Re: svn commit: r1798086 - /ofbiz/ofbiz-framework/trunk/framework/entity/src/main/java/org/apache/ofbiz/entity/finder/ListFinder.java

2022-12-05 Thread Jacques Le Roux
le); ``` Please feel free to Thanks & Regards -- Deepak Dixit ofbiz.apache.org On Sun, Dec 4, 2022 at 10:43 PM Jacques Le Roux < jacques.le.r...@les7arts.com> wrote: Hi Deepak, You are right, I missed to conclude what I said at the end of the commit comment ("I have to chec

Re: CI github failed : Java 11 or java 17

2022-12-04 Thread Jacques Le Roux
Le 02/12/2022 à 11:23, Jacques Le Roux a écrit : Hi Eugen, Actually I can live with changing java_home by hand instead of using a batch file, not a bid deal. It was only a typo somewhere, RAM disk switching still works \o/ On this subject (RAM vs SSD) for those interested: https

Re: svn commit: r1798086 - /ofbiz/ofbiz-framework/trunk/framework/entity/src/main/java/org/apache/ofbiz/entity/finder/ListFinder.java

2022-12-04 Thread Jacques Le Roux
Hi Deepak, You are right, I missed to conclude what I said at the end of the commit comment ("I have to check the whole thing"). So did not see that the called handleOutput() closes the eli var, well spotted. Now if we look at both r1797097

Re: CI github failed : Java 11 or java 17

2022-12-03 Thread Jacques Le Roux
#wrapper_checksum_verification I'm ready to push when the *nix version will be ready. Jacques Le 02/12/2022 à 11:23, Jacques Le Roux a écrit : Hi Eugen, Actually I can live with changing java_home by hand instead of using a batch file, not a bid deal. I only have now to test these small changes

Re: Jira non-asf account disabled

2022-12-02 Thread Jacques Le Roux
+1 Le 02/12/2022 à 16:31, Nicolas Malin a écrit : In your opinion, I forward this on user list ?

Re: CI github failed : Java 11 or java 17

2022-12-02 Thread Jacques Le Roux
to run OFBiz. Regards, Eugen On 30.11.2022 19:39, Jacques Le Roux wrote: I found the cause. For performance reason, and especially in order to be able to quickly switch from a JDK version to another, I use a batch file to copy over JDKs to a RAM Disk. So java_home is always the same: this RAM Dis

Re: CI github failed : Java 11 or java 17

2022-11-30 Thread Jacques Le Roux
what I have read I guess since one version of JDK 16). When setting java_home to the initial location of JDK 17, instead of the RAM Disk, it works. I get only 2 warnings when compiling. I'll have another look ASAP... Le 30/11/2022 à 16:41, Jacques Le Roux a écrit : After upgrading non-functional

Re: CI github failed : Java 11 or java 17

2022-11-30 Thread Jacques Le Roux
;java.nio.file.Path.getFileName()" is null I'll continue to dig starting from https://github.com/gradle/gradle/issues/20837 (notably last comment). It seems a not so obvious issue. I don't think it's related to my Windows version, but not sure... Le 30/11/2022 à 13:24, Jacques Le Roux a écrit

Re: CI github failed : Java 11 or java 17

2022-11-30 Thread Jacques Le Roux
Hi Eugen, As you know I'm still on Win7 and was able to manage all related issues so far (like the need to use npm 13.14.0 locally in build.gradle) To simplify things I just committed the non functional Java changes unrelated to Gradle and JDK upgrades, not the same than your for CsrfUtil

Re: JWT token authentication error

2022-11-29 Thread Jacques Le Roux
Hi Ayan, Your message has been (somehow) moderated, else it would not have reached this Mailing List. Please subscribe to the user ML for such questions and then use your email client. See why here http://ofbiz.apache.org/mailing-lists.html. You will get a better support, people can answer you

Re: CI github failed : Java 11 or java 17

2022-11-28 Thread Jacques Le Roux
Hi, After answering << I never tried JDK 17 yet, but that should easy to upgrade when ready.>> to Michael at https://lists.apache.org/thread/8cpz4dh7zoznp4mx2xxv35hns4j8mvf0 I thought it would be time to go for it. So far, I was wrong. I just tried to use the last JDK 17 (Adoptium)

Re: Tag for 18.12.06 missing? Which commit is latest stable?

2022-11-13 Thread Jacques Le Roux
Hi Joël, As announced at https://lists.apache.org/thread/plrltvptwgvrmpfjfmlchdgl38vkofv1 the current stable branch (18.12) is no longer supported. But some people, like me, continue to backport bugfixes (maybe security ones) to the branch. So the best you can do is not for looking for a

Re: [FYI] meta-data in .asf.yaml

2022-11-11 Thread Jacques Le Roux
Le 11/11/2022 à 10:58, Jacques Le Roux a écrit : I'm not sure what the 1st line means, "not updating" what ? Found nothing googling... Could be related to https://support.atlassian.com/jira-cloud-administration/docs/configure-notification-schemes/ Default is OK :)

[FYI] meta-data in .asf.yaml

2022-11-11 Thread Jacques Le Roux
Hi, With my last push for OFBIZ-12681 I got those 2 lines remote: Saw GitHub meta-data in .asf.yaml, but not master/main or default branch, not updating... remote: [NOTICE] Notification scheme settings can only be applied to the main/master/trunk or default branch. I'm not sure what the 1st

