[jira] [Commented] (OFBIZ-10438) Add method attribute to request-map to controll a uri can be called GET or POST only

2018-08-08 Thread Shi Jinghai (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-10438?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16574287#comment-16574287 ] Shi Jinghai commented on OFBIZ-10438: - Thank you Mathieu! I'm testing these new patches. > Add

[jira] [Updated] (OFBIZ-10438) Add method attribute to request-map to controll a uri can be called GET or POST only

2018-08-08 Thread Mathieu Lirzin (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-10438?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Mathieu Lirzin updated OFBIZ-10438: --- Attachment: (was: OFBIZ-10438_0003-Handle-multiple-request-methods.patch) > Add method

[jira] [Updated] (OFBIZ-10438) Add method attribute to request-map to controll a uri can be called GET or POST only

2018-08-08 Thread Mathieu Lirzin (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-10438?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Mathieu Lirzin updated OFBIZ-10438: --- Attachment: OFBIZ-10438_0003-Handle-multiple-request-methods.patch > Add method attribute

[jira] [Commented] (OFBIZ-10485) Refactor MapContext

2018-08-08 Thread Mathieu Lirzin (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-10485?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16573257#comment-16573257 ] Mathieu Lirzin commented on OFBIZ-10485: Thanks [~jacques.le.roux] for spotting that > Refactor

[jira] [Closed] (OFBIZ-10485) Refactor MapContext

2018-08-08 Thread Jacques Le Roux (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-10485?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jacques Le Roux closed OFBIZ-10485. --- Resolution: Implemented This is not fixed but implemented > Refactor MapContext >

[jira] [Reopened] (OFBIZ-10485) Refactor MapContext

2018-08-08 Thread Jacques Le Roux (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-10485?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jacques Le Roux reopened OFBIZ-10485: - > Refactor MapContext > --- > > Key: OFBIZ-10485 >

[jira] [Updated] (OFBIZ-10508) Remove checks to store only 250 characters of URL in VisitHandler.getVisit() & ServerHitBin.saveHit()

2018-08-08 Thread Aditya Sharma (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-10508?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Aditya Sharma updated OFBIZ-10508: -- Description: Found following checks to restrict "URL" fields for Visit and ServerHit entity:

[jira] [Updated] (OFBIZ-10508) Remove checks to store only 250 characters of URL in VisitHandler.getVisit() & ServerHitBin.saveHit()

2018-08-08 Thread Aditya Sharma (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-10508?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Aditya Sharma updated OFBIZ-10508: -- Description: Found following checks to restrict "URL" fields for Visit and ServerHit entity:

[jira] [Updated] (OFBIZ-10508) Remove checks to store only 250 characters of URL in VisitHandler.getVisit() & ServerHitBin.saveHit()

2018-08-08 Thread Aditya Sharma (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-10508?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Aditya Sharma updated OFBIZ-10508: -- Description: Found following checks to restrict "URL" fields for Visit and ServerHit entity:

[jira] [Created] (OFBIZ-10508) Remove checks to store only 250 characters of URL in VisitHandler.getVisit() & ServerHitBin.saveHit()

2018-08-08 Thread Aditya Sharma (JIRA)
Aditya Sharma created OFBIZ-10508: - Summary: Remove checks to store only 250 characters of URL in VisitHandler.getVisit() & ServerHitBin.saveHit() Key: OFBIZ-10508 URL:

[jira] [Commented] (OFBIZ-10438) Add method attribute to request-map to controll a uri can be called GET or POST only

2018-08-08 Thread Mathieu Lirzin (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-10438?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16572985#comment-16572985 ] Mathieu Lirzin commented on OFBIZ-10438: I don't mind if you go with this strategy, however it

[jira] [Commented] (OFBIZ-10438) Add method attribute to request-map to controll a uri can be called GET or POST only

2018-08-08 Thread Taher Alkhateeb (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-10438?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16572952#comment-16572952 ] Taher Alkhateeb commented on OFBIZ-10438: - Great, I think the first step is to get community

[jira] [Comment Edited] (OFBIZ-10438) Add method attribute to request-map to controll a uri can be called GET or POST only

2018-08-08 Thread Mathieu Lirzin (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-10438?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16552431#comment-16552431 ] Mathieu Lirzin edited comment on OFBIZ-10438 at 8/8/18 9:47 AM: Seems

[jira] [Comment Edited] (OFBIZ-10438) Add method attribute to request-map to controll a uri can be called GET or POST only

2018-08-08 Thread Mathieu Lirzin (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-10438?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16572942#comment-16572942 ] Mathieu Lirzin edited comment on OFBIZ-10438 at 8/8/18 9:43 AM: {quote}

[jira] [Comment Edited] (OFBIZ-10438) Add method attribute to request-map to controll a uri can be called GET or POST only

2018-08-08 Thread Mathieu Lirzin (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-10438?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16572935#comment-16572935 ] Mathieu Lirzin edited comment on OFBIZ-10438 at 8/8/18 9:41 AM: Since

[jira] [Commented] (OFBIZ-10438) Add method attribute to request-map to controll a uri can be called GET or POST only

2018-08-08 Thread Mathieu Lirzin (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-10438?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16572942#comment-16572942 ] Mathieu Lirzin commented on OFBIZ-10438: {quote} Can I bother you to refresh my memory? What are

[jira] [Commented] (OFBIZ-10438) Add method attribute to request-map to controll a uri can be called GET or POST only

2018-08-08 Thread Mathieu Lirzin (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-10438?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16572935#comment-16572935 ] Mathieu Lirzin commented on OFBIZ-10438: Since OFBIZ-10485 is closed, I have updated the

[jira] [Commented] (OFBIZ-10438) Add method attribute to request-map to controll a uri can be called GET or POST only

2018-08-08 Thread Taher Alkhateeb (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-10438?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16572932#comment-16572932 ] Taher Alkhateeb commented on OFBIZ-10438: - Hi Mathieu, Can I bother you to refresh my memory?

