[Bug 71624] Security review of IEG grant review

2014-10-17 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=71624 Chris Steipp cste...@wikimedia.org changed: What|Removed |Added Status|NEW |RESOLVED

[Bug 71624] Security review of IEG grant review

2014-10-09 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=71624 --- Comment #4 from Gerrit Notification Bot gerritad...@wikimedia.org --- Change 165432 had a related patch set uploaded by BryanDavis: Support formatting messages using Parsoid https://gerrit.wikimedia.org/r/165432 -- You are receiving this

[Bug 71624] Security review of IEG grant review

2014-10-09 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=71624 --- Comment #3 from Gerrit Notification Bot gerritad...@wikimedia.org --- Change 165431 had a related patch set uploaded by BryanDavis: Remove markdown support https://gerrit.wikimedia.org/r/165431 -- You are receiving this mail because: You

[Bug 71624] Security review of IEG grant review

2014-10-09 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=71624 Gerrit Notification Bot gerritad...@wikimedia.org changed: What|Removed |Added Status|NEW

[Bug 71624] Security review of IEG grant review

2014-10-09 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=71624 --- Comment #5 from Bryan Davis bda...@wikimedia.org --- (In reply to Chris Steipp from comment #2) Some general comments so far: * The inclusion of script tags in the markdown seems really problematic, and I think needs a better design *

[Bug 71624] Security review of IEG grant review

2014-10-09 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=71624 --- Comment #6 from Gerrit Notification Bot gerritad...@wikimedia.org --- Change 165692 had a related patch set uploaded by BryanDavis: Add headers to make attacking the site harder https://gerrit.wikimedia.org/r/165692 -- You are receiving

[Bug 71624] Security review of IEG grant review

2014-10-09 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=71624 --- Comment #7 from Gerrit Notification Bot gerritad...@wikimedia.org --- Change 165693 had a related patch set uploaded by BryanDavis: Do not use weak random for password hashing https://gerrit.wikimedia.org/r/165693 -- You are receiving

[Bug 71624] Security review of IEG grant review

2014-10-09 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=71624 --- Comment #8 from Chris Steipp cste...@wikimedia.org --- (In reply to Bryan Davis from comment #5) Ok. I am setting meta charset=utf-8/ in my base template, but that isn't seen until the user agent processes the content. I missed that.

[Bug 71624] Security review of IEG grant review

2014-10-09 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=71624 --- Comment #11 from Gerrit Notification Bot gerritad...@wikimedia.org --- Change 165692 merged by jenkins-bot: Add headers to make attacking the site harder https://gerrit.wikimedia.org/r/165692 -- You are receiving this mail because: You

[Bug 71624] Security review of IEG grant review

2014-10-09 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=71624 --- Comment #10 from Gerrit Notification Bot gerritad...@wikimedia.org --- Change 165432 merged by jenkins-bot: Support formatting messages using Parsoid https://gerrit.wikimedia.org/r/165432 -- You are receiving this mail because: You are

[Bug 71624] Security review of IEG grant review

2014-10-09 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=71624 --- Comment #9 from Gerrit Notification Bot gerritad...@wikimedia.org --- Change 165431 merged by jenkins-bot: Remove markdown support https://gerrit.wikimedia.org/r/165431 -- You are receiving this mail because: You are on the CC list for

[Bug 71624] Security review of IEG grant review

2014-10-09 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=71624 --- Comment #12 from Gerrit Notification Bot gerritad...@wikimedia.org --- Change 165693 merged by jenkins-bot: Do not use weak random for password hashing https://gerrit.wikimedia.org/r/165693 -- You are receiving this mail because: You are

[Bug 71624] Security review of IEG grant review

2014-10-09 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=71624 Bryan Davis bda...@wikimedia.org changed: What|Removed |Added Status|PATCH_TO_REVIEW |NEW --- Comment #13

[Bug 71624] Security review of IEG grant review

2014-10-07 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=71624 --- Comment #2 from Chris Steipp cste...@wikimedia.org --- Some general comments so far: * The inclusion of script tags in the markdown seems really problematic, and I think needs a better design * It would help if we had a strict content

[Bug 71624] Security review of IEG grant review

2014-10-04 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=71624 Bryan Davis bda...@wikimedia.org changed: What|Removed |Added CC||bda...@wikimedia.org

[Bug 71624] Security review of IEG grant review

2014-10-03 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=71624 Bryan Davis bda...@wikimedia.org changed: What|Removed |Added Priority|Unprioritized |High