www-infrastructure-issues mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "jan iversen (JIRA)" <j...@apache.org>
Subject [jira] [Updated] (INFRA-7173) update AOO wiki vm and forum with PMC requested changes.
Date Tue, 04 Feb 2014 23:04:18 GMT

     [ https://issues.apache.org/jira/browse/INFRA-7173?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]

jan iversen updated INFRA-7173:
-------------------------------

    Description: 
The AOO PMC have put a vm-team in place for maintenance (pescetti, arist, imacat and jsc)
and jani as sysadm for the 2 project vms.

This issue is mainly a project issue, but are kept at infra level, due to the security implications.

All maintenance will be done as agreed on the ML by the sysadm, and the vm-team is first response
for any outages. 

Current karma will not be touched, unless the rules of the proposal are broken, especially
meaning modifying the vms without prior agrement.

The following outstandings have been identified and agreed on with lazy consensus (thanks
to pescetti):

Wiki1: Upgrade Mediawiki DONE

Wiki2: install RecentChangesLogFilter extension DONE
https://www.mediawiki.org/wiki/Extension:RecentChangesLogFilter to filter out non-interesting
recent changes (such as user registrations); but still make user registrations available in
the RSS feed if possible.

Wiki3: mod_fcgid 2.3.9 released (when upgrading, make sure to test the "cooperation" with
ats, since header handling have changed) REJECT, it does not have any benefit for wiki.

Wiki4: Apache Traffic Server 4.0.2 is released; the ATS caching needs to be corrected
shouldn't) REJECT there are not benefits for wiki

Wiki6: Cats/Dogs CAPTCHA for new user registration is quite broken. It doesn't work in several
browser configurations, it includes HTTP instead of HTTPS https://issues.apache.org/ooo/show_bug.cgi?id=123695
-> Recommended solution: drop it entirely.

DONE, HOWEVER please prepare mwiki admins to watch out for spam !!!


accessibility suggestion from Tyler (haven't tested MediaWiki compatibility): there is a website
which provides text-based CAPTCHA's in the form of logic questions, math problems, etc. It
provides an XML API. See http://www.textcaptcha.com/

REJECT, only official mediawiki supported extensions will be installed.

Wiki7: fix Google CSE, changing http to https endpoints in GoogleCoop/GoogleCoop.php and then
reverting https://wiki.openoffice.org/w/index.php?title=Documentation%2FFAQ%2FInstallation&diff=232487&oldid=188626

DONE, Disclaimer I have no idea how to see if it works.



Forum1: changed parts of php2bb needs to be added to svn
DONE, db info removed from config.php and isolated in local file (no svn)

Forum2: could benefit a lot from having ATS installed, but that requires a change in the httpd
config. If this is considered, please consider update httpd as well, the newer versions allow
fastCGI which on wiki gave us an overall factor on performance.
POSTPONED to when PHP2BB sw is changed.

Forum3: the php2bb could really do with a optimization (especially with sqlconnections).
DONE

Forum4: any href= or src= that contains http:// will give a user warning (actually, href shouldn't)
DONE, config changed, but admins need to change post, or define a regex to be used in a db
table search.


Forum5: all users have the same IP; configuration must use the ip address from the http header
(original address) instead of the tcp/ip addr (any proxy addr). Replace $_SERVER['REMOTE_ADDR']
in session_begin   in   session.php with $_SERVER['HTTP_X_FORWARDED_FOR']
DONE

Forum6: implement private admin mailing list for EN forum (now a Gmail account)
REJECTED, this is a PMC task and not something I can do.

Forum7: implement private admin mailing list for ES forum (now a .org account provided by
Mauricio Baeza)
REJECTED, this is a PMC task and not something I can do.


Forum8: new images see https://forum.openoffice.org/en/forum/viewtopic.php?f=50&t=63523&start=90#p296713
and http://people.apache.org/~pescetti/tmp/2014-01-forum/ ; this requires CSS fixes too, that
can be done by Andrea.



  was:
The AOO PMC have put a vm-team in place for maintenance (pescetti, arist, imacat and jsc)
and jani as sysadm for the 2 project vms.

This issue is mainly a project issue, but are kept at infra level, due to the security implications.

All maintenance will be done as agreed on the ML by the sysadm, and the vm-team is first response
for any outages. 

Current karma will not be touched, unless the rules of the proposal are broken, especially
meaning modifying the vms without prior agrement.

The following outstandings have been identified and agreed on with lazy consensus (thanks
to pescetti):

Wiki1: Upgrade Mediawiki DONE

Wiki2: install RecentChangesLogFilter extension DONE
https://www.mediawiki.org/wiki/Extension:RecentChangesLogFilter to filter out non-interesting
recent changes (such as user registrations); but still make user registrations available in
the RSS feed if possible.

Wiki3: mod_fcgid 2.3.9 released (when upgrading, make sure to test the "cooperation" with
ats, since header handling have changed) REJECT, it does not have any benefit for wiki.

Wiki4: Apache Traffic Server 4.0.2 is released; the ATS caching needs to be corrected
shouldn't) REJECT there are not benefits for wiki

Wiki6: Cats/Dogs CAPTCHA for new user registration is quite broken. It doesn't work in several
browser configurations, it includes HTTP instead of HTTPS https://issues.apache.org/ooo/show_bug.cgi?id=123695
-> Recommended solution: drop it entirely.

DONE, HOWEVER please prepare mwiki admins to watch out for spam !!!


accessibility suggestion from Tyler (haven't tested MediaWiki compatibility): there is a website
which provides text-based CAPTCHA's in the form of logic questions, math problems, etc. It
provides an XML API. See http://www.textcaptcha.com/

REJECT, only official mediawiki supported extensions will be installed.

