Open
Bug 1449026
Opened 7 years ago
Updated 7 years ago
Infosec review of third party code (js) for use on www.mozilla.org
Categories
(mozilla.org :: Security Assurance: Review Request, task)
mozilla.org
Security Assurance: Review Request
Tracking
(Not tracked)
NEW
People
(Reporter: erenaud, Unassigned)
References
Details
Marketing requirements for the Portland campaign include the use of a 3rd party font on www.mozilla.org
We've licensed the font, which requires use of js to track page views.
The code needing review and sign off by Infosec is here https://bugzilla.mozilla.org/attachment.cgi?id=8962437
| Reporter | ||
Comment 1•7 years ago
|
||
Please note required launch of the webpage is 3/30/2018
Comment 2•7 years ago
|
||
If it helps, the page is on a demo server [1], and the code is available in an in-progress PR [2].
[1] https://bedrock-demo-jpetto.us-west.moz.works/en-US/firefox/new/?xv=portland
[2] https://github.com/mozilla/bedrock/pull/5525/
Comment 3•7 years ago
|
||
CCing April
Comment 4•7 years ago
|
||
Do you have the un-minified JavaScript for code review?
Comment 6•7 years ago
|
||
:jpetto ripped out that script, so I got my only security concern answered.
Thanks so much!
Flags: needinfo?(jon)
You need to log in
before you can comment on or make changes to this bug.
Description
•