Re: OFBiz Slack Request

2022-10-21 Thread Jacques Le Roux
Hi Max, Your message has been moderated, else it would not have reached this Mailing List. Please subscribe to the user ML for such questions and then use your email client. See why here http://ofbiz.apache.org/mailing-lists.html. You will get a better support, people can answer you on the

Re: Using htmx to make OFbiz more dynamic - FYI

2022-10-20 Thread Jacques Le Roux
Hi Eugen, This seems to confirm what you said: https://htmx.org/essays/a-real-world-react-to-htmx-port/ Thanks Jacques Le 08/08/2022 à 22:30, Eugen Stan a écrit : Hello, I recently came across htmx (and _hyperscript). I am currently evaluating it - no real experience yet. What I tested so

Re: Welcome to Leila Mekika as new committer

2022-10-17 Thread Jacques Le Roux
, Jacques Le Roux a écrit : Nice to have you on board Leila, welcome! Jacques Le 03/10/2022 à 15:04, Ashish Vijaywargiya a écrit : Many congratulations Leila and welcome aboard!!  -- Kind Regards, Ashish Vijaywargiya Vice President of Operations *HotWax Systems* *Enterprise open source experts

Re: Welcome to Leila Mekika as new committer

2022-10-03 Thread Jacques Le Roux
Nice to have you on board Leila, welcome! Jacques Le 03/10/2022 à 15:04, Ashish Vijaywargiya a écrit : Many congratulations Leila and welcome aboard!!  -- Kind Regards, Ashish Vijaywargiya Vice President of Operations *HotWax Systems* *Enterprise open source experts*

Re: OFBIZ-12694: accelerating partymgr findparty

2022-10-01 Thread Jacques Le Roux
Hi, I finally decided to not change things Le 21/09/2022 à 16:10, Jacques Le Roux a écrit : Hi, Please read my last comment, what is your opinion about that? W/o answers I'll do and close in a week TIA Jacques

OFBIZ-12694: accelerating partymgr findparty

2022-09-21 Thread Jacques Le Roux
Hi, Please read my last comment, what is your opinion about that? W/o answers I'll do and close in a week TIA Jacques

Re: Tenant and properties

2022-09-18 Thread Jacques Le Roux
ing mechanism by commenting out the reference in ofbiz-component.xml. Best regards, Michael Brohl ecomify GmbH - www.ecomify.de Am 30.08.22 um 11:28 schrieb Jacques Le Roux: Le 30/08/2022 à 10:20, Jacques Le Roux a écrit : Hi, It's a long time now I, from time to time, have a look at this issue. A

Re: [jira] [Updated] (OFBIZ-11244) Remove the user login security question

2022-09-14 Thread Jacques Le Roux
Hi, FYI: Following below Infra advice on Slack I had to change the https://www.schneier.com/essays/... URL: Humbedooh17:53 <https://the-asf.slack.com/archives/CBX4TSBQ8/p1663170822890599> << @Jacques Le Roux  you triggered the aardvark spam filter with the URL in your ticket. I

Re: MySql8 issue with add missing on start

2022-09-14 Thread Jacques Le Roux
Hi Deepak, I tried with Postgres, works like a charm with the old 9.1 version Jacques Le 14/09/2022 à 07:37, Deepak Dixit a écrit : Please let me know if it looks good, I'll merge this. This may cause issues with some of the databases. I verified it's working fine with mysql and derby.

Re: Tenant and properties

2022-09-12 Thread Jacques Le Roux
Hi Michael, Did you get a chance? Thanks Jacques Le 03/09/2022 à 20:21, Michael Brohl a écrit : Hi Jacques, I will dig into this further in the next days. Thanks, Michael Am 30.08.22 um 11:28 schrieb Jacques Le Roux: Le 30/08/2022 à 10:20, Jacques Le Roux a écrit : Hi, It's a long

Apache OFBiz - Unauth Path Traversal with file corruption (CVE-2022-25371)

2022-09-08 Thread Jacques Le Roux
Severity: High Vendor: The Apache Software Foundation Versions Affected: OFBiz versions prior to 18.12.06 Description: The Birt viewer version 4.5.0 has a security issue that allows this exploit. We waited long for https://github.com/eclipse/birt/issues/625 to resolve but eventually decided to

Re: Apache OFBiz - Unauth Path Traversal with file corruption (CVE-2022-25371)

2022-09-03 Thread Jacques Le Roux
disabled. My apologies Jacques Le 02/09/2022 à 08:34, Jacques Le Roux a écrit : Severity: High Vendor: The Apache Software Foundation Versions Affected: OFBiz versions prior to 18.12.06 Description: The Birt viewer version 4.5.0 has a security issue that allows this exploit. We waited long

Apache OFBiz - Unauth Stored XSS (CVE-2022-25370)

2022-09-02 Thread Jacques Le Roux
Severity: High Vendor: The Apache Software Foundation Versions Affected: OFBiz versions prior to 18.12.06 Description: The Birt viewer version 4.5.0 has a security issue that allows this exploit. We waited long for https://github.com/eclipse/birt/issues/625 to resolve but eventually decided to

