imbajin commented on PR #472: URL: https://github.com/apache/hugegraph-doc/pull/472#issuecomment-5721033218
Tracking TODO: Kapa / CSP precedent and OINK staging verification Kapa already has an ASF DPA and is permitted with consent before loading: [ASF privacy FAQ](https://privacy.apache.org/faq/committers.html). Relevant Apache precedents: - [Arrow #726](https://github.com/apache/arrow-site/pull/726) cites [INFRA-26638](https://issues.apache.org/jira/browse/INFRA-26638) as its Kapa domain approval. The Jira ticket currently requires login, so its exact approved scope has not been independently verified. - [Superset #42276](https://github.com/apache/superset/pull/42276), merged, extends Kapa backend access through `SetEnv CSP_PROJECT_DOMAINS` and cites the ASF privacy FAQ. - [Fluss #3760](https://github.com/apache/fluss/pull/3760), merged, implements consent-gated Kapa. Its earlier [#3209](https://github.com/apache/fluss/pull/3209) was closed with a policy concern, so that earlier change is not an approval precedent. - HugeGraph previously tested Kapa on Docusaurus staging in [#459](https://github.com/apache/hugegraph-doc/pull/459). This proves prior configuration/testing, not a staging exemption. TODO: - [ ] Test the dedicated OINK staging response CSP and real click-gated Kapa traffic; record exact required hosts and confirm zero third-party requests before activation. - [ ] Check the existing Kapa approval/DPA scope against actual proxy and hCaptcha hosts, retrieving INFRA-26638 or existing project approval evidence where available. Record genuinely unresolved host requirements separately. - [ ] Use the [ASF CSP extension mechanism](https://infra.apache.org/tools/csp.html), preserving the default header rather than replacing it. Do not copy another project's wildcard allowlist. [Arrow's discussion](https://github.com/apache/arrow-site/issues/723#issuecomment-3474114316) recommends a `.asf.yaml` preview site for CSP testing. We found no documented blanket staging exemption; staging may work because of its effective configuration. This TODO does not block native-site implementation, testing, or staging deployment, and does not imply that a new Kapa application is automatically required. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
