[Mageia-webteam] [Mageia-sysadm] identity.mageia.org

nicolas vigier boklm at mars-attacks.org
Tue May 15 13:21:25 CEST 2012


On Tue, 15 May 2012, Romain d'Alverny wrote:

> I'm considering apply the attached patch for identity/trunk.

It seems attachement is missing.

> 
> Applying the new global nav here means inserting a JS snippet that
> will fetch update current document HTML and CSS code (see doc at
> http://www.mageia.org/_nav/) (uses jQuery and custom JS code, see
> http://www.mageia.org/_nav/js/source.js).
> 
> Any comment? security wise, actually, because this would be extended
> to other parts of mageia.org (the main point I see is the need to
> tightly control this service source code to avoid any malicious use of
> it to sniff out info - that may require moving this service to a
> separate repository/host, but I may be missing something else).

Ok, so we need to remember to keep this hosted on a secure server, and
control commits on this. Maybe this would be better to move it outside
www on its own repository, and use an URL like http://nav.mageia.org/ ?



More information about the Mageia-webteam mailing list