[ANNOUNCE] Apache OFBiz 18.12.13 released

2024-05-07 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache
OFBiz 18.12.13".

Apache OFBiz® is an open source product for the automation of enterprise
processes that includes framework components and business applications.

http://ofbiz.apache.org/

"Apache OFBiz 18.12.13" is the 13th release of the 18.12 series.

For details of the changes introduced with this new version
please refer to http://ofbiz.apache.org/release-notes-18.12.13.html

The history of security related fixes included in each release is
available here:
https://ofbiz.apache.org/security.html

The release files can be downloaded following the instructions in the OFBiz
download page:

http://ofbiz.apache.org/download.html


[ANNOUNCE] Apache OFBiz 18.12.12 released

2024-02-28 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache
OFBiz 18.12.12".

Apache OFBiz® is an open source product for the automation of enterprise
processes that includes framework components and business applications.

http://ofbiz.apache.org/

"Apache OFBiz 18.12.12" is the twelfth release of the 18.12 series.

For details of the changes introduced with this new version
please refer to http://ofbiz.apache.org/release-notes-18.12.12.html

The history of security related fixes included in each release is
available here:
https://ofbiz.apache.org/security.html

The release files can be downloaded following the instructions in the OFBiz
download page:

http://ofbiz.apache.org/download.html


[ANNOUNCE] Apache OFBiz 18.12.11 released

2023-12-21 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache
OFBiz 18.12.11".

Apache OFBiz® is an open source product for the automation of enterprise
processes that includes framework components and business applications.

http://ofbiz.apache.org/

"Apache OFBiz 18.12.11" is the eleventh release of the 18.12 series.

For details of the changes introduced with this new version
please refer to http://ofbiz.apache.org/release-notes-18.12.11.html

The history of security related fixes included in each release is
available here:
https://ofbiz.apache.org/security.html

The release files can be downloaded following the instructions in the OFBiz
download page:

http://ofbiz.apache.org/download.html


[ANNOUNCE] Apache OFBiz 18.12.10 released

2023-12-04 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache
OFBiz 18.12.10".

Apache OFBiz® is an open source product for the automation of enterprise
processes that includes framework components and business applications.

http://ofbiz.apache.org/

"Apache OFBiz 18.12.10" is the tenth release of the 18.12 series.

For details of the changes introduced with this new version
please refer to http://ofbiz.apache.org/release-notes-18.12.10.html

The history of security related fixes included in each release is
available here:
https://ofbiz.apache.org/security.html

The release files can be downloaded following the instructions in the OFBiz
download page:

http://ofbiz.apache.org/download.html


[ANNOUNCE] Apache OFBiz 18.12.09 released

2023-11-05 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache
OFBiz 18.12.09".

Apache OFBiz® is an open source product for the automation of enterprise
processes that includes framework components and business applications.

http://ofbiz.apache.org/

"Apache OFBiz 18.12.09" is the ninth release of the 18.12 series.

For details of the changes introduced with this new version
please refer to http://ofbiz.apache.org/release-notes-18.12.09.html

The history of security related fixes included in each release is
available here:
https://ofbiz.apache.org/security.html

The release files can be downloaded following the instructions in the OFBiz
download page:

http://ofbiz.apache.org/download.html


[ANNOUNCE] Apache OFBiz 18.12.08 released

2023-06-01 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache
OFBiz 18.12.08".

Apache OFBiz® is an open source product for the automation of enterprise
processes that includes framework components and business applications.

http://ofbiz.apache.org/

"Apache OFBiz 18.12.08" is the eighth and final release of the 18.12 series.

For details of the changes introduced with this new version
please refer to http://ofbiz.apache.org/release-notes-18.12.08.html

The history of security related fixes included in each release is
available here:
https://ofbiz.apache.org/security.html

The release files can be downloaded following the instructions in the OFBiz
download page:

http://ofbiz.apache.org/download.html


[ANNOUNCE] Apache OFBiz 18.12.07 released

2023-04-10 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache
OFBiz 18.12.07".

Apache OFBiz® is an open source product for the automation of enterprise
processes that includes framework components and business applications.

http://ofbiz.apache.org/

"Apache OFBiz 18.12.07" is the seventh and final release of the 18.12
series.

For details of the changes introduced with this new version
please refer to http://ofbiz.apache.org/release-notes-18.12.07.html

The history of security related fixes included in each release is
available here:
https://ofbiz.apache.org/security.html

The release files can be downloaded following the instructions in the OFBiz
download page:

http://ofbiz.apache.org/download.html


[ANNOUNCE] Apache OFBiz 18.12.06 released

2022-09-01 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache
OFBiz 18.12.06".

Apache OFBiz® is an open source product for the automation of enterprise
processes that includes framework components and business applications.

http://ofbiz.apache.org/

"Apache OFBiz 18.12.06" is the sixth and final release of the 18.12 series.

For details of the changes introduced with this new version
please refer to http://ofbiz.apache.org/release-notes-18.12.06.html

The history of security related fixes included in each release is
available here:
https://ofbiz.apache.org/security.html

The release files can be downloaded following the instructions in the OFBiz
download page:

http://ofbiz.apache.org/download.html


Re: Apache Shiro Error Message

2022-02-08 Thread Jacopo Cappellato
Hi Serge,

It seems like a problem happening when OFBiz tries to decrypt the value of
the fields finAccountCode and finAccountPin (in the FinAccount entity),
that are stored encrypted.
Did you migrate your FinAccount data from a different instance?

Regards,

Jacopo


On Tue, Feb 8, 2022 at 11:22 AM Bs Serge  wrote:

> I found this line the stack trace,
>
> Caused by: javax.crypto.BadPaddingException: Given final block not properly
> padded. Such issues can arise if a bad key is used during decryption.
>
> Full Stack Trace :
>
>
> https://paste.0xfc.de/?855ddf22ba0fbef4#Ef5Fom4VnGfb2XGvNEfK22A8AP5jt5KRMkuhSs4KuCeX
>
> Best regards,
>
> On Mon, Feb 7, 2022 at 10:45 PM Bs Serge  wrote:
>
> > Hi all,
> >
> > Ofbiz 17.12,
> > Postgres Database,
> >
> > I'm getting this error when I try to find financial accounts in the UI
> and
> > I'm not familiar with Apache Shiro. So I'm wondering what could be the
> > reason for this?
> >
> > Any thoughts or comments would be appreciated!
> >
> > java.lang.IllegalArgumentException: Error running script at location
> > [component://webtools/groovyScripts/entity/FindGeneric.groovy]:
> > org.apache.ofbiz.base.util.GeneralRuntimeException: Error creating
> > GenericValue (org.apache.shiro.crypto.CryptoException: Unable to execute
> > 'doFinal' with cipher instance [javax.crypto.Cipher@205e8e3d]. (Unable
> to
> > execute 'doFinal' with cipher instance [javax.crypto.Cipher@205e8e3d].))
> >
> > Best Regards,
> >
>


[ANNOUNCE] Apache OFBiz 18.12.05 released

2022-01-04 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache
OFBiz 18.12.05".

Apache OFBiz® is an open source product for the automation of enterprise
processes that includes framework components and business applications.

http://ofbiz.apache.org/

"Apache OFBiz 18.12.05" is the fifth release of the 18.12 series.

For details of the changes introduced with this new version
please refer to http://ofbiz.apache.org/release-notes-18.12.05.html

The history of security related fixes included in each release is
available here:
https://ofbiz.apache.org/security.html

The release files can be downloaded following the instructions in the OFBiz
download page:

http://ofbiz.apache.org/download.html


[ANNOUNCE] Apache OFBiz 18.12.04 released

2021-12-20 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache
OFBiz 18.12.04".

Apache OFBiz® is an open source product for the automation of enterprise
processes that includes framework components and business applications.

http://ofbiz.apache.org/

"Apache OFBiz 18.12.04" is the fourth release of the 18.12 series.

For details of the changes introduced with this new version
please refer to http://ofbiz.apache.org/release-notes-18.12.04.html

The release file can be downloaded following the instructions in the OFBiz
download page:

http://ofbiz.apache.org/download.html


[ANNOUNCE] Apache OFBiz 18.12.03 released

2021-12-13 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache
OFBiz 18.12.03".

