2023-08-03 Meeting notes
Date
Aug 3, 2023
Attendees
Name | Present |
|---|---|
@Craig McNally | Y |
@Julian Ladisch |
|
@Axel Dörrer |
|
@Ryan Berger (Deactivated) |
|
@Chris Rutledge | Y |
@Jakub Skoczen | Y |
@John Coburn | Y |
@Skott Klebe |
|
|
|
Discussion items
Time | Item | Who | Notes |
|---|---|---|---|
5 min | Embargoed Vulnerability Process Retro | Team | When do we want to schedule this?
|
0 min | OWASP/SNYK | Team |
Today:
|
1 min | NCT group (Pen. testing) | @Axel Dörrer | Progress is slow... at most expect monthly updates.
Today:
|
1 min | STCOR-395 "refactor login form to avoid using any form framework whatsoever" | All | Create a spike to investigate what's involved in divorcing the login page from the NPM ecosystem. Will reach out to John and Ryan as needed. Reopen STCOR-395 and block on the spike. – Done. Where does this stand? Get an update from @Ryan Berger (Deactivated) / @John Coburn Waiting for the spike () to be completed. – currently in the Open state. John to reach out to Skott to discuss what the level of risk associated with this. – Still needs to happen. @John Coburn pulled together two PoCs. See comments in How do we want to move forward? Solutions need to be reviewed and discussed. Sounds like the iframe approach is a non-starter... actually a step in the wrong direction security-wise @John Coburn (and others) to read up on browser CSPs @John Coburn has made some progress on investing CSPs Will share some draft guidance we may want to include into the installation documentation (via slack) SG will review and provide feedback. @Skott Klebe please take a look too Next up: John to work on some spike work - focused on introducing CSPs on the folio-snapshot site can serve as a reference impl of the guidance we'll be adding to the install docs Not much progress since last week, but hopefully get some movement on this soon. Spike @John Coburn trying to get this lined up for next sprint @John Coburn to discuss with another developer (Maccabee) who is familiar with CSPs. John had the chance to look on it but only via metatag need to try out or examine http header configuration at the server side Some things happen in stripes modularity too which might have impact too @John Coburn is making progress - has done some testing locally, but wants to exercise it in a more realistic env. @John Coburn provided update on CSP effort. Experimenting with express to provide CSP (for local dev purposes). Production systems wouldn't use this, it would be formalized by the hosting provider. This allows for local testing and experiments. Today:
|
1 min | Disable tenant checking to support multi tenant requests (MODAT-143). | @Julian Ladisch / All | A few wiki pages have been shared on this... See Enhanced Consortia Support(ECS) @Julian Ladisch will discuss his concerns with Olamide, etc. and we can discuss here again if/when needed.
Today:
|
5 min | FOLIO-3535 Upgrade bitnami/elasticsearch:7.10.2 in reference and vagrant development boxes (folio-ansible) | All |
Today:
|
5-10 min | Craig/Jakub | The wording should be adjusted, it's a little misleading Also need to determine if this is a must have for the Refresh token work. See discussion in slack channel for additional details. TODO:
Ideas:
Today:
| |
* | Review the Kanban board. | Team |
Today: |
Topic Backlog | |||
| Retiring issues which have been open for a long time w/o progress | All | Discussed gathering a report for the TC to review/approve. Need to work out details/logistics. Query so far:
|
| Bot Detection/Control | All |
|
| Time slot | All | Do we need a better time slot for the security team meeting to allow more members to join? |
| Logging & Personal Data | Craig/Team | A developer recently reached to me asking if the security team or TC has guidance or rules in place for logging of personal data. Some guidelines are documented on the wiki, but I'm wondering if it's worth making some clarifications and creating a draft decision record for the TC to formally endorse Is this even in our purview? Should we seek input from the Privacy SIG? Should I raise this with the TC first? Next steps:
|
| Cyber Resilience Act | Team |
|
Action items
Hi Security Team!
Has there been any work to create patches for the July-20 Security Vulnerability for the Morning Glory release ?