[Project_owners] Secure installation of extensions, Project overview pages, and file release system

Onno Ekker o.e.ekker at gmail.com
Fri Mar 28 02:31:27 PDT 2008


Hi,

Can you add file_management.html url to the 
https://www.mozdev.org/profile/index.html ?
And after submitting files, you end up in an empty 
file_managment_actions.php. It would be better to return to the project 
selection page.

I don't really see why end-users would believe they now have safe 
downloads. To the user, the only thing that has changed, is that they 
can start the download from a secure website, but they can't see that 
the file is also verified and they cannot verify the file themselves, 
since you don't display the md5sum. The download itself is still from an 
unsecure website, so the user could download another file than he thinks.

Onno

Douglas E. Warner wrote:
> Mozdev.org has released a number of new features to allow projects to securely 
> install their applications and allow users to find information about projects 
> easier.
>
> Each project has an overview page that prominently displays links to all of a 
> projects tools as well as highlighting each of a project's extensions and 
> their latest releases.  Since this page is served from a secure site the 
> extensions linked from this page make use of InstallTrigger to verify that 
> the file is downloaded correctly by comparing the file's hash.
>
> Each project's overview page is at a URL with the following format:
> https://www.mozdev.org/projects/overview/PROJECT/
> ex: https://www.mozdev.org/projects/overview/www/
>
> In order to have your extensions linked from this page, you'll need to make 
> use of our new file management tool to mark files as released and verify the 
> hash for the file (documentation [2]):
> https://www.mozdev.org/profile/file_management.html
>
> Mozdev will be linking to the new project overview page from the main 
> www.mozdev.org site in various locations such as the active project list and 
> top 50 page.
>
> We hope this new feature brings both project owners and users a new level of 
> comfort knowing the extensions are installed properly and enables users to 
> find project information more quickly.
>
> -Doug
>
> [1] https://www.mozdev.org/bugs/show_bug.cgi?id=17302
> [2] http://www.mozdev.org/drupal/wiki/MozdevDownloadReleases
>
>   
> ------------------------------------------------------------------------
>
> _______________________________________________
> Project_owners mailing list
> Project_owners at mozdev.org
> https://www.mozdev.org/mailman/listinfo/project_owners
>   



More information about the Project_owners mailing list