[Project_owners] Secure installation of extensions, Project overview pages, and file release system
Onno Ekker
o.e.ekker at gmail.com
Fri Mar 28 02:31:27 PDT 2008
Hi,
Can you add file_management.html url to the
https://www.mozdev.org/profile/index.html ?
And after submitting files, you end up in an empty
file_managment_actions.php. It would be better to return to the project
selection page.
I don't really see why end-users would believe they now have safe
downloads. To the user, the only thing that has changed, is that they
can start the download from a secure website, but they can't see that
the file is also verified and they cannot verify the file themselves,
since you don't display the md5sum. The download itself is still from an
unsecure website, so the user could download another file than he thinks.
Onno
Douglas E. Warner wrote:
> Mozdev.org has released a number of new features to allow projects to securely
> install their applications and allow users to find information about projects
> easier.
>
> Each project has an overview page that prominently displays links to all of a
> projects tools as well as highlighting each of a project's extensions and
> their latest releases. Since this page is served from a secure site the
> extensions linked from this page make use of InstallTrigger to verify that
> the file is downloaded correctly by comparing the file's hash.
>
> Each project's overview page is at a URL with the following format:
> https://www.mozdev.org/projects/overview/PROJECT/
> ex: https://www.mozdev.org/projects/overview/www/
>
> In order to have your extensions linked from this page, you'll need to make
> use of our new file management tool to mark files as released and verify the
> hash for the file (documentation [2]):
> https://www.mozdev.org/profile/file_management.html
>
> Mozdev will be linking to the new project overview page from the main
> www.mozdev.org site in various locations such as the active project list and
> top 50 page.
>
> We hope this new feature brings both project owners and users a new level of
> comfort knowing the extensions are installed properly and enables users to
> find project information more quickly.
>
> -Doug
>
> [1] https://www.mozdev.org/bugs/show_bug.cgi?id=17302
> [2] http://www.mozdev.org/drupal/wiki/MozdevDownloadReleases
>
>
> ------------------------------------------------------------------------
>
> _______________________________________________
> Project_owners mailing list
> Project_owners at mozdev.org
> https://www.mozdev.org/mailman/listinfo/project_owners
>
More information about the Project_owners
mailing list