Apache OFBiz - Unauth Path Traversal with file corruption (CVE-2022-25371)

2022-09-02 Thread Jacques Le Roux
Severity: High Vendor: The Apache Software Foundation Versions Affected: OFBiz versions prior to 18.12.06 Description: The Birt viewer version 4.5.0 has a security issue that allows this exploit. We waited long for https://github.com/eclipse/birt/issues/625 to resolve but eventually decided to

Apache OFBiz - Unauth Path Traversal with file corruption (CVE-2022-25371)

2022-09-02 Thread Jacques Le Roux
Severity: High Vendor: The Apache Software Foundation Versions Affected: OFBiz versions prior to 18.12.06 Description: The Birt viewer version 4.5.0 has a security issue that allows this exploit. We waited long for https://github.com/eclipse/birt/issues/625 to resolve but eventually decided to

Apache OFBiz - Java Deserialization via RMI Connection (CVE-2022-29063)

2022-09-02 Thread Jacques Le Roux
Severity: Low (only on shared servers) Vendor: The Apache Software Foundation Versions Affected: OFBiz versions prior to 18.12.06 Description: The OFBiz Solr plugin is configured by default to automatically make a RMI request on localhost, port 1099. By hosting a malicious RMI server on

Apache OFBiz - Regular Expression Denial of Service (ReDoS) [CVE-2022-29158]

2022-09-02 Thread Jacques Le Roux
Severity: High Vendor: The Apache Software Foundation Versions Affected: OFBiz versions prior to 18.12.06 Description: Apache OFBiz up to version 18.12.05 is vulnerable to Regular Expression Denial of Service (ReDoS) in the way it handles URLs provided by external, unauthenticated users.

Subject: Apache OFBiz - Server-Side Template Injection (CVE-2022-25813)

2022-09-02 Thread Jacques Le Roux
Severity: High (SSTI then possible RCE) Vendor: The Apache Software Foundation Versions Affected: OFBiz versions prior to 18.12.06 Description: As an ecommerce anonymous client, an external attacker can insert a malicious content in a message “Subject” field from the "Contact us" page. Then a

[ANNOUNCE] Apache OFBiz 18.12 End-Of-Life (EOL) announcement

2022-09-01 Thread Jacques Le Roux
The Apache OFBiz Project Team would like to inform you that OFBiz 18.12.06 is the last release of the 18.12 branch, which has reached its end of life and won't be longer officially supported. https://ofbiz.apache.org/release-notes-18.12.06.html This announcement takes place on 2022-09-02 and

Re: Tenant and properties

2022-08-30 Thread Jacques Le Roux
Le 30/08/2022 à 10:20, Jacques Le Roux a écrit : Hi, It's a long time now I, from time to time, have a look at this issue. At some point I had at least 13 related links, remain open only: https://issues.apache.org/jira/browse/OFBIZ-7112 "EntityUtilProperties" https://issues.apach

Tenant and properties

2022-08-30 Thread Jacques Le Roux
Hi, It's a long time now I, from time to time, have a look at this issue. At some point I had at least 13 related links, remain open only: https://issues.apache.org/jira/browse/OFBIZ-7112 "EntityUtilProperties" https://issues.apache.org/jira/browse/OFBIZ-6712 "Increase the number of

Re: [VOTE] Apache OFBiz 18.12.06

2022-08-25 Thread Jacques Le Roux
Hi Jacopo, +1 Checksum and GPG OK, running OFBiz too. Thanks Jacques Le 25/08/2022 à 10:10, Jacopo Cappellato a écrit : This is the vote thread to publish "Apache OFBiz 18.12.06", the sixth and final release from the release18.12 branch. The release files can be downloaded from here:

Re: Lots of errors in Eclipse - cleanup?

2022-08-21 Thread Jacques Le Roux
Hi Steve, Of course, you are welcome to change the package names of the .groovy files. Actually you may fix all issues Eclipse reports. TIA Jacques Le 21/08/2022 à 00:10, Stephen Davidson a écrit : Greetings. I'm new to OFBiz, so if I am missing something or making a newbie mistake,

Re: Codenarc integration, rules to use.

2022-07-25 Thread Jacques Le Roux
Hi Gil, Here are my preferences inline... Le 20/07/2022 à 23:49, Gil Portenseigne a écrit : Thanks All for the feedback. I continue in my spare time and did analyse some rule that I propose to disable. Here are my thought : * DuplicateStringLiteral : Not Adapted to OFBiz : String

Re: CI github failed : Java 11 or java 17

2022-07-15 Thread Jacques Le Roux
Hi Nicolas, I did not try, how things works with Java 17? Jacques Le 15/07/2022 à 10:14, Nicolas Malin a écrit : Hello, I saw that break the CI github because I commited a List.of on release22.01 [1] not supported by java 8 After a quick check, the CI work on java 8 and the documentation

Re: Migration from ci.a.o

2022-07-10 Thread Jacques Le Roux
Le 11/01/2022 à 17:54, Jacques Le Roux a écrit : Also are missing, faculty to start a build from IRC and, more technical, the possibility to use several servers to launch builds. We had all that before... Hi, At least I have asked for faculty to start a build from IRC at https

Re: Codenarc integration, rules to use.

