Closed Bug 1616372 Opened 5 years ago Closed 4 years ago

[meta] Simplified about:welcome remotely-configured multivariate experiments

Categories

(Firefox :: Messaging System, enhancement, P1)

enhancement

Tracking

()

RESOLVED WORKSFORME
Firefox 76
Tracking Status
firefox74 --- unaffected
firefox75 --- wontfix
firefox76 --- affected

People

(Reporter: pdahiya, Assigned: pdahiya)

References

Details

(Keywords: meta)

Attachments

(1 file)

Update about:welcome simplified full page with ability to change content via experiments (e.g. the title text) without landing code (i.e. normandy integration)

See https://bugzilla.mozilla.org/show_bug.cgi?id=1616370

Iteration: --- → 75.2 - Feb 24 - Mar 8
Priority: -- → P1
Target Milestone: --- → Firefox 75
Priority: P1 → P2
Assignee: nobody → pdahiya
Iteration: 75.2 - Feb 24 - Mar 8 → 76.1 - Mar 9 - Mar 22
Priority: P2 → P1
Iteration: 76.1 - Mar 9 - Mar 22 → ---
Keywords: meta
Summary: Update about:welcome simplified full page to support changing content via experiments → Simplified about:welcome to support changing content via experiments
Target Milestone: Firefox 75 → Firefox 76
Summary: Simplified about:welcome to support changing content via experiments → Simplified about:welcome remotely-configured multivariate experiments
Summary: Simplified about:welcome remotely-configured multivariate experiments → [meta] Simplified about:welcome remotely-configured multivariate experiments
Depends on: 1622474
Depends on: 1622475
Depends on: 1622476
Depends on: 1622479
Depends on: 1622928
Depends on: 1623710
Depends on: 1624460
Depends on: 1624509
Depends on: 1630456
Depends on: 1631921

Per @dveditz@mozilla.com from Security:

"I've gone over the review request and taken a look at the code. I'm happy to see that about:welcome itself and the remote control experiment mechanism follows the well-tested patterns used in other Messaging System projects like about:newtab.

I don't have any security concerns about the code design itself. As noted in your review request, changing the data on the Remote Settings server changes content in the client. It's not "hacking", but like most of our other Remote Settings, unauthorized changes would result in reputational harm and brand damage. I know from other projects that Remote Settings changes typically require two people, analogous to the review requirement for Firefox code commits. I don't know enough about how Remote Settings are managed to know if that's a blanket requirement or if each project has to set that up, but it should be in force here."

Considering all dependent bugs are resolved and the feature is successfully rolled out in 76, closing tracking bug as resolved

Status: NEW → RESOLVED
Closed: 4 years ago
Resolution: --- → WORKSFORME
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: