08.18.2020 TT Agenda - QualitativeDataRepository/TechnicalTeam GitHub Wiki

People

@nniicc @adam3smith @stahs @qqmyers

Goals

Discussion Topics

Admin

Seba & Jim Coordination

  • CORS/direct download from S3 item noted in Plans

Seba

  • Item

Jim

  • Jim's Report
  • Ready to deploy D8 and Dataverse changes to prod - would be useful to discuss whether we should turn on direct download as part of that and whether we should also lock CORS down further using CSP (as noted above). (Direct download is probably worth it. The additional CORS constraints are not hard, but when CORS is only being used to download content files, and when using presigned URLs (versus web pages), it's not clear there's much someone could do. It is something that would stop others from continuing to use QDR's previewers instead of the ones hosted at GDCC.)

Notes

Assigned Tasks / Decisions