2022-07-08 Thread Jacques Le Roux
Hi Gil, Great initiative, so far it seems we have a lazy consensus We (almost*) did it for Java, why not for Groovy :) Jacques * OFBIZ-12341 Le 04/07/2022 à 17:24, Gil Portenseigne a écrit : Hello Devs, I would like to continue Codenarc integration in OFBiz (OFBIZ-11167). For those who

https://ofbiz.apache.org/release-notes-17.12.02.html missing

2022-07-08 Thread Jacques Le Roux
Hi, We have a 404 at https://ofbiz.apache.org/release-notes-17.12.02.html TIA

Re: [GitHub] [ofbiz-framework] JacquesLeRoux merged pull request #518: Bump uglify-js from 3.16.1 to 3.16.2 in /themes/common-theme/webapp/common-theme/js

2022-07-04 Thread Jacques Le Roux
Actually this one is useless, we use latest in package.json. Dependabot does not seem smart enough :) Le 04/07/2022 à 18:09, GitBox a écrit : JacquesLeRoux merged PR #518: URL: https://github.com/apache/ofbiz-framework/pull/518

Re: Use specific message from the business context

2022-06-16 Thread Jacques Le Roux
the logic to be sure that we going to on the good way :) If you confirm that this idea isn't wrong (break pattern or something like that) I will open the issue to load the code Cheers, Nicolas On 14/06/2022 17:21, Jacques Le Roux wrote: Hi Pierre, Nicolas, I like the idea of the right and wrong

Re: Use specific message from the business context

2022-06-14 Thread Jacques Le Roux
Hi Pierre, Nicolas, I like the idea of the right and wrong messages from form. Could we not have both (request-map and form) to use them accordingly to our (custom for instance) needs? Jacques Le 14/06/2022 à 09:12, Pierre Gaudin a écrit : Hi Nicolas, The solution by putting the message

Re: JS library dynamic import

2022-05-26 Thread Jacques Le Roux
Hi Florian, It all started with OFBIZ-1319. Then somehow related we had OFBIZ-9465 and at some point we envisioned to use Require.js: OFBIZ-9976 Finally in trunk we use npm: OFBIZ-11960 (more with

Re: Migration from ci.a.o

2022-05-25 Thread Jacques Le Roux
Le 14/01/2022 à 18:19, Jacques Le Roux a écrit : We are still waiting for Infra for several missing features, the most important being missing status emails: INFRA-22689 Also are missing, faculty to start a build from IRC and, more technical, the possibility to use several servers to launch

Re: CSP HTTP header causes console errors

2022-05-07 Thread Jacques Le Roux
BTW I created this Jira CSP related filter: https://issues.apache.org/jira/browse/OFBIZ-11889?filter=12351704 Le 07/05/2022 à 10:21, Jacques Le Roux a écrit : Hi Florian, Yes, users could use their own CSP by changing the CSP-Report-Only default from a property in security.properties

Re: CSP HTTP header causes console errors

2022-05-07 Thread Jacques Le Roux
:)) ? So if a theme maintainer wants to include a library/font/... from an external server, he could modify the CSP and avoid piling up warnings. But overriding only one value in a property file is not possible (I think). Le 06/05/2022 à 15:56, Jacques Le Roux a écrit : Hi Florian, Welcome

Re: CSP HTTP header causes console errors

2022-05-06 Thread Jacques Le Roux
Hi Florian, Welcome, glad to have a new front end developer with us. I indeed started to work on that in 2018, and just did the minimum: https://issues.apache.org/jira/browse/OFBIZ-10417 Later Alex Bodnaru (no longer working with us) created https://issues.apache.org/jira/browse/OFBIZ-11889

Re: Ofbiz Developer Subscription

2022-05-03 Thread Jacques Le Roux
Hi Lawrence, Please help yourself: https://ofbiz.apache.org/mailing-lists.html TIA Jacques Le 03/05/2022 à 13:16, sevenwells ioautomata a écrit : Hi Ofbiz admin, Kindly add me to Ofbiz developer subscription. Thank you Lawrence Ndungu Sevenwells eBusiness Consultant

[OFBIZ-10552] Remove AP AR webapps from accounting component - ASF JIRA

2022-04-24 Thread Jacques Le Roux
Hi, Do we really want to do that? https://issues.apache.org/jira/browse/OFBIZ-10552 Jacques

Re: Fwd: [NOTICE] Dependabot Updates enabled for all projects

2022-04-24 Thread Jacques Le Roux
's see how it goes Jacques Le 23/04/2022 à 19:10, Jacques Le Roux a écrit : Hi, As we don't have a direct access to settings in GH, I have rather created INFRA-23193 for that Jacques Le 07/04/2022 à 08:13, Jacques Le Roux a écrit : Hi, I was wondering how Dependabot works with Gradle, here is

Re: Fwd: [NOTICE] Dependabot Updates enabled for all projects

2022-04-23 Thread Jacques Le Roux
Hi, As we don't have a direct access to settings in GH, I have rather created INFRA-23193 for that Jacques Le 07/04/2022 à 08:13, Jacques Le Roux a écrit : Hi, I was wondering how Dependabot works with Gradle, here is the answer https://dev.to/cricketsamya/gradle-with-dependabot-1o47 So

Re: [GitHub] [ofbiz-framework]: Workflow run "Java CI with Gradle" failed!

