Re: Allow modify during import operation

2010-08-03 Thread Eric Norman
Hi Mike, I would lean toward making the property overwrite a separate import option for the same reasons you outlined below. Regards, -Eric On Fri, Jul 30, 2010 at 12:00 PM, Mike Moulton m...@meltmedia.com wrote: I will work on a patch for this. Should we add

Re: Allow modify during import operation

2010-08-05 Thread Eric Norman
I will try to find some time to review the patch in the next few days. Regards, Eric On Aug 5, 2010 11:25 AM, Simon Gaeremynck gaeremyn...@gmail.com wrote: I cannot take any credit for this. It was Zach Thomas who did all the work and it would be totally awesome if it got merged in. :-)

Re: [VOTE] Grant Alison write access to the docs

2010-08-06 Thread Eric Norman
+1 Regards, Eric On Aug 5, 2010 11:21 PM, Carsten Ziegeler cziege...@apache.org wrote: Hi, I would like to call another vote for a new documentation writer: Alison :) Like Jean Christophe she is volunteering to help us and has already made suggestions for improvements and helped with the

Re: [VOTE] Grant Jean Christophe write access to the docs [was Re: Scheduler service problem]

2010-08-06 Thread Eric Norman
+1 On Thu, Aug 5, 2010 at 11:08 PM, Carsten Ziegeler cziege...@apache.orgwrote: Hi, I would like to call a vote to give Jean Christophe write access to our documentation. He is volunteering to help in an area where we definitly need help and he also did some valuable docs in the past

Re: Allow modify during import operation

2010-08-09 Thread Eric Norman
Hi all, I reviewed the patch and checked in the changes with a few minor modifications. Please verify that that the changes will work for your use cases. Regards, Eric On Aug 6, 2010 12:41 AM, Bertrand Delacretaz bdelacre...@apache.org wrote: On Thu, Aug 5, 2010 at 7:36 PM, Simon Gaeremynck

Re: [VOTE] Release Sling API 2.1.0

2010-08-19 Thread Eric Norman
+1 On Wed, Aug 18, 2010 at 9:28 AM, Felix Meschberger fmesc...@gmail.comwrote: Hi, At long last here it is: The Sling API 2.1.0 release vote. We solved 25 issues in this release: https://issues.apache.org/jira/browse/SLING/fixforversion/12314252 Staging repository:

Re: should jackrabbit-accessmanager really export org.apache.sling.jcr.jackrabbit.accessmanager.post?

2010-09-02 Thread Eric Norman
It is probably not needed. I've been using it to provide overiden versions of some of the servlets to provide additional custom validation. I could change my code to use a filter instead. Eric On Sep 1, 2010 8:24 AM, Justin Edelson justinedel...@gmail.com wrote: This just looks odd to me.

[DISCUSS] ResourceResolver with multiple resource providers bound to the same path?

2010-09-06 Thread Eric Norman
Hi All, This seems kind of similar to* SLING-1672https://issues.apache.org/jira/browse/SLING-1672 * which has been marked as resolved. However, with the latest trunk code, I am still running into some difficulties when multiple bundles are providing Sling-Bundle-Resources with the same path. I

Re: [DISCUSS] ResourceResolver with multiple resource providers bound to the same path?

2010-09-06 Thread Eric Norman
valid and really should work. If not, we would have to analyze where in the listChildren implementation the problem lies. At least we would have to have an issue to track this. Regards Felix On 06.09.2010 19:48, Eric Norman wrote: Hi All, This seems kind of similar to* SLING

Re: [DISCUSS] ResourceResolver with multiple resource providers bound to the same path?

2010-09-06 Thread Eric Norman
Hi Vidar, My proposed patch affects only the BundleResourceProvider so I don't think it would affect the scenario you have described. Regards, Eric On Mon, Sep 6, 2010 at 1:30 PM, Vidar Ramdal vi...@idium.no wrote: On 06.09.2010 19:48, Eric Norman wrote: Hi All, This seems kind

Re: [VOTE] Release Apache Sling JCR API, JCR Base, JCR Content Loader, and Jackrabbit Server 2.1.0

2010-09-07 Thread Eric Norman
+1 On Sep 6, 2010 8:42 AM, Justin Edelson jus...@apache.org wrote: Hi, We solved a total of 33 issues in these releases: JCR API - 1 issue: https://issues.apache.org/jira/browse/SLING/fixforversion/12314564 JCR Base - 6 issues:

Re: [VOTE] Release Sling Servlets Resolver 2.1.0, Servlets GET 2.1.0, Servlets POST 2.1.0

2010-10-05 Thread Eric Norman
+1 On Oct 3, 2010 11:48 AM, Felix Meschberger fmesc...@gmail.com wrote: Hi, I hereby start the vote for the release of the Servlet support bundles: Sling Servlets Resolver 2.1.0, Sling Servlets GET 2.1.0, and Sling Servlets POST 2.1.0. All bundles include some kind of extended functionalities

Re: [VOTE] Initial Content and Servlet Archetypes 1.0.0

2010-10-18 Thread Eric Norman
+1 Eric On Oct 15, 2010 7:45 AM, Justin Edelson jus...@apache.org wrote: Hi, This vote is for: Sling Initial Content Archetype 1.0.0 Sling Servlet Archetype 1.0.0 This is the initial version of each. Staging repository: https://repository.apache.org/content/repositories/orgapachesling-001/

Building trunk on windows xp?