Apache OFBiz® is an open source product for the automation of enterprise
processes that includes framework components and business applications.

http://ofbiz.apache.org/

"Apache OFBiz 18.12.03" is the third release of the 18.12 series.

For more details of the changes introduced with this new version
please refer to http://ofbiz.apache.org/release-notes-18.12.03.html

The release file can be downloaded following the instructions in the OFBiz
download page:

http://ofbiz.apache.org/download.html


[ANNOUNCE] Apache OFBiz 18.12.02 released

2021-11-24 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache
OFBiz 18.12.02".

Apache OFBiz® is an open source product for the automation of enterprise
processes that includes framework components and business applications.

http://ofbiz.apache.org/

"Apache OFBiz 18.12.02" is the second release of the 18.12 series.

For more details of the changes introduced with this new version
please refer to http://ofbiz.apache.org/release-notes-18.12.02.html

The release file can be downloaded following the instructions in the OFBiz
download page:

http://ofbiz.apache.org/download.html


[ANNOUNCE] Apache OFBiz 18.12.01 released

2021-10-29 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache
OFBiz 18.12.01".

Apache OFBiz® is an open source product for the automation of enterprise
processes that includes framework components and business applications.

http://ofbiz.apache.org/

"Apache OFBiz 18.12.01" is the first release of the 18.12 series.

For more details of the changes introduced with this new version
please refer to http://ofbiz.apache.org/release-notes-18.12.01.html

The release file can be downloaded following the instructions in the OFBiz
download page:

http://ofbiz.apache.org/download.html

The OFBiz community.


[ANNOUNCE] Apache OFBiz 17.12.08 released

2021-08-11 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache
OFBiz 17.12.08".

Apache OFBiz® is an open source product for the automation of enterprise
processes that includes framework components and business applications.

http://ofbiz.apache.org/

"Apache OFBiz 17.12.08" is the eighth release of the 17.12 series and
probably the last release in this series; in the future releases will
be published from the newer series, which is 18.12.

For more details of the changes introduced with this new version
please refer to http://ofbiz.apache.org/release-notes-17.12.08.html

The release file can be downloaded following the instructions in the OFBiz
download page:

http://ofbiz.apache.org/download.html

The OFBiz community.


[ANNOUNCE] Apache OFBiz 17.12.07 released

2021-04-27 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache
OFBiz 17.12.07".

Apache OFBiz® is an open source product for the automation of enterprise
processes that includes framework components and business applications.

http://ofbiz.apache.org/

"Apache OFBiz 17.12.07" is the seventh release of the 17.12 series and
probably the last release in this series; in the future releases will
be published from the newer series, which is 18.12.

For more details of the changes introduced with this new version
please refer to http://ofbiz.apache.org/release-notes-17.12.07.html

The release file can be downloaded following the instructions in the OFBiz
download page:

http://ofbiz.apache.org/download.html

The OFBiz community.


[ANNOUNCE] Apache OFBiz 17.12.06 released

2021-03-21 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache
OFBiz 17.12.06".

Apache OFBiz® is an open source product for the automation of enterprise
processes that includes framework components and business applications.

http://ofbiz.apache.org/

"Apache OFBiz 17.12.06" is the sixth release of the 17.12 series and
probably the last release in this series; in the future releases will
be published from the newer series, which is 18.12.

For more details of the changes introduced with this new version
please refer to http://ofbiz.apache.org/release-notes-17.12.06.html

The release file can be downloaded following the instructions in the OFBiz
download page:

http://ofbiz.apache.org/download.html

The OFBiz community.


[ANNOUNCE] Apache OFBiz 17.12.05 released

2021-01-12 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache
OFBiz 17.12.05".

Apache OFBiz® is an open source product for the automation of enterprise
processes that includes framework components and business applications.

http://ofbiz.apache.org/

"Apache OFBiz 17.12.05" is the fifth release of the 17.12 series and
probably the last release in this series; in the future releases will
be published from the newer series, which is 18.12.

For more details of the changes introduced with this new version
please refer to http://ofbiz.apache.org/release-notes-17.12.05.html

The release file can be downloaded following the instructions in the OFBiz
download page:

http://ofbiz.apache.org/download.html

The OFBiz community.


[ANNOUNCE] Apache OFBiz 17.12.04 release

2020-07-15 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache
OFBiz 17.12.04".

Apache OFBiz® is an open source product for the automation of enterprise
processes that includes framework components and business applications.

http://ofbiz.apache.org/

"Apache OFBiz 17.12.04" is the fourth release of the 17.12 series; for more
details of the changes introduced with this new version please refer to
http://ofbiz.apache.org/release-notes-17.12.04.html

The release file can be downloaded following the instructions in the OFBiz
download page:

http://ofbiz.apache.org/download.html

The OFBiz community.


[ANNOUNCE] Apache OFBiz 17.12.03 release

2020-04-29 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache
OFBiz 17.12.03".

Apache OFBiz® is an open source product for the automation of enterprise
processes that includes framework components and business applications.

http://ofbiz.apache.org/

"Apache OFBiz 17.12.03" is the third release of the 17.12 series (the
release 17.12.02 was never announced because it had a build issue); for
more details of the changes introduced with this new version please refer
to http://ofbiz.apache.org/release-notes-17.12.03.html

The release file can be downloaded following the instructions in the OFBiz
download page:

http://ofbiz.apache.org/download.html

The OFBiz community.


[CVE-2020-1943] Apache OFBiz XSS Vulnerability

2020-03-06 Thread Jacopo Cappellato
Severity:
Important

Vendor:
The Apache Software Foundation

Versions Affected:
OFBiz 16.11.01 to 16.11.07

Description:
Data sent with "contentId" to "/control/stream" is not sanitized, allowing
XSS attacks.

Mitigation:
Upgrade to 17.12.01 or manually apply the commits at OFBIZ-10753


Credit:
Timon Funck 

References:
http://ofbiz.apache.org/download.html#vulnerabilities


[ANNOUNCE] Apache OFBiz 17.12.01 release

2020-03-06 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache
OFBiz 17.12.01".

Apache OFBiz® is an open source product for the automation of enterprise
processes that includes framework components and business applications.

http://ofbiz.apache.org/

"Apache OFBiz 17.12.01" is the latest release of OFBiz and is the first of
the 17.12 series that supersedes the 16.11 release branch; for more details
of the changes introduced with this new version please refer to
http://ofbiz.apache.org/release-notes-17.12.01.html

The release file can be downloaded following the instructions in the OFBiz
download page:

http://ofbiz.apache.org/download.html

The OFBiz community.


Re: About your contributions to the OFBiz project

2020-03-05 Thread Jacopo Cappellato
Hello Mathieu,

On Thu, Mar 5, 2020 at 8:12 PM Mathieu Lirzin 
wrote:

> Hello Jacopo,
> [...]
> Am I supposed to be the “someone”?
>
> If yes, I would have rather preferred that you expressed your
> disagreement with my point of view either directly or on the public
> mailing list instead [...]


I think you are over-reacting because the goal of my message to Daniel was
not that of criticizing your, or anyone else, but rather to acknowledge his
valuable contributions and involvement with the community and encourage him
to keep a positive attitude even in case of disagreement.


> Don't know if it was intentional or not, but thank you Daniel for
> sharing.
>

It happened because I have set my Apache email with a reply-to address to
the users list, because I use it to announce releases with that in public
lists; no one was trying to put anyone in a bad spot.

Best regards,

Jacopo


[SECURITY] CVE-2019-12426 information disclosure vulnerability in Apache OFBiz

2020-02-06 Thread Jacopo Cappellato
Severity:
Minor

Vendor:
The Apache Software Foundation

Versions Affected:
Apache OFBiz 16.11.01 to 16.11.06

Description:
an unauthenticated user could get access to information of some backend
screens by invoking setSessionLocale.

Mitigation:
Upgrade to 16.11.07

Credit:
This issue was discovered by Dennis Balkir .

