Lucas_Werkmeister_WMDE created this task. Lucas_Werkmeister_WMDE added projects: Wikidata, Wikidata-Query-Service, Discovery, Wikimedia-Site-requests, Security. Restricted Application added a subscriber: Aklapper.
TASK DESCRIPTION In order to create short URLs for queries, `query.wikidata.org` needs to be able to send authenticated API requests (`action=shortenurl`) to some production wiki (Wikidata or Meta would be appropriate, but the config is probably the same for all wikis anyways). This shouldn’t be a security problem because `query.wikidata.org` only runs trusted JavaScript code. That said, I’m not sure if the #wikidata-query-ui <https://phabricator.wikimedia.org/tag/wikidata_query_ui/> code ever actually went through security review (it seems T105196 <https://phabricator.wikimedia.org/T105196> only covered the server-side parts), and apparently T108101 <https://phabricator.wikimedia.org/T108101> explicitly disabled CORS for this domain, so I’m not sure how trivial this request is. TASK DETAIL https://phabricator.wikimedia.org/T218568 EMAIL PREFERENCES https://phabricator.wikimedia.org/settings/panel/emailpreferences/ To: Lucas_Werkmeister_WMDE Cc: Aklapper, Lucas_Werkmeister_WMDE, alaa_wmde, ET4Eva, Nandana, sbassett, Lahi, Gq86, Darkminds3113, GoranSMilovanovic, Jayprakash12345, QZanden, EBjune, HJiang-WMF, Zoranzoki21, merbst, LawExplorer, Avner, DatGuy, Devwaker, Niklitov, Gehel, _jensen, Urbanecm, rosalieper, JEumerus, Jonas, Ananthsubray, FloNight, Xmlizer, dpatrick, Tulsi_Bhagat, Wong128hk, Luke081515, SimmeD, jkroll, Smalyshev, Wikidata-bugs, Jdouglas, Snowolf, aude, Tobias1984, GWicke, Dcljr, Bawolff, Stype_and_Co.-WMF, Manybubbles, Jalexander, Parent5446, Anomie, Grunny, Jdforrester-WMF, MaxSem, csteipp, Matanya, Mbch331, Rxy, Jay8g, Krenair, Legoktm, chasemp
_______________________________________________ Wikidata-bugs mailing list [email protected] https://lists.wikimedia.org/mailman/listinfo/wikidata-bugs
