Re: [galaxy-dev] [galaxy-user] postgres version 9.0.3

2011-03-19 Thread Dannon Baker
Martin,

There were a few issues with postgres 9 that were fixed in changeset 5074, what 
revision is your galaxy instance running?  If you are running something newer 
than that, could you explain more explicitly the steps to reproduce the server 
error?

Also, I've moved the thread to galaxy-dev since this involves a local instance.

-Dannon



On Mar 19, 2011, at 4:45 AM, Martin Senger wrote:

 Hi,
 
 Our system changed from postgres 8.3 to postgres 9.0.3 - and since I am 
 getting Server error on Galaxy. I am still investigating (because the server 
 error is not there always, specifically it does not occur for an anonymous 
 user) but I wonder if there are some known issues with Galaxy running with 
 postgres  8.3. It would definitely help in my error tracking.
 
 Thanks,
 Martin 
 
 -- 
 Martin Senger
 email: martin.sen...@gmail.com,martin.sen...@kaust.edu.sa
 skype: martinsenger
 ___
 The Galaxy User list should be used for the discussion of
 Galaxy analysis and other features on the public server
 at usegalaxy.org.  Please keep all replies on the list by
 using reply all in your mail client.  For discussion of
 local Galaxy instances and the Galaxy source code, please
 use the Galaxy Development list:
 
  http://lists.bx.psu.edu/listinfo/galaxy-dev
 
 To manage your subscriptions to this and other Galaxy lists,
 please use the interface at:
 
  http://lists.bx.psu.edu/

___
Please keep all replies on the list by using reply all
in your mail client.  To manage your subscriptions to this
and other Galaxy lists, please use the interface at:

  http://lists.bx.psu.edu/


Re: [galaxy-dev] [galaxy-user] postgres version 9.0.3

2011-03-19 Thread Martin Senger
Thanks for an answer and for moving it to the proper mailing list.

There were a few issues with postgres 9 that were fixed in changeset 5074,
 what revision is your galaxy instance running?


I am still running the stable version (galaxy-dist branch). I guess that
with this version I need to stick with the older postgres 8.x. And I will
try now, separately, to use the development version (galaxy-central branch).


  If you are running something newer than that, could you explain more
 explicitly the steps to reproduce the server error?


Even though perhaps there is no need to investigate further - all I need is
to use the fixes introduced in 5074 - but still I am attaching the error I
got. Mainly because it is only my guess that the error was caused by the new
postgres (because it does not occur when I switch back to sqlite).

Thanks,
Martin

URL: http://cluster.cbrc.kaust.edu.sa:8080/tool_runner/index
File
'/home/galaxy/galaxy-dist/eggs/Paste-1.6-py2.5.egg/paste/exceptions/errormiddleware.py',
line 143 in __call__
  app_iter = self.application(environ, start_response)
File
'/home/galaxy/galaxy-dist/eggs/Paste-1.6-py2.5.egg/paste/debug/prints.py',
line 98 in __call__
  environ, self.app)
File '/home/galaxy/galaxy-dist/eggs/Paste-1.6-py2.5.egg/paste/wsgilib.py',
line 539 in intercept_output
  app_iter = application(environ, replacement_start_response)
File '/home/galaxy/galaxy-dist/eggs/Paste-1.6-py2.5.egg/paste/recursive.py',
line 80 in __call__
  return self.application(environ, start_response)
File
'/home/galaxy/galaxy-dist/eggs/Paste-1.6-py2.5.egg/paste/httpexceptions.py',
line 632 in __call__
  return self.application(environ, start_response)
File '/home/galaxy/galaxy-dist/lib/galaxy/web/framework/base.py', line 145
in __call__
  body = method( trans, **kwargs )
File '/home/galaxy/galaxy-dist/lib/galaxy/web/controllers/tool_runner.py',
line 68 in index
  template, vars = tool.handle_input( trans, params.__dict__ )
File '/home/galaxy/galaxy-dist/lib/galaxy/tools/__init__.py', line 933 in
handle_input
  _, out_data = self.execute( trans, incoming=params )
File '/home/galaxy/galaxy-dist/lib/galaxy/tools/__init__.py', line 1225 in
execute
  return self.tool_action.execute( self, trans, incoming=incoming,
set_output_hid=set_output_hid, history=history, **kwargs )
File '/home/galaxy/galaxy-dist/lib/galaxy/tools/actions/__init__.py', line
288 in execute
  data.dbkey = str(input_dbkey)
File '/home/galaxy/galaxy-dist/lib/galaxy/model/__init__.py', line 656 in
set_dbkey
  self.metadata.dbkey = [value]
File '/home/galaxy/galaxy-dist/lib/galaxy/datatypes/metadata.py', line 85 in
__setattr__
  self.parent._metadata[name] = self.spec[name].unwrap( value )
TypeError: 'NoneType' object does not support item assignment


-- 
Martin Senger
email: martin.sen...@gmail.com,martin.sen...@kaust.edu.sa
skype: martinsenger
___
Please keep all replies on the list by using reply all
in your mail client.  To manage your subscriptions to this
and other Galaxy lists, please use the interface at:

  http://lists.bx.psu.edu/

[galaxy-dev] Galaxy prone to XSS and HTML injection attacks

2011-03-19 Thread Paul, Rohit (NIH/NCI) [C]
We recently ran a Nessus vulnerability scan against our server that hosts a 
local installation of Galaxy. The scan report showed that the web application 
is vulnerable to XSS and HTML injection attacks. In order to determine if/when 
these vulnerabilities will be fixed, where should I either send or post the 
scan results?

-Rohit

___
Please keep all replies on the list by using reply all
in your mail client.  To manage your subscriptions to this
and other Galaxy lists, please use the interface at:

  http://lists.bx.psu.edu/

Re: [galaxy-dev] Galaxy prone to XSS and HTML injection attacks

2011-03-19 Thread Dannon Baker
I'd be happy to review the scan results, feel free to send them to me.  I'll 
share it with the rest of the team as well.

Thanks!

-Dannon


On Mar 19, 2011, at 11:37 AM, Paul, Rohit (NIH/NCI) [C] wrote:

 We recently ran a Nessus vulnerability scan against our server that hosts a 
 local installation of Galaxy. The scan report showed that the web application 
 is vulnerable to XSS and HTML injection attacks. In order to determine 
 if/when these vulnerabilities will be fixed, where should I either send or 
 post the scan results?
  
 -Rohit
  
 ___
 Please keep all replies on the list by using reply all
 in your mail client.  To manage your subscriptions to this
 and other Galaxy lists, please use the interface at:
 
  http://lists.bx.psu.edu/

___
Please keep all replies on the list by using reply all
in your mail client.  To manage your subscriptions to this
and other Galaxy lists, please use the interface at:

  http://lists.bx.psu.edu/


[galaxy-dev] DB access and passowrd field

2011-03-19 Thread Bossers, Alex
Hi All,

I have some tools that generate some tabular output. The next step is to 
aggregate the data for some filtering and analysis. In my view the best way to 
do by using a DB (MySQL in my case).

Tools and cmd line wrappers can easily connect to this DB (another database 
than galaxy is using of course) when providing the details for access like 
address:port, username and password.

Is there any way to embed a text field for a galaxy tool that is of type 
password or blinded? Don't want to share user specific login details when 
sharing histories or galaxy pages.Or is this a bad thing to pursue anyway?

Thanks for any directions.
Alex



___
Please keep all replies on the list by using reply all
in your mail client.  To manage your subscriptions to this
and other Galaxy lists, please use the interface at:

  http://lists.bx.psu.edu/