Re: Missing State/Province

2018-10-05 Thread Pierre Smits
Hi Wolfgang,

Please open a JIRA ticket.

On Fri, 5 Oct 2018 at 16:46 wp.rauchh...@gmail.com 
wrote:

> The State/Provinces for Spain are missing.
> When entering a new address the system shows "No States/Provinces exist"
> I like to add a list of the autonomous regions in several languages to
> standard ofibz.
> How is this been done?
>
> Thanks, Wolfgang
>
>
> --
Sent from my phone


Missing State/Province

2018-10-05 Thread wp . rauchholz
The State/Provinces for Spain are missing.
When entering a new address the system shows "No States/Provinces exist"
I like to add a list of the autonomous regions in several languages to standard 
ofibz. 
How is this been done?

Thanks, Wolfgang




Re: iCalendar integration not working

2018-10-05 Thread jler...@apache.org

Hi Jyri,

Thanks for your detailed report, it's fixed with 
https://issues.apache.org/jira/browse/OFBIZ-10595

So you need to apply a patch if you want to use the last R16 release

HTH

Jacques


Le 03/10/2018 à 15:26, Jyri Sillanpaa a écrit :


Hi Jacques,

Right click on Thunderbird Calendar tab's left hand side:
New Calendar -> On the Network, Next -> Location: 
https://demo-stable.ofbiz.apache.org/iCalendar/CALENDAR_PUB_DEMO/
, Next -> Name: OFBiz 16.11 Demo, Next -> Finish.
Right click the new calendar -> Synchronize Calendars.

There should be entry for STAFF_MTG Staff Meeting for Monday 01/10/18 but it is 
not shown.

Try to create new calendar event and you will receive the error An error occurred when writing to the calendar (it will not even ask username and 
password).



Best

Jyri

On 03/10/2018 14:49, Jacques Le Roux wrote:

Hi Jyri,

In order to easily reproduce, please give us more details (exact steps) on how 
you

    "copied the DEMO iCalendar URL and pasted it to Lightning's new calendar 
creation window."

Note: I use Thunderbird and have the Lightning addon installed

Thanks

Jacques


Le 03/10/2018 à 12:08, Jyri Sillanpaa a écrit :

Hello Jacques,

Sorry to hear about that.


Your help is greatly appreciated!


Thanks

Jyri

On 03/10/2018 11:53, Jacques Le Roux wrote:

Hi Jyri,

Unfortunately the specialist on this question (Adrian Crum) passed away in end 
of , hence no answer since you asked

Nevertheless, I'll have a look ASAP...

Cheers

Jacques


Le 27/09/2018 à 11:26, Jyri Sillanpaa a écrit :

Hello,

I am trying to access the OFBiz iCalendar with Thunderbird Lightning so I set up 16.11.04 and loaded demo data, copied the DEMO iCalendar URL 
and pasted it to Lightning's new calendar creation window.


I see no the calendar entries in the new calendar in Lightning and when I try to create new entry I get an error message with Error code 
MODIFICATION_FAILED(user name and password are not asked at all) and the calendar is put on read only mode.


This is what I get on the gradlew ofbiz console:

2018-09-27 11:00:20,660 |jsse-nio-8443-exec-3 |ControlFilter |I| [Filtered 
request]: /iCalendar/CALENDAR_PUB_DEMO/ --> /control/main
2018-09-27 11:00:20,715 |sse-nio-8443-exec-10 |ControlEventListener     |I| 
Creating session:  hidden sessionId by default.
2018-09-27 11:00:20,716 |sse-nio-8443-exec-10 |ICalHandlerFactory |I| 
[GetHandler] starting request
2018-09-27 11:00:20,716 |sse-nio-8443-exec-10 |ICalWorker |I| 
[handleGetRequest] workEffortId = control
2018-09-27 11:00:20,716 |sse-nio-8443-exec-10 |ICalConverter |I| WorkEffort 
calendar is not published: control
2018-09-27 11:00:20,716 |sse-nio-8443-exec-10 |ICalHandlerFactory |I| 
[GetHandler] finished request
2018-09-27 11:00:20,716 |sse-nio-8443-exec-10 |ControlEventListener     |W| Could not find visit value object in session [ hidden sessionId by 
default.] that is being destroyed

2018-09-27 11:00:20,716 |sse-nio-8443-exec-10 |ControlEventListener     |I| 
Destroying session:  hidden sessionId by default.


