Extension:Graph/Plans

This page is a place for WMF staff and volunteers to gather the information needed for the WMF to decide the role it will play in ensuring the needs the Graph Extension emerged to serve continue being met.

Decisions to be made
The Open questions listed below are meant to surface the information the WMF will need to make the following decisions:


 * 1) What needs will any proposed path forward need to meet?
 * 2) What role will the WMF play in ensuring these needs are met?

Open questions
In order to make the Decisions to be made above, we think we need to answer the list questions below. We anticipate this list evolving over time as new information emerges.

1) Who are the people (e.g. WMF teams, volunteers, WikiProjects, etc.) that depended on the Graph Extension? In what way(s) had people been using the Graph Extension?

 * 1) A (old, but I doubt much has changed) analysis of this is at User:Bawolff/Reflections on graphs
 * 2) Volunteers
 * 3) Generate infographics to present data to readers in a variety of forms. E.g. bar chats, stacked graphs, pie charts, scatter plots, timelines, histograms, geographic maps.
 * 4) See Category:Pages with disabled graphs for the range of pages/contexts where the Graph Extension was used
 * 5) Generate graphs on talk pages to show article   and user page views over time.
 * 6) Use the Graph extension to generate maps with more features than the Kartographer extension provides.
 * 7) Generate page view graphs on ?action=info as part of Extension:PageViewInfo
 * 8) Generate Interactive COVID-19 maps
 * 9) Pamputt: Generate up-to-date graph from Wikidata data. The only workaround is to create by hand an image, to upload it on Commons and to redo it each time the values are updated.
 * 10) WMF Staff
 * 11) PPelberg (WMF): While WMF Teams do not yet seem to be depending on the Graph Extension, teams' longer-term plans/strategies do depend on a future wherein functionality exists on-wiki to: 1) store data, 2) update data, and  3) generate infographics/visualizations that enable people to explore/interact with said data.
 * 12) "1)", "2)", and "3)" named above are strategically important to the Movement being able to evaluate the impact of the work it's doing and monitor its health.
 * 13) At present, storing data and generating "artifacts" that enable people to interact and explore this data happens off-wiki and takes a great deal of time and technical expertise.

=== 2) What is no longer possible as a result of the Graph Extension being disabled? Asked another way: what capabilities did the Graph Extension provide for which you have not yet found a viable workaround? ===
 * 1) Nux: Generating page views charts for popular pages. E.g. page views template on pl.wiki
 * 2) Nux: Generating charts based on Wikidata. E.g. en:Template:Airport-Statistics (used by multiple other languages).
 * 3) TheDJ: Generate page view graphs on ?action=info.
 * 4) Pamputt: Generate up-to-date graph from Wikidata data.

3) What did you notice yourself (and other people) using the Graph Extension to do that you hadn't been doing before?

 * 1) Ahecht: Treating charts as collaborative content equivalent to the rest of a Wikipedia article. Editors are reluctant to tweak a chart when it requires downloading the source data, recreating a similar chart from scratch in external software, converting it to an image, and uploading it over another editor's image, and therefore each chart would only be edited by it's initial creator.

=== 4) What – if anything – did the Graph Extension make it easier/more convenient to do? If you can, please describe what each "task" you used the Graph Extension for looked like before and after it existed. ===
 * 1) RobinLeicester: As with the charts, improving/adding to an annotated map, either your own or someone elses, became much more like proper wikipedia editing, compared to uploading a 'finished' item to commons. With such limited options within maplink, external graphics programs would have to be used and the result is then fossilised on the page, or never attempted in the first place. Also, placing annotations using 'coords', on a reliable base map, makes them more verifiable and correctable.

5) What workarounds have you developed and/or seen other volunteers develop in the time between now and when the Graph Extension was disabled?

