Hi Drupal security people,
for over a year community member wildkatana has been working on Project browser - a module which will let users search for and install modules and themes from within their Drupal website. The goal is to have this functionality in Drupal 8 core and as a contributed module for Drupal 7. For this functionality to work another module - Project browser server - needs to be deployed on Drupal.org. The main blocker for this deployment now is missing security review.
Here is an issue: http://drupal.org/node/1243332
If someone could do a security review that would be greatly appreciated.
Related core issue: http://drupal.org/node/1841788
Related image
Thanks!