References:
http://ofbiz.apache.org/security.html


[ANNOUNCE] Apache OFBiz 16.11.07 released

2020-02-06 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache
OFBiz 16.11.07".

Apache OFBiz® is an open source product for the automation of enterprise
processes that includes framework components and business applications.

http://ofbiz.apache.org/

"Apache OFBiz 16.11.07" is the latest release of OFBiz and it is probably
going to be the last one in the 16.11 series; for more details of the
changes introduced with this new version please refer to
http://ofbiz.apache.org/release-notes-16.11.07.html

The release file can be downloaded following the instructions in the OFBiz
download page:

http://ofbiz.apache.org/download.html

The OFBiz community.


[CVE-2019-10073] Apache OFBiz XSS vulnerability in the "ecommerce" component

2019-09-10 Thread Jacopo Cappellato
Severity:
Important

Vendor:
The Apache Software Foundation

Versions Affected:
OFBiz 16.11.01 to 16.11.05

Description:
The "Blog", "Forum", "Contact Us" screens of the template "ecommerce"
application bundled in Apache OFBiz are weak to Stored XSS attacks.

Mitigation:
Upgrade to 16.11.06
or manually apply the following commits on branch 16.11:
1858438, 1858543, 1860595 and 1860616


Credit:
Vikash Patnaik 
Dinesh Kumar Mohanty 

References:
http://ofbiz.apache.org/download.html#vulnerabilities


[CVE-2018-17200] Apache OFBiz unauthenticated remote code execution vulnerability in HttpEngine

2019-09-10 Thread Jacopo Cappellato
Severity:
Important

Vendor:
The Apache Software Foundation

Versions Affected:
OFBiz 16.11.01 to 16.11.05

Description:
The OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java)
handles requests for HTTP services via the /webtools/control/httpService
endpoint.  This service takes the `serviceContent` parameter in the request
and
 deserializes it using XStream. This `XStream` instance is slightly guarded
by
 disabling the creation of `ProcessBuilder`.  However, this can be easily
 bypassed (and in multiple ways).

Mitigation:
Upgrade to 16.11.06
or manually apply the following commits on branch 16
r1850017+1850019


Credit:
Man Yue Mo of the Semmle Security Research Team
张剑 

References:
http://ofbiz.apache.org/download.html#vulnerabilities


[CVE-2019-0189] Apache OFBiz remote code execution and arbitrary file delete via Java deserialization

2019-09-10 Thread Jacopo Cappellato
Severity:
Important

Vendor:
The Apache Software Foundation

Versions Affected:
OFBiz 16.11.01 to 16.11.05

Description:
The java.io.ObjectInputStream is known to cause Java serialisation issues.
This issue here is exposed by the "webtools/control/httpService" URL,
and uses Java deserialization to perform code execution.
In the HttpEngine, the value of the request parameter "serviceContext"
is passed to the "deserialize" method of "XmlSerializer".

Ofbiz is affected via two different dependencies:
"commons-beanutils" and an out-dated version of "commons-fileupload"

Mitigation:
Upgrade to 16.11.06
or manually apply the commits from
OFBIZ-10770 AND OFBIZ-10837 on branch 16


Credit:
Man Yue Mo of the Semmle Security Research Team
ricterzheng(郑杜涛) 

References:
http://ofbiz.apache.org/download.html#vulnerabilities


[CVE-2019-10074] Apache OFBiz RCE (template injection)

2019-09-10 Thread Jacopo Cappellato
Severity:
Important

Vendor:
The Apache Software Foundation

Versions Affected:
OFBiz 16.11.01 to 16.11.05

An RCE is possible by entering Freemarker markup in an OFBiz Form Widget
textarea field when encoding has been disabled on such a field.  This was
the case for the Customer Request "story" input in the Order Manager
application.  Encoding should not be disabled without good reason and never
within a field that accepts user input.


Mitigation:
Upgrade to 16.11.06
or manually apply the following commit on branch 16.11:
r1858533


Credit:
Niels Heinen of the Google security team 

References:
http://ofbiz.apache.org/download.html#vulnerabilities


[ANNOUNCE] Apache OFBiz 16.11.06 released

2019-09-10 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache
OFBiz 16.11.06".

Apache OFBiz® is an open source product for the automation of enterprise
processes that includes framework components and business applications.

http://ofbiz.apache.org/

"Apache OFBiz 16.11.06" is the latest and greatest release of OFBiz; for
more details of the changes introduced with this new version please refer
to http://ofbiz.apache.org/release-notes-16.11.06.html

The release file can be downloaded following the instructions in the OFBiz
download page:

http://ofbiz.apache.org/download.html

The OFBiz community.


Re: OFBiz at ApacheCon North America, Las Vegas

2019-05-26 Thread Jacopo Cappellato
Hi Pierre,

yes, we are aware of this. In fact if you are interested in submitting a
proposal please send it to the OFBiz PMC as mentioned in my first email [*].

Thank you,

Jacopo

[*] "please submit your proposal [..] to the OFBiz PMC by writing an email
to priv...@ofbiz.apache.org."


On Sun, May 26, 2019 at 9:55 AM Pierre Smits  wrote:

> Hi Jacopo,
> The site states:
>
> The Call for Papers is currently not open. New submissions cannot be made,
> and existing submissions can only be edited by the event managers.
>
>
> Best regards,
>
> Pierre Smits
>
> *Apache Trafodion <https://trafodion.apache.org>, Vice President*
> *Apache Directory <https://directory.apache.org>, PMC Member*
> Apache Incubator <https://incubator.apache.org>, committer
> *Apache OFBiz <https://ofbiz.apache.org>, contributor (without privileges)
> since 2008*
> Apache Steve <https://steve.apache.org>, committer
>
>
> On Sat, May 25, 2019 at 10:08 PM Jacopo Cappellato 
> wrote:
>
> > Hi all,
> >
> > for those of you who are planning to submit a proposal for a
> presentation,
> > please do it as soon as possible because the organizers may close this
> call
> > for papers anytime after this week end.
> >
> > Thank you!
> >
> > Jacopo Cappellato
> >
> >
> > On Mon, May 20, 2019 at 10:44 AM Jacopo Cappellato 
> > wrote:
> >
> > > Hi all!
> > >
> > > We have a good news: the organizers of ApacheCon North America have
> > > offered to allocate a "full track" to the OFBiz project at the upcoming
> > > conference.
> > > This year's ApacheCon North America, is held in Las Vegas from 9 to 12
> of
> > > September.
> > >
> > > A "full track" is made of 6 presentations. The Call For Presentations
> is
> > > closed but there are still a few slots available for OFBiz: so, if you
> > have
> > > interesting content about OFBiz to present (technical details, how you
> > are
> > > using it, integrations etc...) please submit your proposal and/or
> > questions
> > > to the OFBiz PMC by writing an email to priv...@ofbiz.apache.org. The
> > PMC
> > > will then coordinate with the you about the details/timing of the
> > selection
> > > process.
> > >
> > > This is a great opportunity for the OFBiz project and for you to get in
> > > touch with other members of this community and of the ASF family.
> > >
> > > Best regards,
> > >
> > > Jacopo Cappellato
> > >
> > > [*] https://www.apachecon.com/acna19/index.html
> > >
> > >
> >
>


-- 
Jacopo Cappellato
CTO
*HotWax Systems*
*Enterprise open source experts*

cell: +39 328 6171390
main: 877.736.4080
http://www.hotwaxsystems.com


Re: OFBiz at ApacheCon North America, Las Vegas

2019-05-25 Thread Jacopo Cappellato
Hi all,

for those of you who are planning to submit a proposal for a presentation,
please do it as soon as possible because the organizers may close this call
for papers anytime after this week end.

Thank you!

