<?xml version="1.0"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Transition Technology: Ticket #391: PSE tracking, moderation and security</title>
    <link>http://localhost:8080/trac/ticket/391</link>
    <description>&lt;p&gt;
This ticket is track time spent on the Tracking, Moderation and Security discussion which has a wiki page here: &lt;a class="ext-link" href="https://wiki.transitionnetwork.org/Sharing_Engine/Tracking,_Moderation_and_Security"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://wiki.transitionnetwork.org/Sharing_Engine/Tracking,_Moderation_and_Security&lt;/a&gt;
&lt;/p&gt;
</description>
    <language>en-us</language>
    <image>
      <title>Transition Technology</title>
      <url>/trac/chrome/site/TransitionNetwork-Logo-Web-Small.jpg</url>
      <link>http://localhost:8080/trac/ticket/391</link>
    </image>
    <generator>Trac 0.12.5</generator>
    <item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Thu, 02 Feb 2012 11:57:10 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/391#comment:1</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/391#comment:1</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.5&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.5&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Some initial thoughts have been added to the wiki:
&lt;/p&gt;
&lt;p&gt;
&lt;a class="ext-link" href="https://wiki.transitionnetwork.org/index.php?title=Sharing_Engine/Tracking,_Moderation_and_Security&amp;amp;oldid=326"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://wiki.transitionnetwork.org/index.php?title=Sharing_Engine/Tracking,_Moderation_and_Security&amp;amp;oldid=326&lt;/a&gt;
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Fri, 03 Feb 2012 11:10:48 GMT</pubDate>
      <title>milestone changed</title>
      <link>http://localhost:8080/trac/ticket/391#comment:2</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/391#comment:2</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;milestone&lt;/strong&gt;
                changed from &lt;em&gt;Phase 6&lt;/em&gt; to &lt;em&gt;PSE&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Milestone changed to PSE
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Fri, 03 Feb 2012 11:31:36 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/391#comment:3</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/391#comment:3</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.23&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;0.5&lt;/em&gt; to &lt;em&gt;0.73&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
I did some more work on this wiki page:
&lt;/p&gt;
&lt;p&gt;
&lt;a class="ext-link" href="https://wiki.transitionnetwork.org/index.php?title=Sharing_Engine%2FTracking%2C_Moderation_and_Security&amp;amp;action=historysubmit&amp;amp;diff=333&amp;amp;oldid=326"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://wiki.transitionnetwork.org/index.php?title=Sharing_Engine%2FTracking%2C_Moderation_and_Security&amp;amp;action=historysubmit&amp;amp;diff=333&amp;amp;oldid=326&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Which of these approaches (or a mixture of them) are we going to adopt for the widget?
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;HTML forms
&lt;/li&gt;&lt;li&gt;Javascript write
&lt;/li&gt;&lt;li&gt;Iframes
&lt;/li&gt;&lt;/ul&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Mon, 06 Feb 2012 11:48:41 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/391#comment:4</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/391#comment:4</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.75&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;0.73&lt;/em&gt; to &lt;em&gt;1.48&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
I have done some research on iframes and written it up here:
&lt;/p&gt;
&lt;p&gt;
&lt;a class="ext-link" href="https://wiki.transitionnetwork.org/index.php?title=Sharing_Engine/Tracking,_Moderation_and_Security&amp;amp;oldid=335#iframes"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://wiki.transitionnetwork.org/index.php?title=Sharing_Engine/Tracking,_Moderation_and_Security&amp;amp;oldid=335#iframes&lt;/a&gt;
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>jim</dc:creator>

      <pubDate>Sun, 11 Mar 2012 20:44:17 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/391#comment:5</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/391#comment:5</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.25&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;1.48&lt;/em&gt; to &lt;em&gt;1.73&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Thanks Chris.
&lt;/p&gt;
&lt;h3 id="structureiframesjs"&gt;structure, iframes &amp;amp; js&lt;/h3&gt;
&lt;p&gt;
Further to your research and documentation, the structure of the widget has been defined here: &lt;a class="ext-link" href="https://wiki.transitionnetwork.org/Sharing_Engine/Widget_structure"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://wiki.transitionnetwork.org/Sharing_Engine/Widget_structure&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
We're going for 'progressive enhancement', so the basic 'view' widget will just be an IFrame showing some information on TN.org. The 'Add your project' button will be a plain link that sends a user to TN.org to add their project. BUT if they have &lt;a class="missing wiki"&gt;JavaScript?&lt;/a&gt; enabled, they'll get a nice modal dialogue containing the widget, so they don't 'leave' the underlying page.
&lt;/p&gt;
&lt;p&gt;
Devices/browsers that don't support iFrames will not be able to use the widgets.
&lt;/p&gt;
&lt;h3 id="Securityspam"&gt;Security &amp;amp; spam&lt;/h3&gt;
&lt;p&gt;
Some basic CAPTCHA will be present on all entry forms, and all content posted though the widget must be moderated before going live. This may change in the beta/full version.
&lt;/p&gt;
&lt;p&gt;
All widgets will send an ID to the site that will check they have permission to post through the widget. This is clearly basic security, and if it's not enough we can look at ajax requests that allow posts from an IP based on the referer HTTP header matching. Again, basic and easily beaten by someone wanting to get in, but then they'll hit the moderation.
&lt;/p&gt;
&lt;p&gt;
Further beefing of security is probably beyond the scope of the alpha version, and might necessitate meatier coding/authentication.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Tue, 29 Jan 2013 17:34:59 GMT</pubDate>
      <title>status changed; resolution set</title>
      <link>http://localhost:8080/trac/ticket/391#comment:6</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/391#comment:6</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;status&lt;/strong&gt;
                changed from &lt;em&gt;new&lt;/em&gt; to &lt;em&gt;closed&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;resolution&lt;/strong&gt;
                set to &lt;em&gt;fixed&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Closing this ticket as this has been resolved.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item>
 </channel>
</rss>