...
Time | Item | Who | Notes | |||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1 min | mod-configuration - should it be deprecated or not? | Julian Ladisch | mod-configuration has been discussed on the development channel recently. Developers like it because they can simply drop variables to the /configurations/entries API. Simply use the "configuration.*" permission shared by all modules and you are done. No need to add schema validation, no need to add dedicated permissions, no need to add a dedicated API.
Team decided we want to have this as a RFC. Target should be to have this implemented within Nolana. Could discuss in your meetings while the RFC process moves on.
Today:
| |||||||||||||||
0 min | Kafka security | Team | The topic of Kafka security was raised as part of a conversation at the TC yesterday. The Security Team should be aware of this and probably should weigh in on the topic, or even generate proposals if we have ideas for how to solve the problem.
Today:
| |||||||||||||||
5-10 min | OWASP | Team | Jakub Skoczen raised the idea of evaluating if FOLIO meets these standards. Ryan Berger has run some tools a while back, but it's probably time to revisit, and maybe take it further.
Today:
| |||||||||||||||
10 min | Review the Kanban board. | Team | Core platform teams has prioritized several tickets and will handle them for Nolana: https://issues.folio.org/secure/RapidBoard.jspa?rapidView=80&view=planning.nodetail&quickFilter=1688&issueLimit=100Brainstorm the cumulative upload problem | Team |
|
Jira Legacy | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
|
- FOLIO-3317 - Spike - investigate possible file upload vulnerability OPEN ), let's brainstorm ideas for mitigating the cumulative upload problem, not just he large file upload size problem.
- Some APIs are more vulnerable to this than others, such as those not protected by permissions - e.g. mod-login, edge APIs, etc.
Today:
- Axel provided some background/context. We still need to give this some thought and possibly suggest a solution
*
- Core platform teams has prioritized several tickets and will handle them for Nolana: https://folio-org.atlassian.net/secure/RapidBoard.jspa?rapidView=80&view=planning.nodetail&quickFilter=1688&issueLimit=100
Action items
- Craig McNally will create the ticket and we can revisit in a future meeting (next week or two)
...