Jacopo Cappellato


On Mon, May 20, 2019 at 10:44 AM Jacopo Cappellato 
wrote:

> Hi all!
>
> We have a good news: the organizers of ApacheCon North America have
> offered to allocate a "full track" to the OFBiz project at the upcoming
> conference.
> This year's ApacheCon North America, is held in Las Vegas from 9 to 12 of
> September.
>
> A "full track" is made of 6 presentations. The Call For Presentations is
> closed but there are still a few slots available for OFBiz: so, if you have
> interesting content about OFBiz to present (technical details, how you are
> using it, integrations etc...) please submit your proposal and/or questions
> to the OFBiz PMC by writing an email to priv...@ofbiz.apache.org. The PMC
> will then coordinate with the you about the details/timing of the selection
> process.
>
> This is a great opportunity for the OFBiz project and for you to get in
> touch with other members of this community and of the ASF family.
>
> Best regards,
>
> Jacopo Cappellato
>
> [*] https://www.apachecon.com/acna19/index.html
>
>


Re: Apache OFBiz Blog - April Update 2019 Update

2019-05-22 Thread Jacopo Cappellato
It would be nice to mention the following article in our next blog post:

https://solutionsreview.com/enterprise-resource-planning/top-15-free-and-open-source-erp-solutions/

Regards,

Jacopo


On Thu, May 9, 2019 at 8:29 AM Aditya Sharma 
wrote:

> Hi Everyone,
>
> A brief summary of our project news for April month can be found in our
> monthly blog update at the link below:
> https://s.apache.org/dBiH
>
> Thanks to Sharan Foga, Swapnil M Mane, Suraj Khurana, Deepak Dixit, Michael
> Brohl, Jacques Le Roux and Pranay Pandey for their continued support.
>
> --
> Thanks & Regards
> Aditya Sharma
>


-- 
Jacopo Cappellato
CTO
*HotWax Systems*
*Enterprise open source experts*

cell: +39 328 6171390
main: 877.736.4080
http://www.hotwaxsystems.com


OFBiz at ApacheCon North America, Las Vegas

2019-05-20 Thread Jacopo Cappellato
Hi all!

We have a good news: the organizers of ApacheCon North America have offered
to allocate a "full track" to the OFBiz project at the upcoming conference.
This year's ApacheCon North America, is held in Las Vegas from 9 to 12 of
September.

A "full track" is made of 6 presentations. The Call For Presentations is
closed but there are still a few slots available for OFBiz: so, if you have
interesting content about OFBiz to present (technical details, how you are
using it, integrations etc...) please submit your proposal and/or questions
to the OFBiz PMC by writing an email to priv...@ofbiz.apache.org. The PMC
will then coordinate with the you about the details/timing of the selection
process.

This is a great opportunity for the OFBiz project and for you to get in
touch with other members of this community and of the ASF family.

Best regards,

Jacopo Cappellato

[*] https://www.apachecon.com/acna19/index.html


Re: A point in the right direction

2018-11-13 Thread Jacopo Cappellato
On Thu, Nov 8, 2018 at 12:03 AM Shane F. MacIntyre <
macinty...@d33.courts.mi.gov> wrote:

> I started looking into ofbiz because I need to create a solution for a new
> regulation we have at work. We are a courthouse and the state has mandated
> that we provide representation for individuals on a daily basis.
> In a nutshell, I need to have a system where a clerk can assign a
> defendant to an attorney. The attorney would then have to provide counsel
> within 36 hours and report back that they had done so. An administrator
> would be able to oversee the process and verify it. Then pay the attorney
> for the counsel. The defendant might have multiple consultations with
> different attorneys/ probation officers/ drug testing facilities over the
> time that the case is active.
>
> I've played around with ofbiz, adding data  using the various ootb
> components and I've tried the getting started tutorial, successfully adding
> the ofbiz demo plugin. That went fine. Now I am trying to figure out how to
> implement a solution. I am thinking that the Project component would be a
> good place to start because I can make a "Defendant"  project and add
> attorney / probation officer / reviewer resources, then an administrator
> could create phases like "Initial Counsultation, Drug Testing, etc"
>
> Does this sound like I am on the right track? Or should I be looking at it
> differently?
>
>
Hi Shane,

I think that you are on the right track if you are planning to study how
data is setup by the Project component; I would also consider the "Work
Effort" component and the "Scrum" components as they all use the
"WorkEffort" data model to implement different ways to define/manage/track
tasks execution.
I doubt that any of the above components will fit all your requirements but
reviewing them will lower your learning curve; you may also want to read
some chapters of "The Data Model Resource Book vol 1" by Len Silverstone
because it describes the main concepts that have been integrated in the
OFBiz data model.

As Julian as suggested, I would then create a custom component (that may
extend and reuse any of the artifacts from other components) to build the
ui and processes that are peculiar to your organization.

Kind regards,

Jacopo


[ANNOUNCE] Apache OFBiz 16.11.05 released

2018-10-05 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache
OFBiz 16.11.05".

Apache OFBiz® is an open source product for the automation of enterprise
processes that includes framework components and business applications.

http://ofbiz.apache.org/

"Apache OFBiz 16.11.05" is the latest and greatest release of OFBiz; for
more details of the changes introduced with this new version please refer
to http://ofbiz.apache.org/release-notes-16.11.05.html

The release file can be downloaded following the instructions in the OFBiz
download page:

http://ofbiz.apache.org/download.html

The OFBiz community.


Re: 答复: 答复: 答复: A major bug in OFBiz Manufacturing MRP function

2018-04-02 Thread Jacopo Cappellato
On Sun, Apr 1, 2018 at 10:30 AM, Schumann Ye 
wrote:

> Hi Jacopo,
>
> Thanks for your hints.
> Actually I am not using SVN now, I've done quite some customizations so I
> would like to do it directly in the database mysql by using alter table.
> Is it ok if I do it this way?
>

Yes, you can directly alter the MRP_EVENT table.

Regards,

Jacopo


Re: 答复: 答复: A major bug in OFBiz Manufacturing MRP function

2018-04-01 Thread Jacopo Cappellato
On Sat, Mar 31, 2018 at 4:50 PM, Schumann Ye 
wrote:

> [...]

 followed the ReadMe to install the unzipped Ofbiz 16.11.03;
>

Ok, I have verified and in 16.11.* releases the MySQL type set for the
date-time type is DATETIME instead of DATETIME(3):

https://svn.apache.org/repos/asf/ofbiz/branches/release16.11/framework/entity/fieldtype/fieldtypemysql.xml

Ff you edit the file framework/entity/fieldtype/fieldtypemysql.xml and set
DATETIME(3) there and then run "Gradlew cleanAll loadDefault" you should be
able to execute your workflow.

Kind regards,

Jacopo


Re: 答复: A major bug in OFBiz Manufacturing MRP function

2018-03-30 Thread Jacopo Cappellato
Dear Schumann,

thanks for the feedback and for your tests; please see my comment inline:

On Thu, Mar 29, 2018 at 5:14 PM, Schumann Ye 
wrote:

> [...]
> So after updating the column by "ALTER TABLE ofbiz.mrp_event change
> EVENT_DATE EVENT_DATE DATETIME(6); " and a reboot, MRP is running correctly.
>

OFBiz is configured to assign the DATETIME(3) to that field for MySQL [*];
I am wondering if 3 digits were not enough, even if it is weird because it
was not reported before. also in the error message that you have reported
the digits are not included at all so I am wondering if something went
wrong in the initialization of the database.
It would be useful if you could try to alter the table to use DATETIME(3)
instead of DATETIME(6) and test the MRP use case again. It would also be
useful to know how you setup the database; was it maybe copied from an
older version of OFBiz?

Kind regards,

Jacopo

[*]
https://svn.apache.org/repos/asf/ofbiz/ofbiz-framework/trunk/framework/entity/fieldtype/fieldtypemysql.xml


Re: A major bug in OFBiz Manufacturing MRP function

2018-03-29 Thread Jacopo Cappellato
Dear Schumann,

thanks for your report and analysis.
What version of MySQL are you using? I suspect that the error is caused by
the fact that your version doesn't support milliseconds in the DATETIME
field and this causes the "duplicate record" condition.

