Skip to content
This repository has been archived by the owner on Nov 16, 2022. It is now read-only.

onboard @nashe #712

Closed
chadwhitacre opened this issue Jul 12, 2016 · 48 comments
Closed

onboard @nashe #712

chadwhitacre opened this issue Jul 12, 2016 · 48 comments

Comments

@chadwhitacre
Copy link
Contributor

gratipay/gratipay.com#4081
#134 (comment)
#704 (comment)

Do you have any wishes actually related to the translation process? Like more documentation, automation…

I'm somewhat interested by security-related stuff too, since I'm working in this area.
I'll try to catch you on IRC one of these days, so we can talk about this :-)

@chadwhitacre
Copy link
Contributor Author

Do you have any wishes actually related to the translation process?

@Nashe Mostly I want to make sure we're paying attention to activity on Transifex and responding to work from translators in a timely fashion. I have a nagging sense that our translators are second-class citizens around here, partly because we're so GitHub-centric. I want to make sure our translators are communicating with each other and with the rest of us effectively.

I'm somewhat interested by security-related stuff too, since I'm working in this area.

Nice! We could sure use help there, as well; here's our docs. @TheHmadQureshi has been helping with triage in HackerOne. Are you familiar with HackerOne? Where do you see yourself contributing security-wise? Can you help us actually fix some of the issues piling up on our security radar (#705)? :-)

I'll try to catch you on IRC one of these days, so we can talk about this :-)

I'm actually not using IRC right now. Can we talk here on GitHub? :)

@chadwhitacre
Copy link
Contributor Author

Case in point: I just noticed that we have "7 issues" ... questions about translations, some of which appear to be quite old. :-(

screen shot 2016-07-12 at 8 41 51 am

We need someone to stay on top of these kinds of things in Transifex. Does that sound like a good fit for you, @Nashe?

@chadwhitacre
Copy link
Contributor Author

@Nashe I've made you an administrator of the Gratipay org on Transifex.

@chadwhitacre
Copy link
Contributor Author

Wanna answer those 7 issues? :-)

@ghost
Copy link

ghost commented Jul 12, 2016

@Nashe Mostly I want to make sure we're paying attention to activity on Transifex and responding to work from translators in a timely fashion. I have a nagging sense that our translators are second-class citizens around here, partly because we're so GitHub-centric. I want to make sure our translators are communicating with each other and with the rest of us effectively.

It seems to be the case for the all projects I've been translating for. Let's try to figure a way to improve this relationship. Transifex seems to offer inter-teams forums and public announcements, it may be a way to improve it!

Nice! We could sure use help there, as well; here's our docs. @TheHmadQureshi has been helping with triage in HackerOne. Are you familiar with HackerOne? Where do you see yourself contributing security-wise? Can you help us actually fix some of the issues piling up on our security radar (#705)? :-)

Not especially with the HackerOne UI, but I'm following what's happening on this platform (though @disclosedh1) and I'm hunting bugs on one French platform. I may try to do some triage, depend of how much free time I have. But I'll definitely interest me. Regarding the issues, same thing, I'll take a look :-)

We need someone to stay on top of these kinds of things in Transifex. Does that sound like a good fit for you, @Nashe?

Sure! I plan to improve the inside.gratipay.com page related to translation in order to explain how to find the current context (spoiler: using the "Details" tab + Github).

Wanna answer those 7 issues? :-)

Yep \o

@chadwhitacre
Copy link
Contributor Author

Let's try to figure a way to improve this relationship.

I think having someone take responsibility for it will go a long way. @mattbk has been doing a great job staying on top of customer support (Freshdesk) and team review. @TheHmadQureshi has been helping out with security triage (HackerOne). We need someone to do the same for translations, to act as a bridge between Transifex and GitHub. Seems like you're comfortable in both! :-)

I may try to do some triage,

Cool. I've sent you an invite to our HackerOne program so you can browse our security queue.

