Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update Sendy List ID #976

Closed
2 tasks
SammySteiner opened this issue Jan 4, 2024 · 4 comments
Closed
2 tasks

Update Sendy List ID #976

SammySteiner opened this issue Jan 4, 2024 · 4 comments
Assignees

Comments

@SammySteiner
Copy link
Contributor

SammySteiner commented Jan 4, 2024

Summary

Sendy recommended hardcoding our sendy url, api key, and list id directly in the html of the application.
While we already removed that from the codebase and from the client browser, the url and list id are still in our github history. While the url likely cannot be changed, we should update the list id to prevent any possible malicious use.

Acceptance criteria

  • Sendy list id present in git history is no longer used by the application
  • Sendy list id present in git history is no longer valid in Sendy's system

Note that this ticket previously called for rewriting the git history to remove any Sendy secret data. As this was deemed too risky and complex, the AC was updated.

@SammySteiner SammySteiner added the project: grants.gov Grants.gov Modernization tickets label Jan 4, 2024
@SammySteiner SammySteiner moved this from Icebox to Sprint Ready in Simpler.Grants.gov Product Backlog Jan 4, 2024
@acouch acouch modified the milestones: Security - control implementations, Security - future work Jan 5, 2024
@sumiat sumiat moved this from Sprint Ready to Icebox in Simpler.Grants.gov Product Backlog Feb 7, 2024
@margaretspring margaretspring removed this from the Security - Future work milestone Oct 29, 2024
@mxk0 mxk0 moved this from Icebox to Todo in Simpler.Grants.gov Product Backlog Nov 11, 2024
@mxk0 mxk0 removed the project: grants.gov Grants.gov Modernization tickets label Nov 11, 2024
@mxk0 mxk0 changed the title [Task]: Remove Sendy Info from github history Remove Sendy Info from github history Nov 11, 2024
@doug-s-nava doug-s-nava self-assigned this Nov 15, 2024
@margaretspring margaretspring self-assigned this Nov 22, 2024
@margaretspring
Copy link
Collaborator

@doug-s-nava - Given this has been an open ticket since last Jan. Do you have any objections to pushing it out past the 12/10 deadlines? At that point we'll have a bit of bandwidth to explore rebuilding the account profile to invalidate the one with published data.

@doug-s-nava doug-s-nava changed the title Remove Sendy Info from github history Update Sendy List ID Nov 25, 2024
@doug-s-nava
Copy link
Collaborator

That works for me. I don't think this is particularly pressing. Moving back to the icebox for now.

@doug-s-nava doug-s-nava moved this from In Progress to Icebox in Simpler.Grants.gov Product Backlog Nov 25, 2024
@mxk0 mxk0 moved this from Icebox to Todo in Simpler.Grants.gov Product Backlog Nov 25, 2024
@mxk0
Copy link
Collaborator

mxk0 commented Nov 26, 2024

Noting for posterity that there are a bunch of details from Doug's investigation here.

@mxk0
Copy link
Collaborator

mxk0 commented Nov 26, 2024

We're likely moving off of Sending in the next quad or so; marking this as won't fix.

@mxk0 mxk0 closed this as not planned Won't fix, can't repro, duplicate, stale Nov 26, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Development

No branches or pull requests

5 participants