Kind regards,

Jacopo


On Thu, Mar 29, 2018 at 11:04 AM, Schumann Ye 
wrote:

> Dear Gurus,
>
> I found a serious bug in MRP calculation function (hope I was wrong) and
> I've created a JIRA note OFBIZ-10321.
> In a word, OFBiz MRP function seems currently not supportive of multilevel
> BOM calculation with same material (raw material in my case test) located
> in different BOM level.
>
> While the tested scenario above is quite normal in various industries, so
> my question is, is there any workaround or we have to wait until next patch
> or release?
>
> Thanks
>
> Best Regards
>
> Schumann
>
>
>


Re: GL Account Defaults

2018-03-23 Thread Jacopo Cappellato
Hi James,

usually, before a purchase invoice is posted to the GL, its shipment is
received into inventory and this generates an accounting transaction that
usually:
Debits an inventory account (its balance goes up)
Credits a (temporary) liability account (its balance goes up); this account
is usually named "uninvoiced item receipts" and represents the value of
items for which we are still expecting a formal invoice (we can think of it
as an still unconfirmed "accounts payable" account)

When the purchase invoice is posted we have:
Credits the liability "accounts payable" account (its balance goes up)
Debits the liability "uninvoiced item receipts" account (its balance goes
down)

The end result is that the "uninvoiced item receipts" holds the amount of
the liability since the items are received into the warehouse and until the
time the purchase invoice is posted, when the amount of the liability is
transferred to the "accounts payable" account.

Purchase variance comes into play in order to adjust the difference (if
any) between the purchase order item price and the purchase invoice item
price.

You can control which GL account is credited for Shipment Receipts from the
screen:

https://demo-trunk.ofbiz.apache.org/accounting/control/GlAccountAssignment?organizationPartyId=Company

in it you can edit (remove and add) the row labeled "Uninvoiced Shipment
Receipts" and this will affect the credit part of the transaction generated
by the shipment receipt event.

I hope it helps,

Jacopo

On Thu, Mar 22, 2018 at 5:21 PM, <ja...@productive1.com> wrote:

> Jacopo - Thanks for your email and that makes perfect sense.  Since
> these 2 transactions are related in the Purchase Order to AP.
>
> What controls the GL accounts for Shipment Receipts?  How are the
> Shipment Receipt process and Vendor/Purchase Invoice linked?  How does
> the Purchase Variance come into play?
>
>  Original Message 
> Subject: Re: GL Account Defaults
> From: Jacopo Cappellato <jacopo.cappell...@hotwaxsystems.com>
> Date: Thu, March 22, 2018 8:47 am
> To: "user@ofbiz.apache.org ML" <user@ofbiz.apache.org>
>
> Good morning James,
>
> On Thu, Mar 22, 2018 at 4:10 PM, <ja...@productive1.com> wrote:
>
> > Good morning. Something strange just happened in Financials that maybe
> > this group can point me into the right direction
> >
> > I received a Purchase Order and the system Creating an balancing
> > Accounting Transaction for "Uninvoiced Item Receipt & Inventory". I
> > then marked the vendor invoice as Ready and the system created another
> > balancing transaction with Accounts Payable and Purchase Price Variance.
> >
>
> From what I understand, when the vendor invoice has been posted the
> Accounts Payable has been Credited (correct) and the Purchase Price
> Variance has been Debited (unexpected); could you please share more
> details
> about the invoice transaction (you can find them at the bottom of the
> invoice detail screen)?
>
> The account *debited* for each item in a purchase invoice is determined
> by
> the mapping between the invoice item type and the account id as set in
> this
> screen:
>
> https://demo-trunk.ofbiz.apache.org/accounting/control/editInvoiceItemType
>
> In this screen you should see mappings from various purchase invoice
> item
> types (like PINV_FPROD_ITEM) to the "Uninvoiced Item Receipt" account.
> Please check what you have there.
> As a side note, the "Purchase Price Variance" (that is usually an
> Expense
> account) is used by the system when there is a difference between the
> purchase price (in the order) of an item and its value in the purchase
> invoice.
>
> Kind regards,
>
> Jacopo
>
>
>
> > I was expected it to create a transaction moving the dollar amount from
> > Uninvoiced Item Receipt to accounts payable. My question is where
> > specifically in the system is the Vendor Invoice transaction configured
> > for this process?
> >
> > Thanks,
> >
> > James
> >
>


Re: GL Account Defaults

2018-03-22 Thread Jacopo Cappellato
Good morning James,

On Thu, Mar 22, 2018 at 4:10 PM,  wrote:

> Good morning.  Something strange just happened in Financials that maybe
> this group can point me into the right direction
>
> I received a Purchase Order and the system Creating an balancing
> Accounting Transaction for "Uninvoiced Item Receipt & Inventory".  I
> then marked the vendor invoice as Ready and the system created another
> balancing transaction with Accounts Payable and Purchase Price Variance.
>

>From what I understand, when the vendor invoice has been posted the
Accounts Payable has been Credited (correct) and the Purchase Price
Variance has been Debited (unexpected); could you please share more details
about the invoice transaction (you can find them at the bottom of the
invoice detail screen)?

The account *debited* for each item in a purchase invoice is determined by
the mapping between the invoice item type and the account id as set in this
screen:

https://demo-trunk.ofbiz.apache.org/accounting/control/editInvoiceItemType

In this screen you should see mappings from various purchase invoice item
types (like PINV_FPROD_ITEM) to the "Uninvoiced Item Receipt" account.
Please check what you have there.
As a side note, the "Purchase Price Variance" (that is usually an Expense
account) is used by the system when there is a difference between the
purchase price (in the order) of an item and its value in the purchase
invoice.

Kind regards,

Jacopo



>  I was expected it to create a transaction moving the dollar amount from
> Uninvoiced Item Receipt to accounts payable. My question is where
> specifically in the system is the Vendor Invoice transaction configured
> for this process?
>
> Thanks,
>
> James
>


[ANNOUNCE] Apache OFBiz 16.11.04 released

2018-01-03 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache
OFBiz 16.11.04".

Apache OFBiz® is an open source product for the automation of enterprise
processes that includes framework components and business applications.

http://ofbiz.apache.org/

"Apache OFBiz 16.11.04" is the latest and greatest release of OFBiz; for
more details of the changes introduced with this new version please refer
to http://ofbiz.apache.org/release-notes-16.11.04.html.

The release file can be downloaded following the instructions in the OFBiz
download page:

http://ofbiz.apache.org/download.html

The OFBiz community.


Re: Security Related Issues in OFBiz

2017-12-19 Thread Jacopo Cappellato
Hi Vivek,

the best way to go is to use a release that is part of a release branch
that is still actively maintained:

https://ofbiz.apache.org/download.html

Security vulnerabilities on active branches should be reported to the OFBiz
security list: secur...@ofbiz.apache.org

Thank you,

Jacopo


On Tue, Dec 19, 2017 at 6:40 AM, vivek.mi  wrote:

> Hello All,
>
> A few issues were reported while testing my application using IBM AppScan
> tool, built upon OFBiz framework for Blackbox testing. Issues are listed as
> below:
>
> 1. Unsafe third-party link (target="_blank") in screens and forms.
>
> 2. Query Parameter in SSL Request while sending hidden fields in XML and
> FTL
> forms.
>
> 3. Body Parameters Accepted in Query
>
> 4. Archive File Download
>
> 5. Cacheable SSL Page Found
>
> Please suggest something how can i go ahead to resolve these issues. I am
> using OFBiz version 12.05.
>
> Thanks in advance,
> Vivek Mishra
>
>
>
> -
> Vivek Mishra
> --
> Sent from: http://ofbiz.135035.n4.nabble.com/OFBiz-User-f135036.html
>


Re: MRP log doesn't work

2017-11-21 Thread Jacopo Cappellato
Hi Harry,

unfortunately the user interface doesn't provide enough details about the
problems occurred during the execution of the MRP and you have to analyze
the logs: I'd suggest to run the MRP again and monitor the console logs for
errors that should give you a good hint at the root cause of the problem
(if not feel free to share the relevant part of the log in this thread).

Regards,

Jacopo

On Tue, Nov 21, 2017 at 6:22 PM, harry mead 
wrote:

> Hi,
>
>
> Does anyone know why my MRP wont complete, It keeps saying pending and ive
> reinstalled ofbiz from scratch and I still get the same issue, I have a
> feeling its because I changed the demo suppliers currency to GBP when
> setting up the products, does anyone have an suggestions on how to fix this
> problem?
>
>
> Thanks
>
>
> Harry
>


[ANNOUNCE] Apache OFBiz 16.11.03 released

2017-07-03 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache
OFBiz 16.11.03".