 * 1) 86.122.161.172: Nothing, there are just too many pages and there was too much effort involved in developing the existing graphs to replicate at once on smaller wikis. I really hope that if another solution is provided, an automatic converter will also exist.
 * 2) Nux: Moved a bar chart from graph to timeline . This kind of works, but timeline is rather static (not tooltips on hover) and fonts are less readable.
 * TheDJ: EasyTimeline itself is also no longer receiving updates and depends on perl. I think we should consider that this too will require replacement at some point !!
 * 1) Nux: Added generic pie chart with 2 values pl:Szablon:Wykres Smooth Pie 2. This is a fully functional replacement for pl:Szablon:Demografia_powiatu. Though this doesn't look the same (especially the labels of charts could be better). And also it's not easy to add more then 2 values on this pie chart.
 * 2) Edu!: At Portuguese Wikinews, the Graph 2 module was developed, which uses CSS to generate line, area and column graphs in the Gráfico template. The module does not have limitations that exist in alternative templates used in some Wikipedia languages. The community is working on improvements.
 * 3) TheDJ: The limitation of CSS based graphs is that they generally are not that accessible. There are problems with color inversion, screenreaders etc. This particular example is even worse, as it uses HTML tables to do layout (there is no reason to use tables).
 * 4) TheDJ: en:Template:OSM Location map was switched from the Graph mode to pure Kartographer. This made it loose some features (custom pogs, minimap, custom labels etc).  See also comments by RobinLeicester

6) What tools (on- and off-wiki)/templates/gadgets/etc. are you currently using to create data visualizations for Wikipedia?

 * 1) Nux: I know en.wiki is linking to Wikidata for some stats... But that UX of having to see huge SPARQL on  WikidataQueryService is terrible (see the Airport-Statistics template)...

7) Why do you think it is or is not strategically important for the Wikimedia Movement to offer on-wiki tools for storing, editing, and visualizing data?

 * 1) Nux: A picture is worth a thousand words. And a dynamic chart with context is even more precious...

8) What requests (e.g. wishes) have volunteers made over time to improve support for storing and representing/visualizing data on-wiki?

 * 1) T195627: Support Vega 3.0 in Graphoid
 * 2) T195628: Support Vega Lite 2.0 in Graphoid
 * 3) T100444: Graph localization support
 * 4) T165118: Support Vega 5.0+
 * 5) meta:Improve graphs and interactive content

9) What – if anything – could be done to safely reenable the Graph Extension?

 * 1) Some proposals have included (These may or may not be sufficient and different people have different opinions)
 * 2) T222807 - Use browser based iframe sandboxing
 * 3) PPelberg (WMF): per what Tgr shared in T222807#8858868, and what SBassett (WMF), Tgr, and I met to talk about offline on 20 July 2023, the prospect of iframe sandboxed enhanced with a Content Security Policy seems potentially viable.
 * 4) Render server side (or render client side with some sanitization layer) to allow static but not interactive graphs
 * 5) T336595 - Make editing graphs be restricted similar to MediaWiki:Common.js
 * 6) Bawolff: The elephant in the room is that graph is a high maintenance extension, even before this, that on the whole is not that widely used and where it is used, it is used mostly in a fairly simple fashion. Given its usage numbers and how it is used, it is unclear that further investment is worth it.
 * 7) Bawolff: It was pointed out on phab that vega has not fixed the underlying security issue despite presumably having been aware of it for a while now. In order to be deployed again we would want both the known security issue fixed and some assurance there won't be more or have some sandboxing to lower the impact of any currently unknown issues. If Vega is not fixing it in a timely fashion, WMF could perhaps contribute fixes themselves, but being required to take that on is a very large red flag for the overall security of the library.

10) Of the pages that display graphs/infographics, what proportion of them depended on the Graph Extension?
TheDJ: any sort of listing will be hard to trust, as people have already started to migrate away in various ways. It would be good if we can see if we have some numbers from before somewhere. When it was initially disabled, I mentioned that en.wp had: en.wp used "about 60 000 for en.wp, or just 16k articles". I'm however not sure where i pulled those numbers from.

Background
On April 19, 2023 it was identified that the Graph extension, which uses the older Vega 1 & Vega 2 libraries, had a number of security vulnerabilities.

In the interest of the security of the people who use Wikipedia, the Graph extension was disabled on all Wikimedia wikis.