I tried with the latest trunk and have the same problem (the online demos for 
the trunk and 16.11 also have the same problem).

The online demo of 13.07 works as expected as well as the 13.07.03 I downloaded.

Is this an configuration issue or has the iCalendar integration been broken?


Best regards

Jyri












[SECURITY] CVE-2011-3600 Apache OFBiz XML-RPC XXE Vulnerability

2018-10-05 Thread Taher Alkhateeb

Severity:
Important

Vendor:
The Apache Software Foundation

Versions Affected:
OFBiz 16.11.01 to 16.11.04

Description:
The OFBiz XML-RPC event handler 
(org.apache.ofbiz.webapp.event.XmlRpcEventHandler.java)
acts as a wrapper for any OFBiz service that provides XML-RPC web 
services via

the /webtools/control/xmlrpc endpoint. This endpoint is exposed to External
Entity Injection by passing DOCTYPE declarations with executable 
payloads that
discloses the contents of files in the filesystem. In addition, it can 
also be

used to probe for open network ports, and figure out from returned error
messages whether a file exists or not.

Mitigation:
Upgrade to 16.11.05
or manually apply the following commits on branch 16
r1833724
r1833708
r1836141

Example:
# Payload to find an exposed port

http://localhost:8080;>

    ping


# Payload to display file contents


]>

    


Credit:
James Parfet 

References:
http://ofbiz.apache.org/download.html#vulnerabilities



[ANNOUNCE] Apache OFBiz 16.11.05 released

2018-10-05 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache
OFBiz 16.11.05".

Apache OFBiz® is an open source product for the automation of enterprise
processes that includes framework components and business applications.

http://ofbiz.apache.org/

"Apache OFBiz 16.11.05" is the latest and greatest release of OFBiz; for
more details of the changes introduced with this new version please refer
to http://ofbiz.apache.org/release-notes-16.11.05.html

The release file can be downloaded following the instructions in the OFBiz
download page:

http://ofbiz.apache.org/download.html

The OFBiz community.


Re: Creating product packs

2018-10-05 Thread Wolfgang Paul Rauchholz
That explains it Thank you.

Wolfgang

On Fri, Oct 5, 2018 at 8:38 AM Pritam Kute 
wrote:

