Page MenuHomePhabricator

Setup Semantic MediaWiki on Czech Wikiversity
Closed, DeclinedPublic

Description

Hi, I would like to ask developers to set up Semantic MediaWiki extension on Czech Wikiversity (cs.wikiversity.org). The link to the agreement of the community is here:
http://cs.wikiversity.org/wiki/Wikiverzita:Diskusn%C3%AD_prostor#Request.2F.C5.BD.C3.A1dost


Version: unspecified
Severity: enhancement

Details

Reference
bz25410

Event Timeline

bzimport raised the priority of this task from to Medium.Nov 21 2014, 11:11 PM
bzimport set Reference to bz25410.
bzimport added a subscriber: Unknown Object (MLST).

This extension will need a security review (+need-review)

Regarding the security review, I note that SMW also is available in a "light" variant that has reduced features but that can already be of some use. This SMWLight extension does not support inline queries and drops some datatypes, but it allows data collection, export, and basic retrieval. SMWLight is much smaller in size (currently about 6000 LOC).

It might be a useful strategy to start reviewing this core component first. There is no packaged release of SMWLight yet -- it is rather a configuration for deploying the complete code that makes many files obsolete. If a package of this abridged version is needed, I can provide it upon request. The fact that SMWLight uses the same files as SMW proper also means that any reviewing effort is also useful toward accomplishing the complete reviewing task.

Well, we are just Wikimedians. What is that security review about and why SMWLight doesnt need such review?

(In reply to comment #4)

Well, we are just Wikimedians. What is that security review about and why
SMWLight doesnt need such review?

It means the code needs to be looked at to make sure it doesn't have any security vulnerabilities. SMWLight would also need one; the reason Markus brought it up is that SMWLight is much less code, so it wouldn't take as long to review.

See https://www.mediawiki.org/wiki/Writing_an_extension_for_deployment for information on what is needed to get an extension reviewed before potentially deploying it on a wikisite.

Marking WONTFIX per bug 8390 comment 24