You are viewing a plain text version of this content. The canonical link for it is here.
Posted to infrastructure-issues@apache.org by "jan iversen (JIRA)" <ji...@apache.org> on 2014/02/04 21:02:12 UTC

[jira] [Updated] (INFRA-7173) update AOO wiki vm and forum with PMC requested changes.

     [ https://issues.apache.org/jira/browse/INFRA-7173?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

jan iversen updated INFRA-7173:
-------------------------------

    Description: 
The AOO PMC have put a vm-team in place for maintenance (pescetti, arist, imacat and jsc) and jani as sysadm for the 2 project vms.

This issue is mainly a project issue, but are kept at infra level, due to the security implications.

All maintenance will be done as agreed on the ML by the sysadm, and the vm-team is first response for any outages. 

Current karma will not be touched, unless the rules of the proposal are broken, especially meaning modifying the vms without prior agrement.

The following outstandings have been identified and agreed on with lazy consensus (thanks to pescetti):

Wiki1: Upgrade Mediawiki DONE

Wiki2: install RecentChangesLogFilter extension
https://www.mediawiki.org/wiki/Extension:RecentChangesLogFilter to filter out non-interesting recent changes (such as user registrations); but still make user registrations available in the RSS feed if possible.

Wiki3: mod_fcgid 2.3.9 released (when upgrading, make sure to test the "cooperation" with ats, since header handling have changed)

Wiki4: Apache Traffic Server 4.0.2 is released; the ATS caching needs to be corrected

Wiki5: any href= or src= that contains http:// will give a user warning (actually, href shouldn't)

Wiki6: Cats/Dogs CAPTCHA for new user registration is quite broken. It doesn't work in several browser configurations, it includes HTTP instead of HTTPS https://issues.apache.org/ooo/show_bug.cgi?id=123695 -> Recommended solution: drop it entirely.

accessibility suggestion from Tyler (haven't tested MediaWiki compatibility): there is a website which provides text-based CAPTCHA's in the form of logic questions, math problems, etc. It provides an XML API. See http://www.textcaptcha.com/

Wiki7: fix Google CSE, changing http to https endpoints in GoogleCoop/GoogleCoop.php and then reverting https://wiki.openoffice.org/w/index.php?title=Documentation%2FFAQ%2FInstallation&diff=232487&oldid=188626

Forum1: changed parts of php2bb needs to be added to svn

Forum2: could benefit a lot from having ATS installed, but that requires a change in the httpd config. If this is considered, please consider update httpd as well, the newer versions allow fastCGI which on wiki gave us an overall factor on performance.

Forum3: the php2bb could really do with a optimization (especially with sqlconnections).

Forum4: any href= or src= that contains http:// will give a user warning (actually, href shouldn't)

Forum5: all users have the same IP; configuration must use the ip address from the http header (original address) instead of the tcp/ip addr (any proxy addr). Replace $_SERVER['REMOTE_ADDR'] in session_begin   in   session.php with $_SERVER['HTTP_X_FORWARDED_FOR']

Forum6: implement private admin mailing list for EN forum (now a Gmail account)

Forum7: implement private admin mailing list for ES forum (now a .org account provided by Mauricio Baeza)

Forum8: new images see https://forum.openoffice.org/en/forum/viewtopic.php?f=50&t=63523&start=90#p296713 and http://people.apache.org/~pescetti/tmp/2014-01-forum/ ; this requires CSS fixes too, that can be done by Andrea.



  was:
The AOO PMC have put a vm-team in place for maintenance (pescetti, arist, imacat and jsc) and jani as sysadm for the 2 project vms.

This issue is mainly a project issue, but are kept at infra level, due to the security implications.

All maintenance will be done as agreed on the ML by the sysadm, and the vm-team is first response for any outages. 

Current karma will not be touched, unless the rules of the proposal are broken, especially meaning modifying the vms without prior agrement.

The following outstandings have been identified and agreed on with lazy consensus (thanks to pescetti):

Wiki1: Upgrade Mediawiki

Wiki2: install RecentChangesLogFilter extension
https://www.mediawiki.org/wiki/Extension:RecentChangesLogFilter to filter out non-interesting recent changes (such as user registrations); but still make user registrations available in the RSS feed if possible.

Wiki3: mod_fcgid 2.3.9 released (when upgrading, make sure to test the "cooperation" with ats, since header handling have changed)

Wiki4: Apache Traffic Server 4.0.2 is released; the ATS caching needs to be corrected

Wiki5: any href= or src= that contains http:// will give a user warning (actually, href shouldn't)

Wiki6: Cats/Dogs CAPTCHA for new user registration is quite broken. It doesn't work in several browser configurations, it includes HTTP instead of HTTPS https://issues.apache.org/ooo/show_bug.cgi?id=123695 -> Recommended solution: drop it entirely.

accessibility suggestion from Tyler (haven't tested MediaWiki compatibility): there is a website which provides text-based CAPTCHA's in the form of logic questions, math problems, etc. It provides an XML API. See http://www.textcaptcha.com/

Wiki7: fix Google CSE, changing http to https endpoints in GoogleCoop/GoogleCoop.php and then reverting https://wiki.openoffice.org/w/index.php?title=Documentation%2FFAQ%2FInstallation&diff=232487&oldid=188626

Forum1: changed parts of php2bb needs to be added to svn

Forum2: could benefit a lot from having ATS installed, but that requires a change in the httpd config. If this is considered, please consider update httpd as well, the newer versions allow fastCGI which on wiki gave us an overall factor on performance.