> Hi,
>
> As I said in my previous email, it is just a UI layer problem. There is no
> out of the box UI available on e-commerce for displaying the components of
> the kit product. You need a little bit of customization in the code for
> displaying those components on the product details page.
>
> Thanks and Regards
> --
> Pritam Kute
>
>
> On Thu, Oct 4, 2018 at 8:48 PM Wolfgang Paul Rauchholz <
> wp.rauchh...@gmail.com> wrote:
>
> > I don’t know what I am missing. This is my setup.
> >
> > Part number for the pack / basket:
> > PACK7: defined as Marketing Package: Auto Manufactured (I tried also the
> > Assembly type)
> >
> > Part number products
> > 1000, 1001 and 1002 defined as Finished Good
> >
> > In Tab ASSOCIATION of PACK7 I tried all possible scenarios:
> >
> > Swapping Product ID and Product IT to. Trying several different
> association
> > types.
> >
> > On e-Commerce page, when clicking PACK7 and ofbiz drills down to the
> > product detail page, I do not see the products 100, 1001, 1002 (the
> > contentt of the pack).
> >
> >
> >
> > What am I doing wrong?
> >
> >
> >
> > On Thu, Oct 4, 2018 at 12:30 PM Pritam Kute <
> pritam.k...@hotwaxsystems.com
> > >
> > wrote:
> >
> > > Whatever I can learn from the explanation you have provided, it is
> just a
> > > UI layer you are talking about. Like you just need to show individual
> > > servings to the customer under a particular product pack. There is no
> any
> > > requirement of modifying/deleting of any servings.
> > >
> > > If this is the case, then the marketing package can be exploded using
> the
> > > associations created in "ProductAssoc" entity. I recommend you to go
> > > through the demo data of GZ-BASKET. It will clear all your questions.
> > >
> > > Thanks and Regards
> > > --
> > > Pritam Kute
> > >
> > >
> > > On Thu, Oct 4, 2018 at 3:17 PM Wolfgang Paul Rauchholz <
> > > wp.rauchh...@gmail.com> wrote:
> > >
> > > > Thanks for responses.
> > > > To you question what do you mean by "open the pack and see what is
> > > inside".
> > > > On the e-Commerce page the Customer will pick the product pack that
> is
> > > > composed of 7 servings, from Monday to Sunday. The Customer wants to
> > see
> > > > the individual servings inside the pack.
> > > > In other word, the Customer should be able to 'explode' the pack into
> > its
> > > > individual products.
> > > >
> > > >
> > > > On Thu, Oct 4, 2018 at 11:39 AM Pritam Kute <
> > > pritam.k...@hotwaxsystems.com
> > > > >
> > > > wrote:
> > > >
> > > > > Please see my comments inline.
> > > > >
> > > > > Thanks and Regards
> > > > > --
> > > > > Pritam Kute
> > > > >
> > > > >
> > > > > On Thu, Oct 4, 2018 at 2:19 PM wp.rauchh...@gmail.com <
> > > > > wp.rauchh...@gmail.com> wrote:
> > > > >
> > > > > > How to best setup a pack in ofbiz?
> > > > > > With pack I mean a product (e.g. a pack for 7 days of food
> > servings)
> > > > that
> > > > > > includes in this example 7 individual servings. Each of these
> > > servings
> > > > > > could be sold individually too.
> > > > > >
> > > > >
> > > > > Yes. This is a best case for Marketing Package. See the defination
> of
> > > > > marketing package here
> > > > > https://cwiki.apache.org/confluence/display/OFBENDUSER/Products
> > > > >
> > > > > The price is set for the pack, but the Customer should have the
> > > > possibility
> > > > > > on e-Commerce to open the pack and see what is inside.
> > > > > >
> > > > >
> > > > > Price can be set for the complete set in marketing package type
> > > product.
> > > > > Can you please ellaborate more about the line "open the pack and
> see
> > > what
> > > > > is inside". Like do they just need to see the package content or
> they
> > > can
> > > > > change some packs from the already built package?
> > > > >
> > > > >
> > > > > > The pack is either defined or can be configured.
> > > > > >
> > > > >
> > > > > IMO, defined pakages can be created by using marketing package
> > concept
> > > > > directly but for configured package, you should go for configurable
> > > > product
> > > > > setup.
> > > > >
> > > > >
> > > > > > Is this a case where 'Marketing Package' is used?
> > > > > >
> > > > > > Thanks, Wolfgang
> > > > > >
> > > > > >
> > > > >
> > > >
> > > >
> > > > --
> > > >
> > > > Wolfgang Rauchholz
> > > >
> > >
> >
> >
> > --
> >
> > Wolfgang Rauchholz
> >
>


-- 

Wolfgang Rauchholz


Re: Creating product packs

2018-10-05 Thread Pritam Kute
Hi,

As I said in my previous email, it is just a UI layer problem. There is no
out of the box UI available on e-commerce for displaying the components of
the kit product. You need a little bit of customization in the code for
displaying those components on the product details page.

