Skip to content
This repository has been archived by the owner on Aug 22, 2022. It is now read-only.

Improve docs about security considerations #109

Open
m4dz opened this issue Mar 16, 2015 · 1 comment
Open

Improve docs about security considerations #109

m4dz opened this issue Mar 16, 2015 · 1 comment

Comments

@m4dz
Copy link
Contributor

m4dz commented Mar 16, 2015

As reported by a user, our documentation concerning security (SSL renewal, CouchDB password) are too thin, and we may add some extra infos to drive users through this cases: http://cozy.io/fr/host/install.html#consid-rations-sur-la-s-curit-avec-les-images-pr-install-es.

@audreytoskin
Copy link
Contributor

The handwaving over security concerns in the documentation is also strange. I just read the "Play with the Data System" page (at src/documents/en/hack/getting-started/play-with-data-system.html.md).

you must be aware that we don't do security checks and data validation in the tutorial,
because it is not the point. If you want to know how to do it, please ask us on IRC or by email

It was probably a good idea to skip the security tutorial in the middle of the lesson about basic usage of the Data System. But I think security is important enough that it should be part of the official docs, not just something users have to ask about in IRC or email, where no one else can read it.

Telling users "If you're curious about security, send us an email" is silly. It should be "If you're curious about security, go this other page which talks about it in detail."

audreytoskin added a commit to audreytoskin/cozy-docs that referenced this issue Jun 25, 2015
As I mentioned in a reply to [GitHub Issue 109](cozy#109), the mention of security concerns on this page was a problem. First, I think security should be considered important enough to have its own page or section in the documentation. An invitation to chat on IRC is not good enough.

Other edits are meant improve clarity or make the prose style sound more "natural".
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

4 participants