Forum3: the php2bb could really do with a optimization (especially with sqlconnections).

Forum4: any href= or src= that contains http:// will give a user warning (actually, href shouldn't)

Forum5: all users have the same IP; configuration must use the ip address from the http header (original address) instead of the tcp/ip addr (any proxy addr). Replace $_SERVER['REMOTE_ADDR'] in session_begin   in   session.php with $_SERVER['HTTP_X_FORWARDED_FOR']

Forum6: implement private admin mailing list for EN forum (now a Gmail account)

Forum7: implement private admin mailing list for ES forum (now a .org account provided by Mauricio Baeza)

Forum8: new images see https://forum.openoffice.org/en/forum/viewtopic.php?f=50&t=63523&start=90#p296713 and http://people.apache.org/~pescetti/tmp/2014-01-forum/ ; this requires CSS fixes too, that can be done by Andrea.




> update AOO wiki vm and forum with PMC requested changes.
> --------------------------------------------------------
>
>                 Key: INFRA-7173
>                 URL: https://issues.apache.org/jira/browse/INFRA-7173
>             Project: Infrastructure
>          Issue Type: Task
>          Components: Website
>         Environment: ubuntu 12.04
>            Reporter: jan iversen
>            Assignee: jan iversen
>
> The AOO PMC have put a vm-team in place for maintenance (pescetti, arist, imacat and jsc) and jani as sysadm for the 2 project vms.
> This issue is mainly a project issue, but are kept at infra level, due to the security implications.
> All maintenance will be done as agreed on the ML by the sysadm, and the vm-team is first response for any outages. 
> Current karma will not be touched, unless the rules of the proposal are broken, especially meaning modifying the vms without prior agrement.
> The following outstandings have been identified and agreed on with lazy consensus (thanks to pescetti):
> Wiki1: Upgrade Mediawiki DONE
> Wiki2: install RecentChangesLogFilter extension
> https://www.mediawiki.org/wiki/Extension:RecentChangesLogFilter to filter out non-interesting recent changes (such as user registrations); but still make user registrations available in the RSS feed if possible.
> Wiki3: mod_fcgid 2.3.9 released (when upgrading, make sure to test the "cooperation" with ats, since header handling have changed)
> Wiki4: Apache Traffic Server 4.0.2 is released; the ATS caching needs to be corrected
> Wiki5: any href= or src= that contains http:// will give a user warning (actually, href shouldn't)
> Wiki6: Cats/Dogs CAPTCHA for new user registration is quite broken. It doesn't work in several browser configurations, it includes HTTP instead of HTTPS https://issues.apache.org/ooo/show_bug.cgi?id=123695 -> Recommended solution: drop it entirely.
> accessibility suggestion from Tyler (haven't tested MediaWiki compatibility): there is a website which provides text-based CAPTCHA's in the form of logic questions, math problems, etc. It provides an XML API. See http://www.textcaptcha.com/
> Wiki7: fix Google CSE, changing http to https endpoints in GoogleCoop/GoogleCoop.php and then reverting https://wiki.openoffice.org/w/index.php?title=Documentation%2FFAQ%2FInstallation&diff=232487&oldid=188626
> Forum1: changed parts of php2bb needs to be added to svn
> Forum2: could benefit a lot from having ATS installed, but that requires a change in the httpd config. If this is considered, please consider update httpd as well, the newer versions allow fastCGI which on wiki gave us an overall factor on performance.
> Forum3: the php2bb could really do with a optimization (especially with sqlconnections).
> Forum4: any href= or src= that contains http:// will give a user warning (actually, href shouldn't)
> Forum5: all users have the same IP; configuration must use the ip address from the http header (original address) instead of the tcp/ip addr (any proxy addr). Replace $_SERVER['REMOTE_ADDR'] in session_begin   in   session.php with $_SERVER['HTTP_X_FORWARDED_FOR']
> Forum6: implement private admin mailing list for EN forum (now a Gmail account)
> Forum7: implement private admin mailing list for ES forum (now a .org account provided by Mauricio Baeza)
> Forum8: new images see https://forum.openoffice.org/en/forum/viewtopic.php?f=50&t=63523&start=90#p296713 and http://people.apache.org/~pescetti/tmp/2014-01-forum/ ; this requires CSS fixes too, that can be done by Andrea.



--
This message was sent by Atlassian JIRA
(v6.1.5#6160)