2011-01-30 Thread Eric Norman
) at org.apache.sling.event.impl.jobs.jcr.PersistenceHandler.access$000(PersistenceHandler.java:89) at org.apache.sling.event.impl.jobs.jcr.PersistenceHandler$1.run(PersistenceHandler.java:188) at java.lang.Thread.run(Thread.java:619) Regards, Eric Norman

Re: Building trunk on windows xp?

2011-02-01 Thread Eric Norman
of course build Sling by disabling the tests. (mvn -Dmaven.test.skip=true install) Regards Carsten Eric Norman wrote Hi all, I haven't been able to work on sling for a while due to other commitments, but I am trying to sync up to the current trunk to make a fresh build and I

Re: [VOTE] Apache Sling Launchpad Content 2.0.6 and Apache Sling 6 Source Release

2011-03-14 Thread Eric Norman
+1 Regards, Eric On Mar 13, 2011 11:38 AM, Felix Meschberger fmesc...@adobe.com wrote: Hi all, At long last, here is the (hopefully) final vote for Sling 6: Apache Sling Launchpad Content 2.0.6 Apache Sling Launchpad 6 Apache Sling 6 Source Release I have tagged the Launchpad Testing and

Re: upgrading to Jackrabbit 2.2.5

2011-03-31 Thread Eric Norman
projects. [WARNING] On Mar 31, 2011, at 2:24 PM, Eric Norman wrote: Hi All, I found a use case where I could also use an upgrade to jackrabbit 2.2.5 to utilize some changes in user/group management. I filed JIRA issue SLING-2044 for tracking and will attempt the upgrade today

Re: upgrading to Jackrabbit 2.2.5

2011-03-31 Thread Eric Norman
with the ItemID parameter? I'll take a look at the Tika issue. Did you try 0.9? Justin On Thu, Mar 31, 2011 at 8:45 PM, Eric Norman eric.d.nor...@gmail.com wrote: Moving further discussion to the dev list... Thanks Justin, I almost got it working using your patch + some other changes

Re: upgrading to Jackrabbit 2.2.5

2011-04-01 Thread Eric Norman
at 6:17 AM, Justin Edelson jus...@justinedelson.comwrote: On Fri, Apr 1, 2011 at 12:42 AM, Eric Norman eric.d.nor...@gmail.com wrote: Thanks for the review. Maybe it is ok to just pass the ItemId to the AccessManagerPlugin2#canRead method as a string? That'd solve the export problem

Re: upgrading to Jackrabbit 2.2.5

2011-04-01 Thread Eric Norman
block trunk from being updated to 2.2.5. It is, however, something we should resolve before the next release. Justin On Fri, Apr 1, 2011 at 9:57 AM, Eric Norman eric.d.nor...@gmail.com wrote: It's hard to predict what an implementor would do. The more I think about it, maybe it would

Re: upgrading to Jackrabbit 2.2.5

2011-04-01 Thread Eric Norman
I added an updated patch set @ http://codereview.appspot.com/4345041/ It seems to work locally. Do you see anything wrong with that or see anything that I missed? http://codereview.appspot.com/4345041/Regards, Eric On Fri, Apr 1, 2011 at 12:54 PM, Eric Norman eric.d.nor...@gmail.comwrote

Re: [JSON] Stable Child Resource Order

2011-04-07 Thread Eric Norman
why not just render the ordered child nodes as a json array? On Apr 7, 2011 10:22 AM, Alexander Klimetschek aklim...@adobe.com wrote: On 07.04.11 13:31, Felix Meschberger fmesc...@adobe.com wrote: The problem is that :order already is used by the Sling POST Servlet to define the order of newly

Re: [JSON] Stable Child Resource Order

2011-04-07 Thread Eric Norman
Yes, but if order is important it seems more correct to send an array. And adding a psuedo 'order' property isn't backward compatible either. On Thu, Apr 7, 2011 at 11:26 AM, Tobias Bocanegra tri...@adobe.com wrote: On Thu, Apr 7, 2011 at 10:38 AM, Eric Norman eric.d.nor...@gmail.com wrote

Re: [JSON] Stable Child Resource Order

2011-04-07 Thread Eric Norman
Is there any reason why you can't just make a custom script to output whatever JSON format you want? I'm not convinced this has usefulness outside your use case that would warrant changing the generic format. On Thu, Apr 7, 2011 at 10:26 AM, Tobias Bocanegra tri...@adobe.com wrote: thanks

Re: [VOTE] Release Apache Sling Engine 2.2.4

2011-06-17 Thread Eric Norman
+1 On Tue, Jun 14, 2011 at 10:03 AM, Justin Edelson jus...@apache.org wrote: Hi, We solved 7 issues in this release: https://issues.apache.org/jira/browse/SLING/fixforversion/12316221 Staging repository: https://repository.apache.org/content/repositories/orgapachesling-009/ You can use

Re: release I18N 2.1.2?