Thanks and Regards
--
Pritam Kute


On Thu, Oct 4, 2018 at 8:48 PM Wolfgang Paul Rauchholz <
wp.rauchh...@gmail.com> wrote:

> I don’t know what I am missing. This is my setup.
>
> Part number for the pack / basket:
> PACK7: defined as Marketing Package: Auto Manufactured (I tried also the
> Assembly type)
>
> Part number products
> 1000, 1001 and 1002 defined as Finished Good
>
> In Tab ASSOCIATION of PACK7 I tried all possible scenarios:
>
> Swapping Product ID and Product IT to. Trying several different association
> types.
>
> On e-Commerce page, when clicking PACK7 and ofbiz drills down to the
> product detail page, I do not see the products 100, 1001, 1002 (the
> contentt of the pack).
>
>
>
> What am I doing wrong?
>
>
>
> On Thu, Oct 4, 2018 at 12:30 PM Pritam Kute  >
> wrote:
>
> > Whatever I can learn from the explanation you have provided, it is just a
> > UI layer you are talking about. Like you just need to show individual
> > servings to the customer under a particular product pack. There is no any
> > requirement of modifying/deleting of any servings.
> >
> > If this is the case, then the marketing package can be exploded using the
> > associations created in "ProductAssoc" entity. I recommend you to go
> > through the demo data of GZ-BASKET. It will clear all your questions.
> >
> > Thanks and Regards
> > --
> > Pritam Kute
> >
> >
> > On Thu, Oct 4, 2018 at 3:17 PM Wolfgang Paul Rauchholz <
> > wp.rauchh...@gmail.com> wrote:
> >
> > > Thanks for responses.
> > > To you question what do you mean by "open the pack and see what is
> > inside".
> > > On the e-Commerce page the Customer will pick the product pack that is
> > > composed of 7 servings, from Monday to Sunday. The Customer wants to
> see
> > > the individual servings inside the pack.
> > > In other word, the Customer should be able to 'explode' the pack into
> its
> > > individual products.
> > >
> > >
> > > On Thu, Oct 4, 2018 at 11:39 AM Pritam Kute <
> > pritam.k...@hotwaxsystems.com
> > > >
> > > wrote:
> > >
> > > > Please see my comments inline.
> > > >
> > > > Thanks and Regards
> > > > --
> > > > Pritam Kute
> > > >
> > > >
> > > > On Thu, Oct 4, 2018 at 2:19 PM wp.rauchh...@gmail.com <
> > > > wp.rauchh...@gmail.com> wrote:
> > > >
> > > > > How to best setup a pack in ofbiz?
> > > > > With pack I mean a product (e.g. a pack for 7 days of food
> servings)
> > > that
> > > > > includes in this example 7 individual servings. Each of these
> > servings
> > > > > could be sold individually too.
> > > > >
> > > >
> > > > Yes. This is a best case for Marketing Package. See the defination of
> > > > marketing package here
> > > > https://cwiki.apache.org/confluence/display/OFBENDUSER/Products
> > > >
> > > > The price is set for the pack, but the Customer should have the
> > > possibility
> > > > > on e-Commerce to open the pack and see what is inside.
> > > > >
> > > >
> > > > Price can be set for the complete set in marketing package type
> > product.
> > > > Can you please ellaborate more about the line "open the pack and see
> > what
> > > > is inside". Like do they just need to see the package content or they
> > can
> > > > change some packs from the already built package?
> > > >
> > > >
> > > > > The pack is either defined or can be configured.
> > > > >
> > > >
> > > > IMO, defined pakages can be created by using marketing package
> concept
> > > > directly but for configured package, you should go for configurable
> > > product
> > > > setup.
> > > >
> > > >
> > > > > Is this a case where 'Marketing Package' is used?
> > > > >
> > > > > Thanks, Wolfgang
> > > > >
> > > > >
> > > >
> > >
> > >
> > > --
> > >
> > > Wolfgang Rauchholz
> > >
> >
>
>
> --
>
> Wolfgang Rauchholz
>