Closed KristalAByrd closed 7 years ago
Someone at GSA also raised this issue internally. My response:
I see the issue. In our last scan, we had all 4 endpoints marked as "redirect" of "true", but the overall domain has "redirect" set to "false", which is undesired:
https://s3.amazonaws.com/pulse.cio.gov/archive/2016-11-11/cache/pshtt/fedrooms.gov.json
I'll look into this, thanks for the report.
We'll look into this.
I've filed https://github.com/dhs-ncats/pshtt/pull/41 with the upstream scanner to address this issue.
Note that fedrooms.gov is fixed in the current scan on Pulse, because the root issue is that gsa.gov fails to complete all of its redirects, sometimes. The redirect worked this week, so the domain was correctly marked as a "redirect domain" and removed from eligibility for DAP scans.
Whether pshtt
accepts this or not, I suggest petitioning gsa.gov to make sure its redirects work consistently, as this means that visiting fedrooms.gov
has a high chance of failing to get the user to their intended destination.
Thx Eric. I will follow up with Mark Kaprow of CIO who handles this.
Best, Kristal
On Sun, Nov 20, 2016 at 9:05 PM, Eric Mill notifications@github.com wrote:
I've filed dhs-ncats/pshtt#41 https://github.com/dhs-ncats/pshtt/pull/41 with the upstream scanner to address this issue.
Note that fedrooms.gov is fixed in the current scan on Pulse, because the root issue is that gsa.gov fails to complete all of its redirects, sometimes. The redirect worked this week, so the domain was correctly marked as a "redirect domain" and removed from eligibility for DAP scans.
Whether pshtt accepts this or not, I suggest petitioning gsa.gov to make sure its redirects work consistently, as this means that visiting fedrooms.gov has a high chance of failing to get the user to their intended destination.
— You are receiving this because you authored the thread. Reply to this email directly, view it on GitHub https://github.com/18F/pulse/issues/596#issuecomment-261825774, or mute the thread https://github.com/notifications/unsubscribe-auth/AWZR6SjFTTQt6kSolkNRL-x0aEJ69ozOks5rAPx_gaJpZM4Kyyk2 .
Kristal Byrd, UXC User Experience Certified by Nielsen Norman Group https://www.nngroup.com/ux-certification/verify/
User Experience Specialist and Digital Analyst General Service Administration v: 202-501-4409 c: 202-821-7158
Thanks, @KristalAByrd. Closing since the root cause is known, and a separate PR has been filed.
+Mark Kaprow and Garlette Jordan
Hi Eric: I've added Mark Kaprow of CIO who manages the redirect and Garlette Jordan who owns the URL who request clarification. Mark does not see any evidence that the URL is not redirecting. Do you know what happens when it doesn't redirect?
Pls elaborate.
Best, Kristal
On Mon, Nov 21, 2016 at 11:26 AM, Eric Mill notifications@github.com wrote:
Thanks, @KristalAByrd https://github.com/KristalAByrd. Closing since the root cause is known, and a separate PR has been filed.
— You are receiving this because you were mentioned. Reply to this email directly, view it on GitHub https://github.com/18F/pulse/issues/596#issuecomment-261988258, or mute the thread https://github.com/notifications/unsubscribe-auth/AWZR6a8_n904SErMGqsC6GZcQttOIVfOks5rAcZCgaJpZM4Kyyk2 .
Kristal Byrd, UXC User Experience Certified by Nielsen Norman Group https://www.nngroup.com/ux-certification/verify/
User Experience Specialist and Digital Analyst General Service Administration v: 202-501-4409 c: 202-821-7158
@KristalAByrd Please un-CC GitHub and move this into a new email thread. CC-ing them on email when replying to a GitHub comment doesn't work.
GSA has a vanity URL, fedrooms.gov which redirects to www.gsa.gov/fedrooms and is showing up on the list of DAP non-compliant domains. DAP manager, Tim Lowden, stated, "vanity URLS do not need DAP code, as long as they redirect. Redirects should not be showing up on Pulse." Pls remove fedrooms.gov from the domain list.