2022-04-18 Thread Jacques Le Roux
y GitHub user asfgit (triggered by asfgit). Head commit for run: fa9a94ecf8f0a4a7ea16a1a37a4d9b5f4f1b7140 / Jacques Le Roux Improved: GH Actions and Buildbot Builders are not consistent (INFRA-23076) It's now 2 weeks that INFRA-23076 is open, so like 3 weeks that BuildBot is not working for OFBiz a

Re: Automating to get latest versions of js scripts with npm?

2022-04-09 Thread Jacques Le Roux
I have created OFBIZ-12596 for that Le 09/04/2022 à 09:03, Jacques Le Roux a écrit : Hi Michael, Fair enough, but we still need to keep those files up to date. For Gradle dependencies we (I at least) use    <> (see OFBIZ-10213) The same can be done using "npx npm-check-updates&

Re: Automating to get latest versions of js scripts with npm?

2022-04-09 Thread Jacques Le Roux
in build.gradle. Updating the JS libraries should be done explicitly together with necessary tests. Best regards, Michael Brohl ecomify GmbH - www.ecomify.de Am 08.04.22 um 16:49 schrieb Jacques Le Roux: Hi, Currently we load specific versions of js scripts (dependencies) with npm (see pa

Automating to get latest versions of js scripts with npm?

2022-04-08 Thread Jacques Le Roux
Hi, Currently we load specific versions of js scripts (dependencies) with npm (see package.json) npm has a "latest" option that allows to automatically load the latest versions of a js script. We had only 3 js scripts versions that are not the latest. I changed all to load latest versions.

Re: Fwd: [NOTICE] Dependabot Updates enabled for all projects

2022-04-07 Thread Jacques Le Roux
Hi, I was wondering how Dependabot works with Gradle, here is the answer https://dev.to/cricketsamya/gradle-with-dependabot-1o47 So I'll try it tomorrow Jacques Le 05/04/2022 à 14:11, Jacques Le Roux a écrit : At least we can try and see how easy it is to apply those Dependabot PRs

Re: Fwd: [NOTICE] Dependabot Updates enabled for all projects

2022-04-05 Thread Jacques Le Roux
At least we can try and see how easy it is to apply those Dependabot PRs, or be inspired by them. I trust we should be faster than any pen tester to fix issues (if possible, dependencies can be complicated). Le 05/04/2022 à 14:06, Jacques Le Roux a écrit : On the other hand we can simply

Re: Fwd: [NOTICE] Dependabot Updates enabled for all projects

2022-04-05 Thread Jacques Le Roux
On the other hand we can simply neglect Dependabot and update when we see/"feel" it's needed. But that's not a much secure way. Having Dependabot running for us would have prevented 2 current CVEs pending... Jacques Le 05/04/2022 à 14:02, Jacques Le Roux a écrit : Hi Micha

Fwd: [NOTICE] Dependabot Updates enabled for all projects

2022-04-05 Thread Jacques Le Roux
@a.o as far as I understand. You can read more here: https://docs.github.com/en/code-security/dependabot/dependabot-security-updates/about-dependabot-security-updates J. On Tue, Apr 5, 2022 at 1:25 PM Jacques Le Roux wrote: Hi Jarek, OK, but what about the others, those not public? I guess we can

Re: [NOTICE] Dependabot Updates enabled for all projects

2022-04-05 Thread Jacques Le Roux
Hi Team, If nobody see a problem with that I'll create a Jira for that in 3 days, ie Friday morning Thanks Jacques Le 05/04/2022 à 06:30, Chris Lambertus a écrit : Hi folks, Infra is pleased to announce that GitHub’s Dependabot service has been approved for use by ASF Legal and Infra, and

Re: OFBiz re-architecture thoughts

2022-04-03 Thread Jacques Le Roux
Hi Nicola, I think  Moqui is near from that. Though not totally started from OFBiz it's quite inspired from David's long experience with OFBiz Jacques Le 02/04/2022 à 19:29, Nicola Mazzoni a écrit : I think it would be very interesting if some community developer were interested in creating

Re: "New commiter first steps" wiki page proposal

2022-04-02 Thread Jacques Le Roux
That's indeed a good idea. There is already https://infra.apache.org/new-committers-guide.html#set-up-subversion-or-git-access, but I guess something simplified and focused for OFBiz new committers in wiki may be useful indeed. Giulio, this morning you also asked about

Re: [GitHub] [ofbiz-framework]: Workflow run "Java CI with Gradle" is working again!