Yep \o

💃

@ghost
Copy link

ghost commented Jul 12, 2016

Cool. I've sent you an invite to our HackerOne program so you can browse our security queue.

Can you send me another one? I had to create a new account to redeem it and it's now giving me a "Page not found".

(Edit: my account was created with [email protected])

@chadwhitacre
Copy link
Contributor Author

Done!

@ghost
Copy link

ghost commented Jul 12, 2016

You're now part of team Gratipay.

Sounds like it worked 👍

@ghost
Copy link

ghost commented Jul 12, 2016

How are you handling the H1 reports? Should we only triage them and leave the resolution/closing stuff for you? (eg. #136720 has been resolved but forgot).

@chadwhitacre
Copy link
Contributor Author

How are you handling the H1 reports? Should we only triage them and leave the resolution/closing stuff for you?

I'm happy for others to move H1 reports through the workflow, I don't need to be the one to do it. We just may need to evolve the docs to make sure we're all on the same page. :)

(e.g. #136720 has been resolved but forgot)

@Nashe 136720 is about error pages, not the Server header.

@ghost
Copy link

ghost commented Jul 12, 2016

@Nashe 136720 is about error pages, not the Server header.

You made me doubt, so I checked the documentation and it appears to be the same configuration directive for the two, cf. http://nginx.org/en/docs/http/ngx_http_core_module.html#server_tokens:

Enables or disables emitting nginx version in error messages and in the “Server” response header field.

So you fixed it without willing to :^)

If you have some time, can you review gratipay/grtp.co#141? You'll be able to close another H1 ticket at once 👍

@chadwhitacre
Copy link
Contributor Author

May I add you as a collaborator on GitHub? We prefer to make PRs from topic branches in the same repo rather than from personal forks, so that multiple people can commit to the same PR.

@ghost
Copy link

ghost commented Jul 12, 2016

You can :-)

@chadwhitacre
Copy link
Contributor Author

Invite sent! I've added you to the @gratipay/gratipay and @gratipay/security teams.

@ghost
Copy link

ghost commented Jul 12, 2016

Aaand accepted, thanks!

@chadwhitacre
Copy link
Contributor Author

Welcome aboard! :-)

@chadwhitacre
Copy link
Contributor Author

chadwhitacre commented Jul 12, 2016

Picking up from gratipay/grtp.co#141 (comment) ...

I can't close the related report

I double-checked permissions, and you should be able to. If you still can't, can you contact support@hackerone?

screen shot 2016-07-12 at 1 52 14 pm

@ghost
Copy link

ghost commented Jul 12, 2016

It was not displayed inside the little dropdown… it's now the case after logout && login. Weird. Thanks for the double-check!

@chadwhitacre
Copy link
Contributor Author

@Nashe Do you use Twitter? If so, what's your handle? And may I thank you there? :)

@ghost
Copy link

ghost commented Jul 12, 2016

I'm not using Twitter atm, sorry!

@chadwhitacre
Copy link
Contributor Author

@Nashe No worries! Just thought I'd ask. :-)

@ghost ghost mentioned this issue Jul 13, 2016
@ghost
Copy link

ghost commented Jul 13, 2016

@whit537: Just to know, in which timezone are you?

@chadwhitacre
Copy link
Contributor Author

@Nashe UTC-4 (US/Eastern, Pittsburgh :)

You're in Europe, ya?

@ghost
Copy link

ghost commented Jul 13, 2016

@whit537 Yep, Berlin atm.

@chadwhitacre
Copy link
Contributor Author

@Nashe My primary availability for Gratipay work is Wednesday and Thursday from 9am to 5pm local time, and often Tuesday as well.

@ghost
Copy link

ghost commented Jul 13, 2016

@whit537 It's nice to know, thanks ;-)

@chadwhitacre
Copy link
Contributor Author

:)

@chadwhitacre
Copy link
Contributor Author

@Nashe Re: 118699, our habit is to not use "Team only" comments, because we want to be able to publish the entire record when we disclose. All comments, including severity discussions, should be posted to "All participants."