2011-07-14 Thread Eric Norman
+1

Re: UserManager in ESP

2009-07-07 Thread Eric Norman
You could probably hide some of the low-level details by using the sling resource resolver to lookup the same information. You will need the patch attached to https://issues.apache.org/jira/browse/SLING-1009 for the listChildren call to work. Maybe someone with permissions could review the patch

Re: Self Registration.

2009-07-28 Thread Eric Norman
How would you know which users are administrative users? On Jul 27, 2009 8:57 AM, Ian Boston i...@tfd.co.uk wrote: Hi, I have noticed that the CreateUserServlet does not allow administrative users to create users if self registration is disabled. Was that intentional, or should I fix ? Ian

Re: sling.include cleansing URI?

2009-08-25 Thread Eric Norman
Can you just create the widgets node at the same time you create the page node? You can do that in the POST that creates the page or use a JCR event listener to listen for page creation events. On Aug 25, 2009 12:26 PM, Branden Visser bran...@uwindsor.ca wrote: Alexander Klimetschek wrote: On

Re: Creating multiple nodes in one POST (was Re: sling.include cleansing URI?)

2009-08-25 Thread Eric Norman
terrific. glad to help! On Tue, Aug 25, 2009 at 1:16 PM, Branden Visser bran...@uwindsor.ca wrote: Ahh, I didn't know that, that's very useful.. Thanks! :) Eric Norman wrote: Well the way I've been doing that is to add a hidden input field to the html form that sets the jcr:primaryType

Re: POST esp script

2009-09-08 Thread Eric Norman
Sure, that should work. Just make sure to call jcrSession.save() if you make any JCR updates that should be persisted after the forward. On Sep 7, 2009 4:36 PM, Peter Chiochetti p...@myzel.net wrote: Am 2009-09-07 17:36, schrieb Eric Norman: Try this: % var isValid = true; //TODO: your

Re: WebKit HTTP Authentication

2009-09-17 Thread Eric Norman
to implement, there were a couple servlets (LoginServlet, LogoutServlet) and an AuthenticationHandler class plus an esp script to render the login page. I could provide a patch if you are interested. Regards, -Eric Norman On Wed, Sep 16, 2009 at 4:52 PM, Mike Moulton m...@meltmedia.com wrote

Re: WebKit HTTP Authentication

2009-09-17 Thread Eric Norman
to be configured to perform session replication to avoid the login prompt when you get routed to a different server node. Does that make sense? On Thu, Sep 17, 2009 at 7:45 AM, Vidar Ramdal vi...@idium.no wrote: On Thu, Sep 17, 2009 at 4:00 PM, Eric Norman eric.d.nor...@gmail.com wrote: For my own

Re: Dynamic Class Loader sometimes needs restart

2009-10-23 Thread Eric Norman
I think I have seen the same. Are your scripts embedded inside your bundle? On Oct 23, 2009 6:45 AM, Vidar Ramdal vi...@idium.no wrote: I'm seeing a problem with the org.apache.sling.commons.classloader bundle. When I update certain of my own bundles, RhinoJavaScriptEngineFactory and

Re: Disabling node.infinity.json

2010-01-10 Thread Eric Norman
One option would be to register your own script (or servlet) that also matches the same selector [+extension]. Since your script would be a closer match than the default get servlet, it should use your script instead. For example, create an esp script @

Re: [jira] Updated: (SLING-1116) FORM Based Authentication

2010-01-24 Thread Eric Norman
tried to put non user generated urls at /system/... or /_ to avoid conflicts. Ian Sent from my iPhone On 24 Jan 2010, at 17:18, Eric Norman (JIRA) j...@apache.org wrote: [ https://issues.apache.org/jira/browse/SLING-1116?page=com.atlassian.jira.plugin.system.issuetabpanels:all

Re: Node Access Control

2010-01-28 Thread Eric Norman
Hi Ben, Sure, that is possible. There is a brief example in the comments for https://issues.apache.org/jira/browse/SLING-981 Regards, -Eric On Thu, Jan 28, 2010 at 5:41 AM, Ben Short b...@benshort.co.uk wrote: Hi, Firstly sorry if I'm not using the correct terminology. If I have the

Re: Welcome Eric Norman

2010-02-17 Thread Eric Norman
Regards, -Eric On Wed, Feb 17, 2010 at 7:20 AM, Felix Meschberger fmesc...@gmail.comwrote: Hi all, I want to let you know that the Apache Sling PMC decided to invite Eric Norman as a committer to the Apache Sling project based on his work in the security arena (user management, access control

Re: Add replaceEntry method to AccessControlUtil?

