August 2017 uPortal Slack summary


In August 2017, 2 people participated substantially in conversation in the slack.apereo.org #uportal channel. (This is around one fifth as many participants as in June.)

  • Andrew Petro
  • Christian Murphy

Conversation highlights include:

On Slack

I have concerns about the openness properties of Slack as implemented by Apereo.

  • You can’t access it anonymously.
  • It’s not Google search indexed.
  • Older messages aren’t available even if you log in.

Summarizing the conversations here on apereo.github.io in this anonymously, publicly accessible, and Google-indexable context somewhat mitigates these problems. But not necessarily other problems that make email list communications preferable in open source projects.

Arguably, all of the conversations held in the #uportal Slack channel could have been held via email on uportal-dev@ or uportal-user@ email lists additionally or instead. Some relevant email list threads are linked above.

For myself, I’m convinced that we just shouldn’t use Slack in the Apereo uPortal project. Use the email lists. Possibly look to implementing Discourse for better discussion forums / “email lists”.

See also

-Andrew

Related Posts

CAS OAuth/OpenID Connect Vulnerability Disclosure

Disclosure of a security issue with the Apereo CAS software acting as an OAuth/OpenID Connect provider.

Apereo CAS is now on Develocity

An overview of how Apereo CAS is using Gradle and Develocity to improve its build and test execution cycle.

CAS OAuth/OpenID Connect Vulnerability Disclosure

Disclosure of a security issue with the Apereo CAS software acting as an OAuth/OpenID Connect provider.

CAS Groovy Vulnerability Disclosure

Disclosure of a security issue with the Apereo CAS software when using Groovy.

CAS OpenID Connect Vulnerability Disclosure

Disclosure of a security issue with the Apereo CAS software acting as an OpenID Connect Provider.

CAS X.509 Vulnerability Disclosure

Disclosure of a security issue with the CAS software and its X.509 features.

CAS OpenID Connect Vulnerability Disclosure

Disclosure of a security issue with the CAS software acting as an OpenID Connect Provider.

CAS OpenID Connect Vulnerability Disclosure

Disclosure of a security issue with the CAS software acting as an OpenID Connect Provider.

CAS OpenID Connect Vulnerability Disclosure

Disclosure of a security issue with the CAS software acting as an OpenID Connect Provider.

CAS Spring Framework RCE Vulnerability Disclosure

Disclosure of the Spring framework RCE security issue with the Apereo CAS software.