Re: [Wikitech-l] OAuth and Identities

2013-10-22 Thread Merlijn van Deen
Hi Chris, On 22 October 2013 05:45, Chris Steipp cste...@wikimedia.org wrote: OAuth does not support this, since the results of an api call using OAuth signatures aren't signed (only the request from the OAuth consumer is signed), so it's possible that an attacker could forge a response back

Re: [Wikitech-l] New git-review lets you configure 'origin' as the gerrit remote

2013-10-22 Thread Željko Filipin
This was working great for me on several machines, but it did not work on one machine[1][2]. Adding something like this to git-review.conf fixes the problem: [updates] check=off Željko -- 1: https://bugzilla.wikimedia.org/show_bug.cgi?id=55732 2:

Re: [Wikitech-l] OAuth and Identities

2013-10-22 Thread Gabriel Wicke
On 10/21/2013 08:45 PM, Chris Steipp wrote: Hi all, I wanted to get some input from you all about any ideas or plans they have for identifying OAuth user in your applications. tl;dr, Since lots of people want to do authentication with OAuth, I'm thinking we'll implement a custom way to get

Re: [Wikitech-l] OAuth and Identities

2013-10-22 Thread Chris Steipp
On Tue, Oct 22, 2013 at 1:57 AM, Merlijn van Deen valhall...@arctus.nlwrote: Hi Chris, On 22 October 2013 05:45, Chris Steipp cste...@wikimedia.org wrote: OAuth does not support this, since the results of an api call using OAuth signatures aren't signed (only the request from the OAuth

Re: [Wikitech-l] OAuth and Identities

2013-10-22 Thread Petr Bena
I am basically interested only in oauth that can be used by remote applications / processes running on user's PC, which isn't available yet On Tue, Oct 22, 2013 at 7:18 PM, Chris Steipp cste...@wikimedia.org wrote: On Tue, Oct 22, 2013 at 1:57 AM, Merlijn van Deen valhall...@arctus.nlwrote: Hi

Re: [Wikitech-l] OAuth and Identities

2013-10-22 Thread Chris Steipp
On Tue, Oct 22, 2013 at 10:33 AM, Petr Bena benap...@gmail.com wrote: I am basically interested only in oauth that can be used by remote applications / processes running on user's PC, which isn't available yet This is the second most requested feature that we don't support yet. We've been

Re: [Wikitech-l] OAuth and Identities

2013-10-22 Thread Petr Bena
Do you realize that these application are asking users for their password in this moment? That seems to me even worse than oauth with these caviots On Tue, Oct 22, 2013 at 7:54 PM, Chris Steipp cste...@wikimedia.org wrote: On Tue, Oct 22, 2013 at 10:33 AM, Petr Bena benap...@gmail.com wrote: I

[Wikitech-l] Redirects from Commons to wikimediafoundation

2013-10-22 Thread Eugene Zelenko
Hi! I experienced weird problem today when accessing Commons (addresses like https://commons.wikimedia.org/wiki/Special:Watchlist and http://commopns.wikimedia.org/wiki/Category:Yuri_Gagarin): I was redirected to same pages on http://wikimediafoundation.org. Eugene.

Re: [Wikitech-l] Redirects from Commons to wikimediafoundation

2013-10-22 Thread Brion Vibber
I believe there was a configuration error this morning which got some redirects stuck in cache; they should be on the way to being fixed... -- brion On Tue, Oct 22, 2013 at 11:56 AM, Eugene Zelenko eugene.zele...@gmail.comwrote: Hi! I experienced weird problem today when accessing Commons

[Wikitech-l] input requested re: metrics for hackathons

2013-10-22 Thread Jonathan Morgan
Hi all, OrenBachman has asked several questions about how to evaluate the impact of Hackathon events on the Evaluation Portal*[1]* and I'm hoping some folks from this list can share their advice and perspectives. Please read and respond there if you have input. Several outstanding questions are:

Re: [Wikitech-l] Redirects from Commons to wikimediafoundation

2013-10-22 Thread Daniel Zahn
Hi, here's a more detailed report: As part of an ongoing effort to simplify, cleanup and reduce code lines of the Apache cluster config, we we're planning to unify a lot of document roots for the www-portals into a single docroot, like here: https://gerrit.wikimedia.org/r/#/c/90669/ looking at

[Wikitech-l] HTTP Archive now tracking several Wikimedia wikis

2013-10-22 Thread Ori Livneh
The HTTP Archive (http://httparchive.org/) audits the setup and performance of popular websites, reporting things like load times, download sizes, performance scores, waterfall charts, and cache headers. They provide per-site reports as well as aggregate data about trends in web technology. They

[Wikitech-l] mw.inspect: new CSS report

2013-10-22 Thread Ori Livneh
Running mw.loader.inspect('css') in a JavaScript console will now report CSS stats for each active ResourceLoader style module, including the total count of selectors and the percentage of those that match some node in the current DOM. --- Ori Livneh o...@wikimedia.org

Re: [Wikitech-l] OAuth and Identities

2013-10-22 Thread MZMcBride
Petr Bena wrote: Do you realize that these application are asking users for their password in this moment? That seems to me even worse than oauth with these caviots Which applications are asking users for their password? The only partial example I can come up with off-hand is AutoWikiBrowser,