Hi Justin

The GSIP-82 patch requires a new section in
http://docs.geoserver.org/stable/en/user/datadirectory/migrating.html
If this is not possible between 2.2.x versions, the backport is not
possible. Please tell me.

As a developer I am not keen on the backport. It is much easier for me to
put my focus on 2.3.x only.  As a user, I would be  frustrated. As an
example, on some chains you can add/remove filters, press save and
everything looks ok. After reopening the panel you will get a surprise. The
changes are lost. I know from some users that they are modifying the
security config.xml manually to get changes saved. This is one example why
I want to do the backport.

Another example: Add remove/filters from a chain and change the selection
in the filter chain drop box --> changes lost.

I do not insist on the backport , but I want to point out that for 2.2.x it
is better to avoid configuring authentication mechanisms, an admin needs
some luck to get  his needed configuration  working. (if it is possible at
all).

For future user mails in this area, I will advise users to wait for 2.3.0.
It also does not make sense to invest in bugfixes concerning filter chains
on 2.2.x without  the backport.

Anyways, thanks for the discussion and I will start applying the patch to
2.3.x

Christian



2012/12/5 Justin Deoliveira <[email protected]>

> Hey Christian,
>
> I certainly understand your desire to backport, I think we all have this
> desire when we do something on master that improves a specific feature or
> subsystem. But we have to have be disciplined on this regard so we try to
> provide our selves with rules that determine if something is
> "backportable". And one of those rules is not changing the data directory /
> configuration format between releases of the stable series. Doing so
> basically would not allow users to freely move between minor versions which
> is something we have always avoided.
>
> So i guess a question is whether this change forward compatible as well as
> backward compatible. If it is then I think we can start to have a
> discussion about backporting, but if it isn't i think that ends the
> conversation.
>
> If it is forward compatible it is also common / best practice to allow for
> a decent time period for a new feature to sit on master before its
> backported to stable, so it gets some extended exposure by other devs in
> order to:
>
>  * work out any remaining kinks
>  * give developers confidence that the change is indeed safe to backport
>
> -Justin
>
>
> On Wed, Dec 5, 2012 at 9:20 AM, Christian Mueller <[email protected]>wrote:
>
>> Hi all
>>
>> First, thanks for your votes.
>>
>> Justin, I feared the discussion about the backport and I also feel
>> uncomfortable about the migration within 2.2.x.  But lets have a look at
>> the current situation.
>>
>> IMHO GSIP-82 is not a pure improvement proposal. In fact, it is a
>> cumulative bugfix  (especially for the GUI) and it makes  GUI filter chain
>> configuration possible. It also adds validation code to prevent
>> misconfiguration concerning filter chains. Within the last weeks, I  had to
>> answer security questions and mostly I had to put people off to future
>> versions. Within the last days look at
>>
>>
>> http://sourceforge.net/mailarchive/forum.php?thread_name=20121204140710.98397dymbmve5oji%40webmail.nvoe.at&forum_name=geoserver-users
>>
>> or
>>
>>
>> http://sourceforge.net/mailarchive/forum.php?thread_name=20121204140601.731010nafeocopx5%40webmail.nvoe.at&forum_name=geoserver-users
>>
>> Another fact is that the filter tutorials have to be reworked, because
>> people have problems with them (me too). I have this on my list after GSIP
>> 82, otherwise it does not make sense.
>>
>> Additionally,  CAS works quite will based on GSIP 82. There are two
>> alternatives:
>>
>> 1) Doing a backport and harvest the fruits of our common efforts
>>
>> 2) Avoiding the backport and
>> - telling users to wait on 2.3.x for security configuration concerning
>> authentication mechanisms
>> - removing CAS from the 2.2.x download page
>> - hope that only few admins invest their time in such configurations (we
>> offer it officially , but it does not work)
>>
>> At the end of the day, I would like to backport  and avoid all this
>> questions and time spent (from the users and mine) to get forward.
>>
>> Perhaps I can make your decision easier.  What about 2 commits on master,
>> the first for GSIP-82 and a second for CAS. Then you can have a look at the
>> commit  and decide.
>>
>> Cheers
>> Christian
>>
>>
>> 2012/12/5 Ben Caradoc-Davies <[email protected]>
>>
>>> +0.5 (enthusiastic support combined with my solid lack of understanding
>>> of the security subsystem).
>>>
>>>
>>> On 14/11/12 23:42, Christian Mueller wrote:
>>>
>>>> Please vote on
>>>>
>>>> http://geoserver.org/display/**GEOS/GSIP+82+-+Reworking+**
>>>> security+filter+chains<http://geoserver.org/display/GEOS/GSIP+82+-+Reworking+security+filter+chains>
>>>>
>>>> Thanks to all
>>>> Christian
>>>>
>>>
>>> --
>>> Ben Caradoc-Davies <[email protected]>
>>> Software Engineer
>>> CSIRO Earth Science and Resource Engineering
>>> Australian Resources Research Centre
>>>
>>
>>
>>
>> ------------------------------------------------------------------------------
>> LogMeIn Rescue: Anywhere, Anytime Remote support for IT. Free Trial
>> Remotely access PCs and mobile devices and provide instant support
>> Improve your efficiency, and focus on delivering more value-add services
>> Discover what IT Professionals Know. Rescue delivers
>> http://p.sf.net/sfu/logmein_12329d2d
>> _______________________________________________
>> Geoserver-devel mailing list
>> [email protected]
>> https://lists.sourceforge.net/lists/listinfo/geoserver-devel
>>
>>
>
>
> --
> Justin Deoliveira
> OpenGeo - http://opengeo.org
> Enterprise support for open source geospatial.
>
>
------------------------------------------------------------------------------
LogMeIn Rescue: Anywhere, Anytime Remote support for IT. Free Trial
Remotely access PCs and mobile devices and provide instant support
Improve your efficiency, and focus on delivering more value-add services
Discover what IT Professionals Know. Rescue delivers
http://p.sf.net/sfu/logmein_12329d2d
_______________________________________________
Geoserver-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/geoserver-devel

Reply via email to