2022-04-02 Thread Jacques Le Roux
it for run: 1be718e818e03e595ea5e4ff6559b819ab9b7868 / Jacques Le Roux Forgot a space before if Report URL: https://github.com/apache/ofbiz-framework/actions/runs/2081652160 With regards, GitHub Actions via GitBox

Re: [INFRA-22722] Restart the ofbiz-vm3 demos server

2022-03-28 Thread Jacques Le Roux
Hi, Infra ran the cron as root. It should be ofbizDemo user. I told them, I hope all will be OK then Thanks for your patience :) Le 28/03/2022 à 18:52, Jacques Le Roux a écrit : Hi, The demos are back, next will only work tomorrow morning around 3 UTC Enjoy Jacques Le 18/03/2022 à 11:46

Re: [INFRA-22722] Restart the ofbiz-vm3 demos server

2022-03-28 Thread Jacques Le Roux
Hi, The demos are back, next will only work tomorrow morning around 3 UTC Enjoy Jacques Le 18/03/2022 à 11:46, Jacques Le Roux a écrit : Hi, Good news, demos will soon be back :). Greg asked me to provide specs for a new OFBIZ-VM, I guess OFBIZ-VM4. If nobody is against Monday I'll ask

Re: [INFRA-22722] Restart the ofbiz-vm3 demos server

2022-03-28 Thread Jacques Le Roux
and will have longer support. Thoughts? Michael Am 23.03.2022 um 17:58 schrieb Jacques Le Roux : BTW, Is there someone who is already using Java 11 with 18.12? TIA Jacques Le 23/03/2022 à 16:24, Jacques Le Roux a écrit : Hi Michael, I don't remember clearly why I had that in mind. I have

Re: [INFRA-22722] Restart the ofbiz-vm3 demos server

2022-03-24 Thread Jacques Le Roux
ally (Win7) with "openjdk 11.0.2 2019-01-15"  for trunk. Nobody ever crossed that? TIA Jacques Le 18/03/2022 à 11:46, Jacques Le Roux a écrit : Hi, Good news, demos will soon be back :). Greg asked me to provide specs for a new OFBIZ-VM, I guess OFBIZ-VM4. If nobody is against Monday I'll a

Re: [INFRA-22722] Restart the ofbiz-vm3 demos server

2022-03-23 Thread Jacques Le Roux
Ah forgot, did you fix the warnings? Le 23/03/2022 à 19:09, Jacques Le Roux a écrit : Great, thanks Gil! Le 23/03/2022 à 18:15, Gil Portenseigne a écrit : Hello Jacques, We have some production server based on 18.12, with java 11. It is working fine. Gil On Wed, Mar 23, 2022 at 05:58:25PM

Re: [INFRA-22722] Restart the ofbiz-vm3 demos server

2022-03-23 Thread Jacques Le Roux
Great, thanks Gil! Le 23/03/2022 à 18:15, Gil Portenseigne a écrit : Hello Jacques, We have some production server based on 18.12, with java 11. It is working fine. Gil On Wed, Mar 23, 2022 at 05:58:25PM +0100, Jacques Le Roux wrote: BTW, Is there someone who is already using Java 11

Re: [INFRA-22722] Restart the ofbiz-vm3 demos server

2022-03-23 Thread Jacques Le Roux
BTW, Is there someone who is already using Java 11 with 18.12? TIA Jacques Le 23/03/2022 à 16:24, Jacques Le Roux a écrit : Hi Michael, I don't remember clearly why I had that in mind. I have just tried to run current 18.12 with Java 11 and so far it seems OK. I'll check that better

Re: [INFRA-22722] Restart the ofbiz-vm3 demos server

2022-03-23 Thread Jacques Le Roux
. Jacques Le 18/03/2022 à 12:55, Jacques Le Roux a écrit : Hi Michael, I suggest to tackle that, including the necessary on the VM, when we will effectively switch 22.01 to JDK 11 Jacques Le 18/03/2022 à 12:03, Michael Brohl a écrit : Hi Jacques, should we not also have a VM supporting Java 11

Re: Welcome to Nicola Mazzoni and Giulio Speri as new committers

2022-03-22 Thread Jacques Le Roux
Welcome Nicola and Giulio :) Jacques Le 22/03/2022 à 09:30, Gil Portenseigne a écrit : Congratulations, Welcome ! Gil On Mon, Mar 21, 2022 at 09:26:16PM +0100, Jacopo Cappellato wrote: The OFBiz PMC has invited Nicola Mazzoni and Giulio Speri as new committers and we are glad to announce

Re: [ofbiz-framework] branch trunk updated: Fixed: Date picker not initialised in ajax-called form (OFBIZ-)

2022-03-20 Thread Jacques Le Roux
Hi, This needs more information, not a big deal anyway. 1. I forgot the Jira issue number, it's for OFBIZ-12097 "Date picker not initialised in ajax-called form ". I fixed that. 2. The macro in Html*MacroLibrary.ftl files should all have the same signatures, right? I had a doubt because for

Re: [INFRA-22722] Restart the ofbiz-vm3 demos server

2022-03-18 Thread Jacques Le Roux
of the specifications Thanks, Michael Brohl ecomify GmbH - www.ecomify.de Am 18.03.22 um 11:46 schrieb Jacques Le Roux: Hi, Good news, demos will soon be back :). Greg asked me to provide specs for a new OFBIZ-VM, I guess OFBIZ-VM4. If nobody is against Monday I'll ask for the same than OFBIZ-VM3

[INFRA-22722] Restart the ofbiz-vm3 demos server

2022-03-18 Thread Jacques Le Roux
Hi, Good news, demos will soon be back :). Greg asked me to provide specs for a new OFBIZ-VM, I guess OFBIZ-VM4. If nobody is against Monday I'll ask for the same than OFBIZ-VM3 (JDK 8, 8GB RAM, letsencrypt). I guess it will be Ubuntu again. JDK8 because it will still need to support 18.12

