWiki (SRE)
Reception123 moved T10454: Request: Add i.ytimg.com to CSP from SRE Review to Completed on the CSP Review board.
Feb 8 2023, 08:25 · CSP Review, MediaWiki (SRE)
Reception123 closed T10454: Request: Add i.ytimg.com to CSP as Resolved.

Since Google has been approved in T7872 and this is part of Google/YouTube approved and added.

Feb 8 2023, 08:25 · CSP Review, MediaWiki (SRE)

Feb 7 2023

Reception123 moved T10226: Add Scryfall to CSP whitelist from SRE Review to T&S Review on the CSP Review board.
Feb 7 2023, 15:57 · Trust & Safety, MediaWiki (SRE), CSP Review