2010-02-23 Thread Eric Norman
Hi Ray, Thanks for testing and reporting this. You raise a good point. The ModifyAceServlet should handle updates involving aggregate privileges transparently. I'll re-open SLING-997 and work on an updated fix to address your scenario. Regards, Eric On Tue, Feb 23, 2010 at 3:32 PM, Ray Davis

Re: Add replaceEntry method to AccessControlUtil?

2010-02-23 Thread Eric Norman
Ray, I applied a new patch in r915670. Can you please verify that this addresses your concerns? Thanks! Eric On Tue, Feb 23, 2010 at 7:42 PM, Eric Norman eric.d.nor...@gmail.comwrote: Hi Ray, Thanks for testing and reporting this. You raise a good point. The ModifyAceServlet should

Re: [VOTE] Release Commons MIME type support 2.1.4, Eventing 2.3, File System Provider 1.0, and Scripting Core 2.0.10

2010-02-27 Thread Eric Norman
+1 On Sat, Feb 27, 2010 at 5:01 AM, Ian Boston i...@tfd.co.uk wrote: +1 Artifacts check out ok and I cant see any issues with the fix sets (although I am not 100% familiar with all of the components) Ian On 23 Feb 2010, at 13:08, Carsten Ziegeler wrote: Hi, this is the next vote for

Re: can ace.html.esp and acl.html.esp be moved out of launchpad/content?

2010-03-01 Thread Eric Norman
I guess we could move them to the jackrabbit-accessmanager bundle. I could be convinced otherwise, but I always thought of the ace.html.esp and acl.html.esp scripts in launchpad.content as examples rather than something that would be used in a real system. The user interface in those scripts

Re: can ace.html.esp and acl.html.esp be moved out of launchpad/content?

2010-03-01 Thread Eric Norman
That would work for me. Regards, Eric On Mon, Mar 1, 2010 at 11:15 AM, Felix Meschberger fmesc...@gmail.comwrote: Hi, And if we created a sample project for user and access control management ? Regards Felix On 01.03.2010 18:30, Eric Norman wrote: I guess we could move them

Re: AccessControlUtil.replaceAccessControlEntry

2010-03-17 Thread Eric Norman
Hi Ian, I am having trouble reproducing what you have described. I added a new unit test in r924618 to test the scenario you described and it appears to work correctly for me. Can you check the new unit test to see if there are some extra steps in your use case that I am missing? Regards,

Re: Build fails, wrong version for maven-launchpad-plugin?

2010-04-25 Thread Eric Norman
Yeah, I think you are right. I just ran into the same issue doing a clean build. I've updated the version number in r937907. Try syncing to that to see if it works better for you. Regards, Eric On Sun, Apr 25, 2010 at 11:53 AM, Pontus Amberg pontus.amb...@comhem.sewrote: Currently the trunk

Re: Caching Support Request Filter

2010-04-28 Thread Eric Norman
Hi all, In general, I like the idea of a server side cache. However, I agree with Vidar that a cache without resource tracking has limited usefulness in a real system. In the past I had implemented something similar. The key parts I remember were: - I used a (slightly) modified version of

Re: [jira] Resolved: (SLING-1172) Allow uploading JSON files to create content structures

2010-06-30 Thread Eric Norman
, at 20:39, Eric Norman (JIRA) wrote: [ https://issues.apache.org/jira/browse/SLING-1172?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel] Eric Norman resolved SLING-1172. Fix Version/s: JCR ContentLoader 2.0.8 Resolution

Re: upgrade version # of jackrabbit-usermanager bundle

2011-11-10 Thread Eric Norman
Sounds good to me. Eric On Thu, Nov 10, 2011 at 1:34 PM, Justin Edelson jus...@justinedelson.comwrote: I'd like to release the jackrabbit-usermanager bundle soon. Looking at the changes, it seem like this should really be 2.2.0, not 2.1.2. Specifically, a new API was added

Re: [VOTE] Release Apache Sling Jackrabbit UserManager 2.2.0

2011-11-13 Thread Eric Norman
+1 On Nov 13, 2011 1:01 PM, Justin Edelson jus...@apache.org wrote: Any voters? On Fri, Nov 11, 2011 at 10:15 AM, Justin Edelson jus...@apache.org wrote: Hi, We solved 6 issues in this release: https://issues.apache.org/jira/browse/SLING/fixforversion/12315521 Staging repository:

Re: LoginServlet broken since SLING-2165

2012-01-10 Thread Eric Norman
Maybe it should only be checking the referrer when the request is a POST. The intent of that referer checking was to make sure you returned to the same login page when there was an error with the credentials that were posted from the login form. Regards, Eric On Tue, Jan 10, 2012 at 12:23 PM,

Re: Delete operation advice

2012-03-16 Thread Eric Norman
If you want to use a servlet to override the behavior, you can perform your extra logic in your servlet and then forward to the default sling post servlet at the end to do the rest. For example, something like this: Resource resource = request.getResource(); RequestDispatcher rd =

