Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

WikiContrib violates user privacy by loading third party content from Cloudflare #279

Open
aklapper opened this issue Jul 7, 2022 · 9 comments

Comments

@aklapper
Copy link

aklapper commented Jul 7, 2022

https://wikicontrib.toolforge.org/ loads <link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/semantic-ui/2.4.1/semantic.min.css">. This is a third-party privacy violation.

It's more concerning now that this tool is linked from the Wikimedia Developer Portal.

Please use https://tools-static.wmflabs.org/cdnjs/ajax/libs/semantic-ui/2.4.1/semantic.min.css instead and deploy.

See also https://phabricator.wikimedia.org/T231312

@srish
Copy link
Member

srish commented Jul 8, 2022

@NdibeRaymond You still have access to this tool on Toolforge right? I'd let you take on this.

@aklapper
Copy link
Author

aklapper commented Jul 8, 2022

https://toolsadmin.wikimedia.org/tools/id/wikicontrib lists four maintainers :)

@NdibeRaymond
Copy link
Collaborator

@NdibeRaymond You still have access to this tool on Toolforge right? I'd let you take on this.

yes I still do @srish. I will fix this issue

@NdibeRaymond
Copy link
Collaborator

https://wikicontrib.toolforge.org/ loads <link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/semantic-ui/2.4.1/semantic.min.css">. This is a third-party privacy violation.

It's more concerning now that this tool is linked from the Wikimedia Developer Portal.

Please use https://tools-static.wmflabs.org/cdnjs/ajax/libs/semantic-ui/2.4.1/semantic.min.css instead and deploy.

See also https://phabricator.wikimedia.org/T231312

thanks for making this known @aklapper . I will fix this ASAP

@wkyoshida
Copy link

Hi!

Out of curiosity - I was wondering if this issue has now been resolved with #280 - would that be right?

@aklapper
Copy link
Author

That's a good question for @NdibeRaymond - if this is fixed, please close this ticket

@NdibeRaymond
Copy link
Collaborator

Yeaaa forgot to close this, closing now

@aklapper
Copy link
Author

This is still an issue when I go to https://wikicontrib.toolforge.org/ - how was this resolved? If this was resolved, do you plan to deploy the changes?

@aklapper aklapper reopened this Oct 24, 2023
@aklapper
Copy link
Author

@NdibeRaymond This is still an issue when I go to https://wikicontrib.toolforge.org/ - how was this resolved? If this was resolved, do you plan to deploy the changes?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants