imbajin commented on PR #472:
URL: https://github.com/apache/hugegraph-doc/pull/472#issuecomment-5721033218

   Tracking TODO: Kapa / CSP precedent and OINK staging verification
   
   Kapa already has an ASF DPA and is permitted with consent before loading: 
[ASF privacy FAQ](https://privacy.apache.org/faq/committers.html).
   
   Relevant Apache precedents:
   - [Arrow #726](https://github.com/apache/arrow-site/pull/726) cites 
[INFRA-26638](https://issues.apache.org/jira/browse/INFRA-26638) as its Kapa 
domain approval. The Jira ticket currently requires login, so its exact 
approved scope has not been independently verified.
   - [Superset #42276](https://github.com/apache/superset/pull/42276), merged, 
extends Kapa backend access through `SetEnv CSP_PROJECT_DOMAINS` and cites the 
ASF privacy FAQ.
   - [Fluss #3760](https://github.com/apache/fluss/pull/3760), merged, 
implements consent-gated Kapa. Its earlier 
[#3209](https://github.com/apache/fluss/pull/3209) was closed with a policy 
concern, so that earlier change is not an approval precedent.
   - HugeGraph previously tested Kapa on Docusaurus staging in 
[#459](https://github.com/apache/hugegraph-doc/pull/459). This proves prior 
configuration/testing, not a staging exemption.
   
   TODO:
   - [ ] Test the dedicated OINK staging response CSP and real click-gated Kapa 
traffic; record exact required hosts and confirm zero third-party requests 
before activation.
   - [ ] Check the existing Kapa approval/DPA scope against actual proxy and 
hCaptcha hosts, retrieving INFRA-26638 or existing project approval evidence 
where available. Record genuinely unresolved host requirements separately.
   - [ ] Use the [ASF CSP extension 
mechanism](https://infra.apache.org/tools/csp.html), preserving the default 
header rather than replacing it. Do not copy another project's wildcard 
allowlist.
   
   [Arrow's 
discussion](https://github.com/apache/arrow-site/issues/723#issuecomment-3474114316)
 recommends a `.asf.yaml` preview site for CSP testing. We found no documented 
blanket staging exemption; staging may work because of its effective 
configuration. This TODO does not block native-site implementation, testing, or 
staging deployment, and does not imply that a new Kapa application is 
automatically required.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to