Re: Creating a user as anonymous (SLING-2465)

2012-05-19 Thread Eric Norman
It looks like all it needs is the path of the created user. The created user should always be the first Modification in the changes list so you can probably just get the user path from there if the returned user is null. See patch [1]. Regards, Eric 1. http://pastebin.com/0DX4i8fK On Wed, May

Re: Build failure

2012-06-24 Thread Eric Norman
The error message says repo1.maven.org is an unknown host. Are you able to ping repo1.maven.org and get a response? On Sun, Jun 24, 2012 at 2:15 AM, Bhathiya Jayasekara tobhathi...@gmail.comwrote: Hi devs, When I try to build Sling from trunk, I get following error. Can you please help me

Re: explorer bundle doesn't work when sling webapp is not mounted as ROOT

2012-06-24 Thread Eric Norman
Which version are you using? There were a couple of reported defects that were fixed in the trunk that may have corrected this already. See: https://issues.apache.org/jira/browse/SLING-2019 On Thu, Jun 21, 2012 at 3:44 AM, Torgeir Veimo torg...@netenviron.comwrote: If I mount the sling

Re: [jira] [Commented] (SLING-2803) Create a Validation module capable of validating POST requests or Resources

2013-03-29 Thread Eric Norman
If I recall corectly, sometimes errors occur before the post processor gets a chance to run. Such as constraint violations on a node type. So I would think doing validation as a pre processor would catch a larger universe of errors. But, that could be complex to do right. On Mar 29, 2013 9:11

Re: Disabling flaky tests

2013-06-02 Thread Eric Norman
Personally, I'm not a big fan of hiding flaky/failing tests since it tends to remove some of the motivation to stabilize/fix them in a timely manner. That's my 2 cents. Regards, Eric On Fri, May 31, 2013 at 12:14 PM, Robert Munteanu romb...@apache.orgwrote: Hi, It seems that the

Re: [Dev][GSoC] Using a cache to store a string value

2018-06-06 Thread Eric Norman
to generate, validate and persist the secure tokens. 1. https://github.com/scribejava/scribejava -Eric Norman On Wed, Jun 6, 2018 at 11:37 AM, Ioan Eugen Stan wrote: > Hi, > > I think you should store it in memory. Use a hashmap or something. > > Make it work and then optimize. T

Re: [Dev][GSoC] Using a cache to store a string value

2018-06-06 Thread Eric Norman
Keep in mind that an in memory cache wont work so well in a cluster unless you can guarantee sticky sessions from your load balancer. On Wed, Jun 6, 2018, 1:11 PM Robert Munteanu wrote: > On Wed, 2018-06-06 at 21:37 +0300, Ioan Eugen Stan wrote: > > Hi, > > > > I think you should store it in

Re: New "capabilities" module, feedback welcome

2018-06-22 Thread Eric Norman
Honestly, I haven't seen any explanation of the use cases that would justify the complexity of the solution. You seem to be creating a resource in the reposotory whose sole purpose is to trigger rendering by the servlet bound to the resource type. With that in mind, my inclination would be to

Re: New "capabilities" module, feedback welcome

2018-06-20 Thread Eric Norman
It seems to me that there a risk that this endpoint could leave the system vulnerable to an information disclosure attack. This is the kind of data that would be useful in refining an attack on the server. Regards, Eric On Wed, Jun 20, 2018, 7:09 AM Robert Munteanu wrote: > Hi Bertrand, > >

Re: New "capabilities" module, feedback welcome

2018-06-21 Thread Eric Norman
an wrote: > > On 20.06.2018 19:02, Eric Norman wrote: > > >... It seems to me that there a risk that this endpoint could leave the > system > > > vulnerable to an information disclosure attack. > > > > > I was thinking the same thing. I think this should b

Re: [Dev][GSoC]Redirecting to Apache Sling home page with logged user.

2018-07-24 Thread Eric Norman
You may want to check your project dependencies to make sure you have the osgi annotations artifacts that correspond to the r6 or later versions of the OSGi specifications. The earlier versions of the specification stated that the @Reference annotation was only allowed on the bind method, so a

Re: [Dev][GSoc] How to create a user without password using Jackrabbit API

2018-07-08 Thread Eric Norman
If I am reading the code correctly, it looks like both the jackrabbit 2.x and oak implementation of UserManager API allows you to pass null as the password and it doesn't attempt to store a password in that case. Your other option would be just to generate some random password value that the user

Re: [Dev][GSoc] How to create a user without password using Jackrabbit API

2018-07-13 Thread Eric Norman
Yes, self registration by an anonymous user is disabled by default. This self-registration configuration can be changed by navigating to http://localhost:8080/system/console/configMgr and modify the configuration of the "Apache Sling Create User" component. Or as Robert stated, the admin user

Re: [sling:resourceType] protected execution

2018-10-05 Thread Eric Norman
> > 1. Users can freely define sling:resourceType properties Is there some reason why this must be so? In JCR land, the jcr:nodeTypeManagement privilege must be granted for the user to have permission to add and remove mixin node types and change the primary node type of a node. I would expect

Re: [sling:resourceType] protected execution

2018-10-04 Thread Eric Norman
security nodes. Regards, Eric On Thu, Oct 4, 2018, 4:45 AM Radu Cotescu wrote: > Hi Eric, > > > On 3 Oct 2018, at 20:50, Eric Norman wrote: > > > > 1. To handle POST requests, each servlet does it's own access checking in > > java code to ensure the right pri

Re: How to manage repoinit language + implementation evolutions?