Re: [ofbiz-framework] branch trunk updated: Improved: Create a deny list to reject webshell tokens (OFBIZ-12324)

2022-02-14 Thread Jacques Le Roux
4fa50c87b708d0445b86af6d2062d336e543c971 Author: Jacques Le Roux AuthorDate: Tue Feb 15 07:54:17 2022 +0100 Improved: Create a deny list to reject webshell tokens (OFBIZ-12324) After reviewing https://github.com/nsacyber/Mitigating-Web-Shells this mostly adds as tokens the "Linux applications commonly

Re: [ofbiz-framework] branch release18.12 updated: Fixed: CLONE - [SECURITY] Upgrade Tika to 1.28.1 (OFBIZ-12573)

2022-02-12 Thread Jacques Le Roux
Le 12/02/2022 à 11:48, jler...@apache.org a écrit : Fixed: CLONE - [SECURITY] Upgrade Tika to 1.28.1 (OFBIZ-12573) Simpler for now, later OFBIZ 12573 needs to be done Here I meant OFBIZ 12572 (ie upgrade Tika to 2.3.0 Jacques

Re: [jira] [Commented] (OFBIZ-11948) Remote Code Execution (File Upload) Vulnerability

2022-02-04 Thread Jacques Le Roux
, you stated: * Adds "https://ofbiz.apache.org/> since 2008 (without privileges) Proud contributor to the ASF since 2006 *Apache Directory <https://directory.apache.org>, PMC Member* Anyone could have been you, whereas I've always been anyone. On Fri, Feb 4, 2022 at 2:06 PM Jacques

Re: [jira] [Commented] (OFBIZ-11948) Remote Code Execution (File Upload) Vulnerability

2022-02-04 Thread Jacques Le Roux
d have been you, whereas I've always been anyone. On Fri, Feb 4, 2022 at 2:06 PM Jacques Le Roux wrote: Hi Pierre, How is your question related? Le 04/02/2022 à 12:53, Pierre Smits a écrit : Hi Jacques, Wasn't there PHP code in the scrum application/ component to work with a git repository? O

Fwd: [GitHub] [ofbiz-framework] mbrohl commented on pull request #498: Improved: WorkEffort - MainActionMenu (OFBIZ-12557)

2022-02-04 Thread Jacques Le Roux
Message transféré Sujet : Re: [GitHub] [ofbiz-framework] mbrohl commented on pull request #498: Improved: WorkEffort - MainActionMenu (OFBIZ-12557) Date : Fri, 4 Feb 2022 11:01:16 +0100 De :Jacques Le Roux Répondre à :memb...@apache.org Pour : memb...@apache.org Hi Pierre

Re: [jira] [Commented] (OFBIZ-11948) Remote Code Execution (File Upload) Vulnerability

2022-02-04 Thread Jacques Le Roux
Commit b0b02034eecf8d18ac7ea12f34469ec511269fa0 in ofbiz-framework's branch refs/heads/trunk from Jacques Le Roux [ https://gitbox.apache.org/repos/asf?p=ofbiz-framework.git;h=b0b0203 ] Fixed: Remote Code Execution (File Upload) Vulnerability (OFBIZ-11948) Lion Tree has reported us that "CV

Re: [ofbiz-framework] branch trunk updated: Improved: no functional change, labels improvements

2022-02-03 Thread Jacques Le Roux
ibed below commit 8a9596be849f6709cb17c24a598c4862e8df867c Author: Jacques Le Roux AuthorDate: Sun Jan 16 08:51:03 2022 +0100 Improved: no functional change, labels improvements In French, and maybe other languages, there is not only one word for new. There are nouveau (masculine), nouvelle (fé

Re: [ofbiz-framework] branch trunk updated: Improved: no functional change, adds a BuildBot badge (INFRA-22807)

2022-02-03 Thread Jacques Le Roux
es Jacques, I revert my local fix commit, you gone faster than me. What can I do for help, to escape any collision  with you ? Nicolas On 03/02/2022 10:02, Jacques Le Roux wrote: Le 03/02/2022 à 09:54,jler...@apache.org a écrit :     Improved: no functional change, adds a BuildBot badge (I

Re: [ofbiz-framework] branch trunk updated: Improved: no functional change, adds a BuildBot badge (INFRA-22807)

2022-02-03 Thread Jacques Le Roux
Le 03/02/2022 à 09:54, jler...@apache.org a écrit : Improved: no functional change, adds a BuildBot badge (INFRA-22807) It works locally (once you have installed Ruby, asciidoctor and asciidoctor-diagram). CHecking that it's also OK on BuildBot, let's see result

Re: [ofbiz-framework] branch trunk updated: Improved: no functional change, labels improvements

2022-02-03 Thread Jacques Le Roux
[1]. Michael [1] https://lists.apache.org/thread/93ptk5nfrf2pjfwnl6ovm0lc6l42yb85 Am 03.02.22 um 08:18 schrieb Pierre Smits: Good to see that the two of you confirm that cleanup can be combined with other improvements . Op do 3 feb. 2022 07:15 schreef Jacques Le Roux < jacques.l

Re: [ofbiz-framework] branch trunk updated: Improved: no functional change, labels improvements