[jira] [Updated] (OFBIZ-10438) Add method attribute to request-map to controll a uri can be called GET or POST only

2018-08-08 Thread Mathieu Lirzin (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-10438?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Mathieu Lirzin updated OFBIZ-10438: --- Attachment: (was: OFBIZ-10438_0003-Handle-multiple-request-methods.patch) > Add method

[jira] [Updated] (OFBIZ-10438) Add method attribute to request-map to controll a uri can be called GET or POST only

2018-08-08 Thread Mathieu Lirzin (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-10438?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Mathieu Lirzin updated OFBIZ-10438: --- Attachment: (was: OFBIZ-10438_0002-Parse-controller-config-in-one-place.patch) > Add

[jira] [Updated] (OFBIZ-10438) Add method attribute to request-map to controll a uri can be called GET or POST only

2018-08-08 Thread Mathieu Lirzin (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-10438?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Mathieu Lirzin updated OFBIZ-10438: --- Attachment: OFBIZ-10438_0001-Add-optional-method-attribute-in-request.patch

[jira] [Updated] (OFBIZ-10438) Add method attribute to request-map to controll a uri can be called GET or POST only

2018-08-08 Thread Mathieu Lirzin (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-10438?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Mathieu Lirzin updated OFBIZ-10438: --- Attachment: (was: OFBIZ-10438_0001-Add-optional-method-attribute-in-request.patch) >

[jira] [Commented] (OFBIZ-10507) LoginServices.userLogin: Respond "fail" instead of "error" to avoid the (automatic service engine) logging of a stack trace on missing/invalid credentials

2018-08-08 Thread Deepak Dixit (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-10507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16572902#comment-16572902 ] Deepak Dixit commented on OFBIZ-10507: -- It helps to identify the root cause of login failure, and

[jira] [Commented] (OFBIZ-10507) LoginServices.userLogin: Respond "fail" instead of "error" to avoid the (automatic service engine) logging of a stack trace on missing/invalid credentials

2018-08-08 Thread Benjamin Jugl (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-10507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16572869#comment-16572869 ] Benjamin Jugl commented on OFBIZ-10507: --- Let me rephrase: What relevant information is there, to

[jira] [Commented] (OFBIZ-10507) LoginServices.userLogin: Respond "fail" instead of "error" to avoid the (automatic service engine) logging of a stack trace on missing/invalid credentials

2018-08-08 Thread Deepak Dixit (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-10507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16572861#comment-16572861 ] Deepak Dixit commented on OFBIZ-10507: -- Also we can have two type of generic message, In this case

[jira] [Commented] (OFBIZ-10507) LoginServices.userLogin: Respond "fail" instead of "error" to avoid the (automatic service engine) logging of a stack trace on missing/invalid credentials

2018-08-08 Thread Deepak Dixit (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-10507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16572846#comment-16572846 ] Deepak Dixit commented on OFBIZ-10507: -- [~bjugl] error logging helps developer while debugging, it

[jira] [Comment Edited] (OFBIZ-10507) LoginServices.userLogin: Respond "fail" instead of "error" to avoid the (automatic service engine) logging of a stack trace on missing/invalid credentials

2018-08-08 Thread Benjamin Jugl (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-10507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16572836#comment-16572836 ] Benjamin Jugl edited comment on OFBIZ-10507 at 8/8/18 7:59 AM: --- I partly

[jira] [Updated] (OFBIZ-10507) LoginServices.userLogin: Respond "fail" instead of "error" to avoid the (automatic service engine) logging of a stack trace on missing/invalid credentials

2018-08-08 Thread Benjamin Jugl (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-10507?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Benjamin Jugl updated OFBIZ-10507: -- Attachment: OFBIZ-10507_org.apache.ofbiz.common.login.LoginServices.patch >

[jira] [Commented] (OFBIZ-10507) LoginServices.userLogin: Respond "fail" instead of "error" to avoid the (automatic service engine) logging of a stack trace on missing/invalid credentials

2018-08-08 Thread Benjamin Jugl (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-10507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16572836#comment-16572836 ] Benjamin Jugl commented on OFBIZ-10507: --- I partly agree. Generic messanges for the user are a good

[jira] [Updated] (OFBIZ-10507) LoginServices.userLogin: Respond "fail" instead of "error" to avoid the (automatic service engine) logging of a stack trace on missing/invalid credentials

2018-08-08 Thread Benjamin Jugl (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-10507?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Benjamin Jugl updated OFBIZ-10507: -- Attachment: (was: OFBIZ-10507_org.apache.ofbiz.common.login.LoginServices.patch) >

[jira] [Comment Edited] (OFBIZ-10507) LoginServices.userLogin: Respond "fail" instead of "error" to avoid the (automatic service engine) logging of a stack trace on missing/invalid credentials

2018-08-08 Thread Deepak Dixit (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-10507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16572708#comment-16572708 ] Deepak Dixit edited comment on OFBIZ-10507 at 8/8/18 6:00 AM: -- The login

[jira] [Commented] (OFBIZ-10507) LoginServices.userLogin: Respond "fail" instead of "error" to avoid the (automatic service engine) logging of a stack trace on missing/invalid credentials

2018-08-08 Thread Deepak Dixit (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-10507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16572708#comment-16572708 ] Deepak Dixit commented on OFBIZ-10507: -- The login page is prone to a user-enumeration attack, Error