Wiki7: fix Google CSE, changing http to https endpoints in GoogleCoop/GoogleCoop.php and then
reverting https://wiki.openoffice.org/w/index.php?title=Documentation%2FFAQ%2FInstallation&diff=232487&oldid=188626

DONE, Disclaimer I have no idea how to see if it works.



Forum1: changed parts of php2bb needs to be added to svn
DONE, db info removed from config.php and isolated in local file (no svn)

Forum2: could benefit a lot from having ATS installed, but that requires a change in the httpd
config. If this is considered, please consider update httpd as well, the newer versions allow
fastCGI which on wiki gave us an overall factor on performance.
POSTPONED to when PHP2BB sw is changed.

Forum3: the php2bb could really do with a optimization (especially with sqlconnections).
DONE

Forum4: any href= or src= that contains http:// will give a user warning (actually, href shouldn't)
DONE, config changed, but admins need to change post, or define a regex to be used in a db
table search.


Forum5: all users have the same IP; configuration must use the ip address from the http header
(original address) instead of the tcp/ip addr (any proxy addr). Replace $_SERVER['REMOTE_ADDR']
in session_begin   in   session.php with $_SERVER['HTTP_X_FORWARDED_FOR']

Forum6: implement private admin mailing list for EN forum (now a Gmail account)

Forum7: implement private admin mailing list for ES forum (now a .org account provided by
Mauricio Baeza)

Forum8: new images see https://forum.openoffice.org/en/forum/viewtopic.php?f=50&t=63523&start=90#p296713
and http://people.apache.org/~pescetti/tmp/2014-01-forum/ ; this requires CSS fixes too, that
can be done by Andrea.




> update AOO wiki vm and forum with PMC requested changes.
> --------------------------------------------------------
>
>                 Key: INFRA-7173
>                 URL: https://issues.apache.org/jira/browse/INFRA-7173
>             Project: Infrastructure
>          Issue Type: Task
>          Components: Website
>         Environment: ubuntu 12.04
>            Reporter: jan iversen
>            Assignee: jan iversen
>
> The AOO PMC have put a vm-team in place for maintenance (pescetti, arist, imacat and
jsc) and jani as sysadm for the 2 project vms.
> This issue is mainly a project issue, but are kept at infra level, due to the security
implications.
> All maintenance will be done as agreed on the ML by the sysadm, and the vm-team is first
response for any outages. 
> Current karma will not be touched, unless the rules of the proposal are broken, especially
meaning modifying the vms without prior agrement.
> The following outstandings have been identified and agreed on with lazy consensus (thanks
to pescetti):
> Wiki1: Upgrade Mediawiki DONE
> Wiki2: install RecentChangesLogFilter extension DONE
> https://www.mediawiki.org/wiki/Extension:RecentChangesLogFilter to filter out non-interesting
recent changes (such as user registrations); but still make user registrations available in
the RSS feed if possible.
> Wiki3: mod_fcgid 2.3.9 released (when upgrading, make sure to test the "cooperation"
with ats, since header handling have changed) REJECT, it does not have any benefit for wiki.
> Wiki4: Apache Traffic Server 4.0.2 is released; the ATS caching needs to be corrected
> shouldn't) REJECT there are not benefits for wiki
> Wiki6: Cats/Dogs CAPTCHA for new user registration is quite broken. It doesn't work in
several browser configurations, it includes HTTP instead of HTTPS https://issues.apache.org/ooo/show_bug.cgi?id=123695
-> Recommended solution: drop it entirely.
> DONE, HOWEVER please prepare mwiki admins to watch out for spam !!!
> accessibility suggestion from Tyler (haven't tested MediaWiki compatibility): there is
a website which provides text-based CAPTCHA's in the form of logic questions, math problems,
etc. It provides an XML API. See http://www.textcaptcha.com/
> REJECT, only official mediawiki supported extensions will be installed.
> Wiki7: fix Google CSE, changing http to https endpoints in GoogleCoop/GoogleCoop.php
and then reverting https://wiki.openoffice.org/w/index.php?title=Documentation%2FFAQ%2FInstallation&diff=232487&oldid=188626
> DONE, Disclaimer I have no idea how to see if it works.
> Forum1: changed parts of php2bb needs to be added to svn
> DONE, db info removed from config.php and isolated in local file (no svn)
> Forum2: could benefit a lot from having ATS installed, but that requires a change in
the httpd config. If this is considered, please consider update httpd as well, the newer versions
allow fastCGI which on wiki gave us an overall factor on performance.
> POSTPONED to when PHP2BB sw is changed.
> Forum3: the php2bb could really do with a optimization (especially with sqlconnections).
> DONE
> Forum4: any href= or src= that contains http:// will give a user warning (actually, href
shouldn't)
> DONE, config changed, but admins need to change post, or define a regex to be used in
a db table search.
> Forum5: all users have the same IP; configuration must use the ip address from the http
header (original address) instead of the tcp/ip addr (any proxy addr). Replace $_SERVER['REMOTE_ADDR']
in session_begin   in   session.php with $_SERVER['HTTP_X_FORWARDED_FOR']
> DONE
> Forum6: implement private admin mailing list for EN forum (now a Gmail account)
> REJECTED, this is a PMC task and not something I can do.
> Forum7: implement private admin mailing list for ES forum (now a .org account provided
by Mauricio Baeza)
> REJECTED, this is a PMC task and not something I can do.
> Forum8: new images see https://forum.openoffice.org/en/forum/viewtopic.php?f=50&t=63523&start=90#p296713
and http://people.apache.org/~pescetti/tmp/2014-01-forum/ ; this requires CSS fixes too, that
can be done by Andrea.



--
This message was sent by Atlassian JIRA
(v6.1.5#6160)

Mime
View raw message