2022-02-02 Thread Jacques Le Roux
f867c Author: Jacques Le Roux AuthorDate: Sun Jan 16 08:51:03 2022 +0100 Improved: no functional change, labels improvements In French, and maybe other languages, there is not only one word for new. There are nouveau (masculine), nouvelle (féminine) and nouvel (masculine followed   

Re: [GitHub] [ofbiz-framework] JacquesLeRoux edited a comment on pull request #466: Improved: List and Grid (OFBIZ-11345)

2022-01-29 Thread Jacques Le Roux
Le 27/01/2022 à 15:57, Pierre Smits a écrit : Playing the 'blame' game is detrimental to the success of the project, and thus to all using, contributing, making a living with... Hi Pierre, It seems you don't understand why I put "is broken by" references from and in Jiras and GH. It's not at

Re: [ofbiz-framework] branch trunk updated: Fixed: Upgrade Tomcat from 9.0.54 to 9.0.58 (OFBIZ-12539)

2022-01-26 Thread Jacques Le Roux
Tomcat from 9.0.54 to 9.0.58 (OFBIZ-12539) 6ed30b7 is described below commit 6ed30b76652e24162bcbc6efe4ca912ba0e31bc2 Author: Jacques Le Roux AuthorDate: Wed Jan 26 12:31:50 2022 +0100 Fixed: Upgrade Tomcat from 9.0.54 to 9.0.58 (OFBIZ-12539) The fix for bug CVE-2020-9484 introduced a t

Re: Fwd: [jira] [Commented] (OFBIZ-12534) Comments on Commits in Github must go to a mailing list of the project

2022-01-25 Thread Jacques Le Roux
à 16:48, Jacques Le Roux a écrit : OK then, I don't need PMC approval to report a bug to Infra. Not sure though that Infra will consider it a bug, let's see Jacques Le 25/01/2022 à 14:53, Pierre Smits a écrit : Forwarded to the dev@ofbiz mailing list of OFBiz for those community members

Re: Fwd: [jira] [Commented] (OFBIZ-12534) Comments on Commits in Github must go to a mailing list of the project

2022-01-25 Thread Jacques Le Roux
e Directory <https://directory.apache.org>, PMC Member* On Tue, Jan 25, 2022 at 2:23 PM Jacques Le Roux (Jira) Comments on Commits in Github must go to a mailing list of the project -- Key: OFBIZ-12534

Re: Fwd: Returned post for annou...@apache.org

2022-01-21 Thread Jacques Le Roux
now. Jacopo On Fri, Jan 21, 2022 at 9:57 AM Jacques Le Roux < jacques.le.r...@les7arts.com> wrote: Better, I'll use https://downloads.apache.org/ofbiz/ Le 21/01/2022 à 09:52, Jacques Le Roux a écrit : Hi, As we prefer to advertise about R18 than 17.12.09, I picked

[ANNOUNCE] Apache OFBiz 17.12 End-Of-Life (EOL) announcement

2022-01-21 Thread Jacques Le Roux
The Apache OFBiz Project Team would like to inform you that OFBiz 17.12.09 is the last release of the 17.12 branch, which has reached its end of life and won't be longer officially supported. https://ofbiz.apache.org/release-notes-17.12.09.html This announcement takes place on 2022-01-21 and

Re: Fwd: Returned post for annou...@apache.org

2022-01-21 Thread Jacques Le Roux
Better, I'll use https://downloads.apache.org/ofbiz/ Le 21/01/2022 à 09:52, Jacques Le Roux a écrit : Hi, As we prefer to advertise about R18 than 17.12.09, I picked https://downloads.apache.org/ofbiz/apache-ofbiz-17.12.09.zip and will resend the announce. Mark Thomas should let it pass

Re: Fwd: Returned post for annou...@apache.org

2022-01-21 Thread Jacques Le Roux
Hi, As we prefer to advertise about R18 than 17.12.09, I picked https://downloads.apache.org/ofbiz/apache-ofbiz-17.12.09.zip and will resend the announce. Mark Thomas should let it pass. Jacques Le 20/01/2022 à 20:22, Jacques Le Roux a écrit : We could also use modified https

Re: Fwd: Returned post for annou...@apache.org

2022-01-20 Thread Jacques Le Roux
We could also use modified https://ofbiz.apache.org/release-notes-17.12.09.html (a bit more work...) Le 20/01/2022 à 20:19, Jacques Le Roux a écrit : Hi Jacopo, The announce was refused (moderated) because there is no direct link to download 17.12.09 in the announce. I found we could use

Re: Fwd: Returned post for annou...@apache.org

2022-01-20 Thread Jacques Le Roux
Hi Jacopo, The announce was refused (moderated) because there is no direct link to download 17.12.09 in the announce. I found we could use https://downloads.apache.org/ofbiz/apache-ofbiz-17.12.09.zip. Is that correct, and enough? TIA Jacques Le 20/01/2022 à 17:08, jler...@apache.org a

Re: Add CHANGELOG.md file

2022-01-17 Thread Jacques Le Roux
Done Le 14/01/2022 à 18:58, Jacques Le Roux a écrit : Hi, If nobody is against I'll remove this file Monday. Note that it will still be available in Git history/log... Jacques Le 09/01/2022 à 09:17, Jacques Le Roux a écrit : But if we don't do anything about it, why keep this misleading

<    1   2   3   4   5   6   7   8   9   10   >