Wikimedia Security Team/AppSec Clinic Minutes/2022-10-17

From mediawiki.org

Date: 2022-10-17

Attending: CLemoisson-WMF, MMartorana_(WMF), SBassett_(WMF), MStyles_(WMF)

Phabricator Tasks In Progress[edit]

  1. MMartorana_(WMF)
    1. T315407 - "Passive watching", maybe get Kelton's take?
    2. T316414 - Manfredi will work on a ported patch for this edge case.
    3. T318915 - Tag PE for risk assessment help, determine some path forward.
  2. MStyles_(WMF)
    1. T313241 - Maint script merged, determine next steps.
    2. T316360 - Awaiting feedback.
    3. T316998 - Overly-cautious security-protection, possible follow-up.
    4. T318731 - Assigned to MStyles_(WMF) for follow-up.
    5. T318731 - Assigned to MStyles_(WMF) for follow-up.
    6. T319134 - Assigned to MStyles_(WMF) for follow-up.
    7. T320363 - Assigned to MStyles_(WMF) for follow-up.
  3. Reedy_(WMF)
    1. T306211 - Open, untriaged.
    2. T310393 - Open, untriaged.
    3. T318825 - Assigned to Reedy for follow-up.
  4. SBassett_(WMF)
    1. T314884 - Awaiting further response from legoktm.
    2. T315820 - Triage, await discussion.
    3. T316722 - Await discussion.
    4. T320540 - Assigned to SBassett_(WMF) for follow-up.

New Phabricator Tasks Reviewed[edit]

  1. T317595 - Assigned to MMartorana_(WMF) to review discussion and new tasks.
  2. T320611 - Assigned to MStyles_(WMF) to review 2fa and then grant access to relevant sub-policy.
  3. T320719 - Assigned to SBassett_(WMF) to review 2fa and then grant access to relevant sub-policy.