Apache OFBiz® is an open source product for the automation of enterprise
processes that includes framework components and business applications.

http://ofbiz.apache.org/

"Apache OFBiz 16.11.03" is the latest and greatest release of OFBiz; for
more details of the changes introduced with this new version please refer
to http://ofbiz.apache.org/release-notes-16.11.03.html.

The release file can be downloaded following the instructions in the OFBiz
download page:

http://ofbiz.apache.org/download.html

The OFBiz community.


[ANNOUNCE] Apache OFBiz 16.11.02 released

2017-05-24 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache
OFBiz 16.11.02".

Apache OFBiz® is an open source product for the automation of enterprise
processes that includes framework components and business applications.

http://ofbiz.apache.org/

"Apache OFBiz 16.11.02" is the latest and greatest release of OFBiz; for
more details of the changes introduced with this new version please refer
to http://ofbiz.apache.org/release-notes-16.11.02.html.

The release file can be downloaded following the instructions in the OFBiz
download page:

http://ofbiz.apache.org/download.html

The OFBiz community.


Re: Stable Release Schedule?

2017-05-10 Thread Jacopo Cappellato
Hi,

I think it is indeed time to discuss/prepare the new 16.11.02 release.

I am going to start a thread on the dev list now.

Thanks,

Jacopo


On Wed, May 10, 2017 at 1:08 AM,  wrote:

> Hi,
>
> I'm wondering how often stable releases occur? I see on the downloads page
> it doesn't seem to be very often, perhaps a year or more between releases.
> Would it be safe to assume I won't be seeing any fixes for WebPOS for at
> least another year if I wait (this would be terrible news)? I haven't seen
> any activity on the JIRA bug report for this, so I'd assume even
> intermediate releases on git may not see this fixed in a reasonable time.
>
> I'm trying to go through logs on demo data loads and manually loading XML
> from demo data to see if I can spot an order of load where I might be able
> to manually edit demo data XML files and not having much luck...it seems
> the demo data load succeeds (so far as logs show), but when running from
> the web tools I end up getting errors where it doesn't think the XML is
> well-formed. Even so, if I use command line via something like this it
> imports, but I've not been able to get a WebPOS which can be logged in to:
> ./gradlew "ofbiz --load-data file=/some/file.xml"
>
> This is very slow and very painful due to the enormous amount of XML data,
> so I'm not confident this can succeed in the time I have. I hate to go back
> to an unsupported prior release, but would something like the 14.12 or
> 15.12 offer a stable POS of some sort where it can be used with a real
> company and not with demo data? Would anyone know what the most recent
> release is with a working POS of any kind? It's absolutely mandatory that
> some sort of POS be available at the cash register.
>
> Thanks!


Re: Accounting_quantity_diff <-- Item variance

2017-04-26 Thread Jacopo Cappellato
Hi Ingo,

in rev. 1792609 I have committed a fix for the issue you have reported.
However there are some use cases that may still not be covered well but in
order to enhance the system we need to discuss some design before; if you
are interested we could continue this conversation in the dev list.

Jacopo

On Tue, Apr 18, 2017 at 3:59 PM, Ingo Wolfmayr <ingo.wolfm...@wolfix.at>
wrote:

> Hi Jacopo,
>
> in fact that's the case.
>
> Shipment receipt creates 2 entries. Second adjusts the ACOUNTING_QUANTITY
> colums.
> Item variance creates 1 entry. ACOUNTING_QUANTITY colums are empty.
>
> I create a jira https://issues.apache.org/jira/browse/OFBIZ-9324.
>
> Ingo
>
> -----Ursprüngliche Nachricht-
> Von: Jacopo Cappellato [mailto:jacopo.cappell...@hotwaxsystems.com]
> Gesendet: Dienstag, 18. April 2017 14:49
> An: user@ofbiz.apache.org ML <user@ofbiz.apache.org>
> Betreff: Re: Accounting_quantity_diff <-- Item variance
>
> Hi Ingo,
>
> could you please check and confer that, during step #2, the
> ACCOUNTING_QUANTITY is not changed for any InventoryItem? In fact, there is
> no guarantee that the system will change the ACCOUNTING_QUANTITY on the
> same InventoryItem for which the ATP and QOH are changed: however it should
> be changed in one item. If it doesn't happen then there we will have to
> enable it for item variances.
>
> Jacopo
>
>
> On Tue, Apr 18, 2017 at 2:00 PM, Ingo Wolfmayr <ingo.wolfm...@wolfix.at>
> wrote:
>
> > Hi everybody,
> >
> > I have a question regarding ACCOUNTING_QUANTITY_DIFF and inventory
> > shrinkage. I created the following case:
> >
> >
> > 1.   Shipment Receipt: 1 Piece for 15$ (Facility --> Receive
> Inventory)
> >
> > 2.   Item Variance: 1 Piece (via physical inventory on inventory item
> > -1 ATP, -1 QOH) - item lost
> >
> > Step 1
> >
> > * increases the ACCOUNTING_QUANTITY --> ACCOUNTING_QUANTITY_DIFF
> =
> > 1
> >
> > * creates an accounting transaction --> INVENTORY +1 (15$ Credit)
> > Step 2
> >
> > * ACCOUNTING_QUANTITY no change
> >
> > * creates an accounting transaction --> INVENTORY -1 (15$ Debit)
> >
> > Therefore the ITEM VALUATION report still shows 15$ / 1 Accounting
> > Quanity sum after step two. Shouldn't the physical inventory change
> > also have an effect on the ACCOUNTING_QUANTITY, or do I misinterpet
> something?
> >
> > Done on current trunk.
> >
> > Best regards,
> > Ingo
> >
>


Re: plugin and hotdeploy

2017-04-24 Thread Jacopo Cappellato
On Sat, Apr 22, 2017 at 7:49 AM, Mike  wrote:

> [...] All the previous books, emails, articles, wikis, and blogs that
> guided folks on how to deploy a new app, or modify one has been completely
> wiped out [...]


Software documentation is always written for a target version of a software
product and most of the users understand and accept that some of the
information in an older book may not be applicable to newer versions of the
software.

Jacopo


Re: Clean Slate

2017-04-19 Thread Jacopo Cappellato
On Wed, Apr 19, 2017 at 9:35 AM, Jacopo Cappellato <
jacopo.cappell...@hotwaxsystems.com> wrote:

> Hi Craig,
>
> the name loadDefault may be a bit misleading: it actually loads the seed
> data but also testing and demo data (maybe loadAll may be more accurate).
> Anyway, you are probably looking for:
>
> ./gradlew "ofbiz --load-data readers=seed,seed-initial"
>
> You will find a description of the various options and their meaning in
> the README.md file section titled "Data loading tasks".
>

And there is one more task you may want to run:

./gradlew loadAdminUserLogin -PuserLoginId=MyUserName

This will create a user with id MyUserName (of course choose the name you
prefer) with password "ofbiz" (the system will ask you to change it after
the first successful login).

Jacopo


Re: Clean Slate

2017-04-19 Thread Jacopo Cappellato
Hi Craig,

the name loadDefault may be a bit misleading: it actually loads the seed
data but also testing and demo data (maybe loadAll may be more accurate).
Anyway, you are probably looking for:

./gradlew "ofbiz --load-data readers=seed,seed-initial"

You will find a description of the various options and their meaning in the
README.md file section titled "Data loading tasks".