2018-10-03 Thread Eric Norman
I'm with Jörg, the old syntax was fine. The bad behavior seems to be just a bug to me that should just be fixed. Adding more complex choices seems unnecessary. Regards, Eric On Wed, Oct 3, 2018, 9:58 AM Dominik Süß wrote: > Hi Jörg, > > As you can imagine I disagree as users might have used

Re: [sling:resourceType] protected execution

2018-10-03 Thread Eric Norman
Is it the resource type that needs protection? Or the script/servlet that is handling a specific method+selector+extension for the resource type? I generally prefer to have all my servlets get called regardless of whether the user has rights to do that action so any invalid requests can be

Re: [VOTE] Initial Release of Apache Sling Resource Filter version 1.0.0

2018-09-02 Thread Eric Norman
Is there a chance of using a more descriptive name? "Resource Filter" seems too generic to me and could have different meanings. Regards, Eric On Sun, Sep 2, 2018, 1:02 PM Jason E Bailey wrote: > Hi, > > We solved 1 issue in this release: >

Re: Preparing to release JCR Base 3.0.6

2018-12-12 Thread Eric Norman
Thanks for the clarification. I've moved the open issues to 3.0.8 On Wed, Dec 12, 2018 at 1:21 AM Robert Munteanu wrote: > On Tue, 2018-12-11 at 11:14 -0800, Eric Norman wrote: > > I don't know the status of the work on those 2 issues. Are there any > > objections to moving tho

[VOTE] Release Apache Sling JCR Base 3.0.6

2018-12-12 Thread Eric Norman
Hi, We solved 3 issues in this release: https://issues.apache.org/jira/projects/SLING/versions/12341119 Staging repository: https://repository.apache.org/content/repositories/orgapachesling-2024/ You can use this UNIX script to download the release and verify the signatures:

[RESULT] [VOTE] Release Apache Sling JCR Base 3.0.6

2018-12-15 Thread Eric Norman
Hi, The vote has passed with the following result : +1 (binding): Julian Sedding, Daniel Klco, Oliver Lietz, Robert Munteanu +1 (non binding): Eric Norman I need someone from the PMC to copy this release to the Sling dist directory. Once that is done I will promote this to the central Maven

Re: [RESULT] [VOTE] Release Apache Sling JCR Jackrabbit Access Manager 3.0.4, Apache Sling JCR ContentLoader 2.3.0

2018-12-20 Thread Eric Norman
e I should be checking. Regards, -Eric On Thu, Dec 20, 2018 at 10:28 AM Oliver Lietz wrote: > On Wednesday 19 December 2018 20:09:07 Eric Norman wrote: > > Hi, > > Hi Eric, > > > The vote has passed with the following result : > > > > +1 (binding): Robert Munteanu

Preparing to release JCR Base 3.0.6

2018-12-11 Thread Eric Norman
I'd like to release JCR Base 3.0.6 to unblock work on another issue. There are currently 2 unresolved/open issues linked to that version in JIRA ( see [1] ). I don't know the status of the work on those 2 issues. Are there any objections to moving those 2 unresolved issues to the next version

[RESULT] [VOTE] Release Apache Sling Testing Sling Mock Jackrabbit Oak-based Resource Resolver version 2.1.2

2018-12-11 Thread Eric Norman
Hi, The vote has passed with the following result : +1 (binding): Eric Norman, Stefan Seifert, Robert Munteanu, Daniel Klco +1 (non binding): Jason E. Bailey I need someone from the PMC to copy this release to the Sling dist directory. Once that is done I will promote this to the central Maven

[VOTE] Release Apache Sling JCR Jackrabbit Access Manager 3.0.4, Apache Sling JCR ContentLoader 2.3.0

2018-12-16 Thread Eric Norman
Hi, We solved 3 issues in these two releases: https://issues.apache.org/jira/browse/SLING/fixforversion/12344571 https://issues.apache.org/jira/browse/SLING/fixforversion/12344121 Staging repository: https://repository.apache.org/content/repositories/orgapachesling-2031/ You can use this UNIX

Re: [VOTE] Release Apache Sling JCR Base 3.0.6

2018-12-15 Thread Eric Norman
+1 (non-binding) On Wed, Dec 12, 2018 at 12:45 PM Eric Norman wrote: > Hi, > > We solved 3 issues in this release: > https://issues.apache.org/jira/projects/SLING/versions/12341119 > > Staging repository: > https://repository.apache.org/content/repositories/orgapachesling-

