Sorry I was unable to attend; a couple things to discuss post meeting.
1) release schedule; think we are still looking for volunteers, I updated
the schedule to have a later code freeze, and wrote down a geotools 14-M1
release (for when IP issue is resolved)
2) IP issue - got an open IP issues I am still waiting on feedback from;
marked the issue as a blocker (as we should not go to press with some non
open source code in the mix)
Thanks to everyone who reviewed the geoserver dev-guide pull requests;
there were a couple comments that I am not sure were included in the final
result/merge?
--
Jody Garnett
On 7 July 2015 at 16:11, Ben Caradoc-Davies <[email protected]> wrote:
> GeoTools / GeoServer Meeting 2015-07-07
> =======================================
>
> Attending
> ---------
>
> Ben Caradoc-Davies
> Jukka Rahkonen
> Kevin Smith
> Torben Barsballe
>
> Agenda
> ------
>
> - Security
> - Pull requests
> - ESRI WMS cascading problem
>
> Actions
> -------
>
> AA: Create Jira components Security (Authentication) and Security
> (Authorization) to replace Security
>
> Actions from last meeting
> -------------------------
>
> AA: Create Security (Authentication) and Security (Authorization) to
> replace Security [NOT DONE]
> BCD: email user list: "SECURITY: Remote file disclosure vulnerability
> [GEOS-7032]" [DONE]
> BCD: add Vulnerability component to GeoServer Jira [DONE]
>
> Security
> --------
>
> - Discussion about our improved response to vulnerability reports
> - Thanks to Torben for the fix for GEOS-7095!
>
> Pull requests
> -------------
>
> Reviewed and merged:
>
> refresh psc list (GSIP 129)
> https://github.com/geoserver/geoserver/pull/1133
>
> responsible disclosure (GSIP-129)
> https://github.com/geoserver/geoserver/pull/1134
>
> Clarification on our expectations for submitting fixes (GSIP 129)
> https://github.com/geoserver/geoserver/pull/1135
>
> Moved WCS 1.1 schema to GeoTools
> https://github.com/geoserver/geoserver/pull/1129
>
> [GEOS-7095] Fix for exploitable bypass for XXE fix
> https://github.com/geoserver/geoserver/pull/1130
>
> [GEOS-7102] Importer support for non-JDBC databases
> https://github.com/geoserver/geoserver/pull/1136
>
> developers guide tutorial review and cleanup (GSIP-129)
> https://github.com/geoserver/geoserver/pull/1131
>
> ESRI WMS cascading problem
> --------------------------
>
> - Jukka, from the mapserver users list:
>
> ESRI has decided not to follow the standard and has closed the bug,
> NIM104744, we submitted about not decoding a plus symbol ‘+’ to a space.
> Their solution is for everyone else to encode all spaces as %20 and to
> ignore http://tools.ietf.org/html/rfc3986. They have closed the bug and
> listed it as a known limit.
>
> http://support.esri.com/en/bugs/nimbus/TklNMTA0NzQ0
>
> So, in order for Mapserver to consume ESRI WMS services, with spaces in
> the name, the spaces have to be encoded as %20.
>
> - Jukka noted that this can cause problems with cascading WMS
> - Ben suggested adding a note to the user guide
>
>
> --
> Ben Caradoc-Davies <[email protected]>
> Director
> Transient Software Limited <http://transient.nz/>
> New Zealand
>
>
> ------------------------------------------------------------------------------
> Don't Limit Your Business. Reach for the Cloud.
> GigeNET's Cloud Solutions provide you with the tools and support that
> you need to offload your IT needs and focus on growing your business.
> Configured For All Businesses. Start Your Cloud Today.
> https://www.gigenetcloud.com/
> _______________________________________________
> GeoTools-Devel mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/geotools-devel
>
------------------------------------------------------------------------------
Don't Limit Your Business. Reach for the Cloud.
GigeNET's Cloud Solutions provide you with the tools and support that
you need to offload your IT needs and focus on growing your business.
Configured For All Businesses. Start Your Cloud Today.
https://www.gigenetcloud.com/
_______________________________________________
GeoTools-Devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/geotools-devel