Regards,

Jacopo

On Wed, Apr 19, 2017 at 2:40 AM, Craig Parker  wrote:

> ./gradlew cleanAll loadDefault will load some test data. Or is that wrong?
> I'm only thinking so because I saw things in the PRODUCTS table besides the
> item I started creating.
>
> Dropping the databases, running and firing OFBiz up again seems to have
> rebuilt the databases (I thought I'd read somewhere that they'd get rebuilt
> like that), but there's no data. This was the desired effect, but I can't
> launch the software now. I can post the whole error, or just say that I see
> a lot of "Template location is empty" messages.
>
> Is that the right way to start with a clean slate and I missed a step, or
> is that totally wrong?
>


Re: Accounting_quantity_diff <-- Item variance

2017-04-18 Thread Jacopo Cappellato
Hi Ingo,

could you please check and confer that, during step #2, the ACCOUNTING_QUANTITY
is not changed for any InventoryItem? In fact, there is no guarantee that
the system will change the ACCOUNTING_QUANTITY on the same InventoryItem
for which the ATP and QOH are changed: however it should be changed in one
item. If it doesn't happen then there we will have to enable it for item
variances.

Jacopo


On Tue, Apr 18, 2017 at 2:00 PM, Ingo Wolfmayr 
wrote:

> Hi everybody,
>
> I have a question regarding ACCOUNTING_QUANTITY_DIFF and inventory
> shrinkage. I created the following case:
>
>
> 1.   Shipment Receipt: 1 Piece for 15$ (Facility --> Receive Inventory)
>
> 2.   Item Variance: 1 Piece (via physical inventory on inventory item
> -1 ATP, -1 QOH) - item lost
>
> Step 1
>
> * increases the ACCOUNTING_QUANTITY --> ACCOUNTING_QUANTITY_DIFF =
> 1
>
> * creates an accounting transaction --> INVENTORY +1 (15$ Credit)
> Step 2
>
> * ACCOUNTING_QUANTITY no change
>
> * creates an accounting transaction --> INVENTORY -1 (15$ Debit)
>
> Therefore the ITEM VALUATION report still shows 15$ / 1 Accounting Quanity
> sum after step two. Shouldn't the physical inventory change also have an
> effect on the ACCOUNTING_QUANTITY, or do I misinterpet something?
>
> Done on current trunk.
>
> Best regards,
> Ingo
>


Re: Default key size

2017-04-07 Thread Jacopo Cappellato
I think that the root of the problems here is to store information in the
id fields (e.g. productId).
It would instead be better to let the system generate a unique id and then
store the more meaningful identifiers (e.g. UPC for products) in separate
entities or fields (e.g. GoodIdentification for products,
PartyIdentification for parties etc...).
If the id fields are simply used to store a unique identifier then the
current size will not be a problem.
I know that the (seed and demo) data we release are misleading because they
suggest information should be stored in the ids and similarly most of the
applications (where for example, we have several search forms to search by
product id or input fields for the productId) and I wish we will slowly
improve them to provide a better implementation that hides the db ids to
the user by implementing a better UX.

Jacopo

On Wed, Apr 5, 2017 at 7:06 PM, Pierre Smits  wrote:

> HI Mike, all,
>
> Re 2: Talk about adjustment of default key size
> Why is that absurd? You believe it is too long/too short?
> Following JIRA issue may be of interest:
> https://issues.apache.org/jira/browse/OFBIZ-8343
>
> Best regards,
>
> Pierre Smits
>
> ORRTIZ.COM 
> OFBiz based solutions & services
>
> OFBiz Extensions Marketplace
> http://oem.ofbizci.net/oci-2/
>
> On Wed, Apr 5, 2017 at 5:10 PM, Mike  wrote:
>
> > Nice videos.  Regarding the mysql setup, you may want to include two
> items:
> >
> > 1) Make sure mysql is setup as UTF8, discussed earlier in this mail
> group.
> > Requires tweaking:
> >
> > framework/entity/config/entityengine.xml
> > /etc/mysql/my.cnf
> >
> > 2) Talk about adjusting the default sizes of primary keys (ID).  The
> > default is an absurd 20 characters:
> >
> > framework/entity/fieldtype/fieldtypemysql.xml
> >
> > 
> >  > java-type="String"/>
> >  > java-type="String"/>
> >
> >
> >
> > On Wed, Apr 5, 2017 at 6:03 AM, Pranay Pandey <
> > pranay.pan...@hotwaxsystems.com> wrote:
> >
> > > Thanks so much Deepak!
> > >
> > > Best regards,
> > >
> > > Pranay Pandey
> > >
> > >
> > > On Wed, Apr 5, 2017 at 5:51 PM, Deepak Dixit
>  > > com
> > > > wrote:
> > >
> > > > Hi Team,
> > > >
> > > > Here are some more videos from Pranay
> > > >
> > > > -  Setup OFBiz in IntelliJ IDEA IDE - Release 16.11 and Trunk
> > > > 
> > > > - Setup OFBiz with MySQL 
> > > >
> > > >
> > > > Thanks Pranay for your effort.
> > > >
> > > >
> > > > Thanks & Regards
> > > > --
> > > > Deepak Dixit
> > > > www.hotwaxsystems.com
> > > >
> > > > On Wed, Mar 22, 2017 at 7:07 PM, akash jain 
> > > > wrote:
> > > >
> > > > > Nice videos, thanks Pranay!
> > > > >
> > > > > Thanks and Regards
> > > > > --
> > > > > Akash Jain
> > > > >
> > > > > On Thu, Mar 9, 2017 at 6:18 PM, Deepak Dixit
> > >  > > > > com
> > > > > > wrote:
> > > > >
> > > > > > Hi Everyone,
> > > > > >
> > > > > > Pranay has created two video tutorials, these have been published
> > on
> > > > our
> > > > > > OFBiz YouTube channel :
> > > > > > 1 - Apache OFBiz Mailing Lists  > > > > > watch?v=bIS2kftvsq4>
> > > > > > 2 - OFBiz Beginners Tutorial - Basic Setup Release16.11
> > > > > > 
> > > > > >
> > > > > > Thanks Pranay for these helpful videos.
> > > > > >
> > > > > > Thanks & Regards
> > > > > > --
> > > > > > Deepak Dixit
> > > > > > www.hotwaxsystems.com
> > > > > >
> > > > >
> > > >
> > >
> >
>


Re: Relate Purchase Order with Sales Order

2017-03-30 Thread Jacopo Cappellato
Hello Jonathan,

you can look at the following entities:

OrderItemAssoc
OrderItemAssocType

The currently available association types (orderItemAssocTypeId) are:

PURCHASE_ORDER
DROP_SHIPMENT
REPLACEMENT
NEW_VERSION
EXCHANGE

I hope it helps,

Jacopo


On Wed, Mar 29, 2017 at 5:05 PM, Jonathan Javier 
wrote:

> Hello,
> Knowing that an order can link an invoice,
> I would like to know if there is an opportunity in OFBiz to be able to link
> a Sales Order to a Purchase Order.
>


Re: [NOTICE] All systems acting up! (was Re: Public election open for votes: stv9-test (STV 9 Test))

2017-03-22 Thread Jacopo Cappellato
Jacques,

it is not ok to forward any message from members@ to public lists.

Jacopo


Re: Loans

2017-03-17 Thread Jacopo Cappellato
Hi Bahaa,

you can record them with manually entered accounting transactions.
The screen to use is the following:

https://demo-stable.ofbiz.apache.org/accounting/control/newAcctgTrans?
organizationPartyId=Company

Enter the information for the header (you can leave most of the fields
blank) and then hit the "create" button; in the next screen you will create
Debit and Credit entries for the accounts you want to post to: you will
probably want to use one liability account for the Credit (to represent the
amount your company owe to the investor) and a cash/bank account for the
Debit (to represent the money received from the investor).