Re: Support for ACE Restrictions with jackrabbit.accessmanager REST

2018-12-06 Thread Eric Norman
Hi Robert, Ok, I will give it a try. Please advise if I mess something up. Regards, Eric On Mon, Dec 3, 2018 at 1:39 AM Robert Munteanu wrote: > Hi Eric, > > On Tue, 2018-11-27 at 17:10 -0800, Eric Norman wrote: > > Would someone be able to review the changes done f

[VOTE] Release Apache Sling Testing Sling Mock Jackrabbit Oak-based Resource Resolver version 2.1.2

2018-12-06 Thread Eric Norman
Hi, We solved 1 issues in this release: https://issues.apache.org/jira/browse/SLING/fixforversion/12343921 Staging repository: https://repository.apache.org/content/repositories/orgapachesling-2023 You can use this UNIX script to download the release and verify the signatures:

Re: [VOTE] Release Apache Sling Testing Sling Mock Jackrabbit Oak-based Resource Resolver version 2.1.2

2018-12-08 Thread Eric Norman
+1 On Thu, Dec 6, 2018 at 8:36 PM Eric Norman wrote: > Hi, > > We solved 1 issues in this release: > https://issues.apache.org/jira/browse/SLING/fixforversion/12343921 > > Staging repository: > https://repository.apache.org/content/repositories/orgapachesling-2023 >

Support for ACE Restrictions with jackrabbit.accessmanager REST

2018-11-27 Thread Eric Norman
Hey all, I've been doing some work to try to solve the issue reported in the thread at [1] and tracked as SLING-8117 1.

Re: [VOTE] Release Apache Sling Jackrabbit JSR-283 Access Control Manager Support 3.0.2

2018-09-12 Thread Eric Norman
+1 On Wed, Sep 12, 2018 at 8:43 AM Daniel Klco wrote: > +1 > > On Wed, Sep 12, 2018 at 8:22 AM Robert Munteanu > wrote: > > > Hi, > > > > We solved 4 issues in this release: > > https://issues.apache.org/jira/projects/SLING/versions/12341398 > > > > > > Staging repository: > >

Re: [VOTE] Release Apache Sling Jackrabbit UserManager Support 2.2.8

2018-09-12 Thread Eric Norman
+1 On Wed, Sep 12, 2018 at 8:47 AM Daniel Klco wrote: > +1 > > On Wed, Sep 12, 2018 at 8:24 AM Robert Munteanu > wrote: > > > Hi, > > > > We solved 5 issues in this release: > > https://issues.apache.org/jira/projects/SLING/versions/12340294 > > > > Staging repository: > >

[RESULT] [VOTE] Release Apache Sling JCR Jackrabbit Access Manager 3.0.4, Apache Sling JCR ContentLoader 2.3.0

2018-12-19 Thread Eric Norman
Hi, The vote has passed with the following result : +1 (binding): Robert Munteanu, Karl Pauls, Radu Cotescu +1 (non binding): Eric Norman I need someone from the PMC to copy these releases to the Sling dist directory. Once that is done I will promote this to the central Maven repository

Re: [VOTE] Release Apache Sling JCR Jackrabbit Access Manager 3.0.4, Apache Sling JCR ContentLoader 2.3.0

2018-12-19 Thread Eric Norman
+1 (non binding) On Sun, Dec 16, 2018 at 7:53 PM Eric Norman wrote: > Hi, > > We solved 3 issues in these two releases: > https://issues.apache.org/jira/browse/SLING/fixforversion/12344571 > https://issues.apache.org/jira/browse/SLING/fixforversion/12344121 > > > Sta

Re: [RTC] Rename error.log to success.log

2019-04-01 Thread Eric Norman
Neither of those names are accurate though. The file is just logs, there isn't any reason to conclude that the contents are errors or successes. The reality is a mix of log messages for lots of different reasons. -Eric On Mon, Apr 1, 2019, 12:19 AM Robert Munteanu wrote: > Hi, > > I think for

Re: [Done] Consolidate starter-startup and startupfilter/startupfilter-disabler to use Apache Felix HC ServiceUnavailableFilter

2019-05-24 Thread Eric Norman
he rest of the html file (which is great from a > maintenance point of view I think). > > - Georg > > [1] > > https://github.com/apache/felix/blob/trunk/healthcheck/README.md#service-unavailable-filter > > > > On 2019-05-23 23:45, Eric Norman wrote: > > Hi Geor

Re: [Done] Consolidate starter-startup and startupfilter/startupfilter-disabler to use Apache Felix HC ServiceUnavailableFilter

2019-05-22 Thread Eric Norman
Hi Georg, I'm trying to digest what has been done here. It looks like this makes the solution that was done for https://issues.apache.org/jira/browse/SLING-7764 obsolete and breaks compatibility for any customization done via a fragment attached to the previous o.a.sling.starter.startup snapshot

Re: [Done] Consolidate starter-startup and startupfilter/startupfilter-disabler to use Apache Felix HC ServiceUnavailableFilter