@ghost
Copy link

ghost commented Jul 13, 2016

Noted, I'll make it public next time 😭

@chadwhitacre
Copy link
Contributor Author

Thanks. :)

@ghost
Copy link

ghost commented Jul 21, 2016

What's the goal of a participant'sis_free_rider attribute? I'm saw something like "can use Gratipay for free" but it's not making much more sense to me.

@chadwhitacre
Copy link
Contributor Author

Free riders are those who benefit without paying. In our case, the attribute refers to those who have clicked the "No thanks" link on our global call to action, explicitly opting out of supporting Gratipay.

screen shot 2016-07-21 at 9 52 11 pm

@ghost
Copy link

ghost commented Jul 22, 2016

Thanks :)

@ghost
Copy link

ghost commented Aug 21, 2016

@whit537: how is assets.gratipay.com working? Same question for downloads.gratipay.com. It seems to be on Heroku but I can't find any other information about it.

@ghost
Copy link

ghost commented Aug 21, 2016

(and for the record, I just moved to Paris for some years, if somebody is around and wants to grab a coffee!)

@chadwhitacre
Copy link
Contributor Author

I just moved to Paris for some years

Ah, oui ! Tres bien ! Peut-être que je vais vous trouver l'année prochaine ? ;-)

how is assets.gratipay.com working?

Hmm ... we should document this somewhere (maybe on gratipay.rtfd.io?). Both assets. and downloads. are hosted by MaxCDN. The former is a so-called "pull zone", the latter a "push zone." assets. proxies through to https://gratipay.com/assets/. Does that get you pointed in the right direction, at least?

@Changaco
Copy link
Contributor

@whit537 Do you mean you may be going to OuiShare Fest again next year?

@Nashe I rarely go to Paris, but next time I do maybe we can meet. Also if you're ever in Normandy you're welcome to drop by. ;-)

@ghost
Copy link

ghost commented Aug 22, 2016

Ah, oui ! Tres bien ! Peut-être que je vais vous trouver l'année prochaine ? ;-)

I hope so! I guess that OuiShare Fest may be one very interesting place to meet—I never attended to this conference before.

@Changaco: Just drop me a line on this issue or by email and it'll be a pleasure! Lower or Upper Normandy? ;-)

@chadwhitacre
Copy link
Contributor Author

Do you mean you may be going to OuiShare Fest again next year?

Too soon to tell, but I haven't ruled it out! :-)

@Changaco
Copy link
Contributor

Lower or Upper Normandy? ;-)

Well, officially they've been reunited. ;-) Where I am specifically is (sometimes) called Suisse Normande (Norman Switzerland).

@chadwhitacre
Copy link
Contributor Author

Seems like you're pretty well onboarded by this point, eh @Nashe? We good to close here? :)

@ghost
Copy link

ghost commented Sep 14, 2016

Can I talk you in private, @whit537? Like email, webrtc… the one you prefer :-)

@chadwhitacre
Copy link
Contributor Author

@Nashe Sure thing, let's start with email ([email protected]), and we can schedule a face-to-face from there, ya?

@chadwhitacre
Copy link
Contributor Author

For the record, @Nashe has had to back away from Gratipay work for the time being, due to other commitments. I am closing this ticket, therefore ... perhaps we'll be able to reopen it someday. 😁

Thanks for all your efforts, @Nashe! Best wishes! :-)

!m @Nashe 💃

@chadwhitacre
Copy link
Contributor Author

P.S. @Nashe has removed himself from the Gratipay orgs on HackerOne and GitHub, and I've removed him from the Gratipay team on Gratipay.

@chadwhitacre
Copy link
Contributor Author

Now removed from Transifex as well (#189 (comment)).

@ghost
Copy link

ghost commented Oct 8, 2017

For the record, @Nashe has had to back away from Gratipay work for the time being, due to other commitments. I am closing this ticket, therefore ... perhaps we'll be able to reopen it someday. 😁

Aloha @whit537! How about opening this issue again? 💃

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

3 participants