2019-05-22 Thread Eric Norman
disclosure security vulnerability. What do you think about setting the "includeExecutionResult" service configuration property to false to suppress that report injection? For example, this html comment was being injected into the starting up page: Regards, Eric On Wed, May 22,

Re: [Done] Consolidate starter-startup and startupfilter/startupfilter-disabler to use Apache Felix HC ServiceUnavailableFilter

2019-05-23 Thread Eric Norman
om response text/html" > > https://github.com/apache/felix/blob/trunk/healthcheck/README.md#service-unavailable-filter > > [2] > > https://github.com/apache/felix/blob/trunk/healthcheck/core/src/main/java/org/apache/felix/hc/core/impl/filter/ServiceUnavailableFilter.java#

Re: Missing horizontal scroll bars on Sling Website

2019-09-16 Thread Eric Norman
FYI: I also see missing horizontal bars with Chromium 76 on linux. -Eric On Mon, Sep 16, 2019 at 9:47 AM Jason E Bailey wrote: > I may have spoke to soon. I'm seeing horizontal scoll bars when they are > needed. Are you on mobile? > > -- > Jason > > On Mon, Sep 16, 2019, at 12:42 PM, Jason E

Re: Missing horizontal scroll bars on Sling Website

2019-09-16 Thread Eric Norman
It seems to be related to the " overflow-x: hidden;" style applied to the html element from bulma.min.css On Mon, Sep 16, 2019 at 9:53 AM Eric Norman wrote: > FYI: I also see missing horizontal bars with Chromium 76 on linux. > > -Eric > > On Mon, Sep 16, 2019 at 9:47 A

Re: [VOTE] Release Apache Sling Models Implementation 1.4.12

2019-11-01 Thread Eric Norman
+1 (non-binding) On Fri, Nov 1, 2019 at 4:14 AM Nicolas Peltier wrote: > Hi, > > We solved 6 issues in this release > > https://issues.apache.org/jira/browse/SLING-8781?jql=project%20%3D%20SLING%20AND%20fixVersion%20%3D%20%22Sling%20Models%20Impl%201.4.12%22 > > Staging repository: >

Re: auto-created PRs from github/dependabot for security-related deps updates

2019-11-14 Thread Eric Norman
I think I would prefer that we don't ever depend on any version with known security issues . So for me, it would be appropriate to take these PRs seriously and apply the updates as requested. What would it hurt to have the next release of the affected sling bundle depend on the newer minimum

Re: auto-created PRs from github/dependabot for security-related deps updates

2019-11-14 Thread Eric Norman
n my pov the osgi package version dependencies are not the right vehicle > to enforce deploying 3rdparty bundles without vulnerabilities on the target > systems. > > stefan > > >-Original Message- > >From: Eric Norman [mailto:enor...@apache.org] > >Sent: Thursd

Re: [VOTE] Release Apache Sling XSS Protection API 2.1.10

2019-10-25 Thread Eric Norman
+1 (non-binding) Regards, Eric Norman On Fri, Oct 25, 2019 at 7:57 AM Radu Cotescu wrote: > Hi, > > We solved 2 issues in this release: > https://issues.apache.org/jira/projects/SLING/versions/12346347 < > https://issues.apache.org/jira/projects/SLING/versions/12346347> &

Re: [VOTE] Release Apache Sling Commons Johnzon version 1.2.2

2020-04-22 Thread Eric Norman
+ 1 non-binding Thanks, Eric On Wed, Apr 22, 2020 at 6:48 AM Konrad Windszus wrote: > > Hi, > > We solved 1 issue in this release: > https://issues.apache.org/jira/browse/SLING-9218 > > Staging repository: > https://repository.apache.org/content/repositories/orgapachesling-2244/ > > You can

[VOTE] Release Apache Sling JCR Oak Server version 1.2.8

2020-09-10 Thread Eric Norman
Hi, We solved 2 issues in this release: https://issues.apache.org/jira/browse/SLING/fixforversion/12348709 Staging repository: https://repository.apache.org/content/repositories/orgapachesling-2329/ You can use this UNIX script to download the release and verify the signatures:

[RESULT] [VOTE] Release Apache Sling JCR Oak Server version 1.2.8

2020-09-14 Thread Eric Norman
Hi, The vote has passed with the following result : +1 (binding): Radu Cotescu, Daniel Klco, Stefan Seifert, Eric Norman +1 (non binding): none I will copy this release to the Sling dist directory and promote the artifacts to the central Maven repository.

Re: [VOTE] Release Apache Sling JCR Oak Server version 1.2.8

2020-09-14 Thread Eric Norman
+1 On Thu, Sep 10, 2020 at 5:36 PM Eric Norman wrote: > Hi, > > We solved 2 issues in this release: > https://issues.apache.org/jira/browse/SLING/fixforversion/12348709 > > Staging repository: > https://repository.apache.org/content/repositories/orgapachesling-2329/ >

  1   2   3   4   5   6   7   8   9   10   >