I hope it helps,

Jacopo

On Sun, Mar 12, 2017 at 2:18 PM, Bahaa Alamood <
balam...@arcdigitalsolutionsandconsultancy.com> wrote:

> Hello all,
>
> We have a situation where the business borrow money from the investors and
> then the business returns  the money to the investors when the project they
> helped financing is done. How can I input this in ofbiz in  a way such that
> this money shows up in the reports?
>
>
> --
> Bahaaldin Al-amood
> IQ Tel: +964 (0) 780 926 2103
> US tel: 540 632 1388
> email: ba...@arcdsc.com
> Skype ID: bahaa.alamood
>
> Arc Digital Solutions and Consultancy
> www.arcdsc.com
>
> This message contains information that may be confidential
> and privileged to Arc digital Solutions and Consultancy, its partners, or
> customers.
> Unauthorized use is strictly prohibited. Unless you are the
> addressee (or authorized to receive mail for the addressee),
> you should not use, copy or disclose to anyone this message
> or any information contained in this message. If you have
> received this message in error, please so advise the sender
> by reply e-mail and delete this message. Thank you for your
> cooperation.
>
>


Re: opening balances

2017-03-09 Thread Jacopo Cappellato
Hi Moatasim,

you can create opening balances with a manually entered accounting
transaction.
The screen to use is the following:

https://demo-stable.ofbiz.apache.org/accounting/control/newAcctgTrans?organizationPartyId=Company

Enter the information for the header (you can leave most of the fields
blank) and then hit the "create" button; in the next screen you will create
Debit and Credit entries for the opening balance.

I hope it helps,

Jacopo


On Wed, Mar 8, 2017 at 3:41 PM, Moatasim Al Masri 
wrote:

> Hi everybody
>
> This is Moatasim, I would like to ask how can enter opening balances for
> GLs and Vendors?
>
>
>
> *Best Regards,*
>
>
>
> *Moatasim L. Al-Masri*
>
> Program Manager
>
>
>
> [image: Description: Logo for Office-4]
>
>
>
> [image: Description: bi email-3-02]
>
>
>
> P.O.Box 3516 Amman, 11821
>
> The Hashemite Kingdom of Jordan
>
> *Tel.* +962 (6) 556 2620
>
> *Mob (Jordan).*   +962 79 5426384
>
> [image: Description: bi email-3-04]
>
> [image: Description: bi email-3-05]
>
> /biict
>
> @biict
>
> Kingdom of Saudi Arabia
>
> *Mob (KSA).*+966 55 7885607
>
>
>
>
>
>
>
>
>


Re: Setup Dev system with IntelliJ IDEA

2017-02-17 Thread Jacopo Cappellato
Hi Clifford,

here is how I usually configure IntelliJ for OFBiz with Gradle:

1) checkout the project using svn from the command line
2) Start IntelliJ and select New Project From Existing Sources...
3) Select the Gradle option
4) Then select the Gradle Wrapper mode (default); in this screen make sure
you select Java 8 (for this to appear, you have to properly set your
environment outside of IntelliJ)
5) when prompted, select all the modules and also keep the root module

After that you can use Gradle from IntelliJ.

I hope it helps,

Jacopo

On Fri, Feb 10, 2017 at 6:04 PM, Clifford Williams <
cliffwilliam...@icloud.com> wrote:

> Tahar, once I figured out how to properly set my JAVA_HOME for the JDK
> this was very simple to implement.
>
> Thank you for pointing me in the right direction.
>
> On Feb 09, 2017, at 02:14 AM, Taher Alkhateeb 
> wrote:
>
> Hi Cliff,
>
> We did not yet integrate Gradle with Intellij but it is relatively easy.
> You can get more information here ->
> https://docs.gradle.org/3.3/userguide/idea_plugin.html
>
> This would be a good area to start working on.
>
> Regards,
>
> Taher Alkhateeb
>
> On Wed, Feb 8, 2017 at 4:33 PM, Clifford Williams <
> cliffwilliam...@icloud.com> wrote:
>
> Please bare with me as we are a group of old school guys trying to move
>
> into this arena.
>
>
> I have tried to setup a dev system using IntelliJ but I keep failing at
>
> the Gradle configuration. So apparently I am missing something.
>
>
> Thanks in advance,
>
>
> Cliff
>
>
>


Re: Inbound Email

2017-02-08 Thread Jacopo Cappellato
On Tue, Feb 7, 2017 at 7:48 PM,  wrote:

> Thanks Jacques.  Can you tell me how it was intended to work?  Is it one
> big inbound account or does each user have the ability to have his/her
> emails brought into their view?
>

Hi James,

the idea is to setup one mail account and then configure OFBiz to "listen"
on it for incoming emails: you can then trigger actions (i.e. call
services) by defining "mca" (mail-condition-action); in the mca you can
specify mail filters, so that you can define different events based on the
content/meta content of the mails.

Jacopo


Re: Async Service Thread Locking

2017-02-06 Thread Jacopo Cappellato
Hi Ryan,

On Tue, Jan 31, 2017 at 9:24 PM, Ryan Moriarty <
ryan.moria...@ableengineering.com> wrote:

> I'm having difficulty with asynchronous jobs not completing. Many jobs
> finish normally, but most show "Running" into perpetuity. I see no pattern
> in services that finish and services that continue running indefinitely.


Does it happen with different services? Or all the jobs stuck in the
"Running" state are executions of the same service?
It may be really useful to extract and analyze the logs of a job execution
that is stuck.

Jacopo


Re: a vendor

2017-01-26 Thread Jacopo Cappellato
On Thu, Jan 26, 2017 at 1:32 PM, Heidi Dehaes - Olagos <
info.ola...@gmail.com> wrote:

> Yes, Pierre,
>
> A vendor in ofbiz is not always used in the same manner. However i try to
> think about to create a marketplace and their i need the role of vendor.
> In ofbiz there can be connected one vendor per product. I have to extend
> that to more different vendors per product. But ofbiz doesn't foresee
> different prices of the same product offered by different vendors.
>

Hi Eric, please have a look at the entity named SupplierProduct (and
related business logic): this is probably what you are looking for.

Jacopo

So there i have to think about to modify the logic.
> I have to add a partyrole or party to the productprice entity. And modify
> the calculateprice service.
>
> Regards,
> Eric
>
> Olagos bvba
> Heidi Dehaes
> Kerkstraat 34
> 2570 Duffel
> Belgium
> Tel. : 015/31 53 04
> GSM :0485/22 35 80
> E-mail : info.ola...@gmail.com
> http://www.olagos.eu
> http://www.olagos.com
> http://www.olagos.be
> http://www.olagos.nl
>
>


Re: Wiki beginner - some things to correct

2017-01-18 Thread Jacopo Cappellato
Thank you Ludovic,

I have fixed the typo.

Jacopo

On Wed, Jan 18, 2017 at 9:44 AM, Ludovic GILBON 
wrote:

> Hello Jacopo,
>
> I am new on OFBiz and i am on the wiki "A Beginners Development Guide".
>
> I would like notice you some little things to correct :
>
> Here,
> https://cwiki.apache.org/confluence/display/OFBIZ/
> OFBiz+Tutorial+-+A+Beginners+Development+Guide;jsessionid=
> CDD039F18082B39BE9F8BAE0255EEDD2#OFBizTutorial-ABeginnersDevelopmentGuide-
> Runningyourfirstapplication
>
> In the code paragraph, i think it is "label text" instead of "labeltext"
> (it is "label text" just under).
>
>
> Then, some screenshots seems KO :
>
> 1 screenshot
> https://cwiki.apache.org/confluence/display/OFBIZ/
> OFBiz+Tutorial+-+A+Beginners+Development+Guide;jsessionid=
> CDD039F18082B39BE9F8BAE0255EEDD2#OFBizTutorial-ABeginnersDevelopmentGuide-
> CreateaService
>
> 2 links beginning with "XML Data ..."
> https://cwiki.apache.org/confluence/display/OFBIZ/
> OFBiz+Tutorial+-+A+Beginners+Development+Guide;jsessionid=
> CDD039F18082B39BE9F8BAE0255EEDD2#OFBizTutorial-ABeginnersDevelopmentGuide-
> Loadingdatainentity
>
> 1 screenshot
> https://cwiki.apache.org/confluence/display/OFBIZ/
> OFBiz+Tutorial+-+A+Beginners+Development+Guide;jsessionid=
> CDD039F18082B39BE9F8BAE0255EEDD2#OFBizTutorial-ABeginnersDevelopmentGuide-
> ControllerEntryforForm
>
>
> Thanks,
>
>
> --
> [image: logoNrd] 
> Ludovic GILBON
> Intégrateur Apache-OFBiz, ERP en logiciel Libre
> ludovic.gil...@nereide.fr
> 8 rue des Déportés 37000 TOURS
> 02 47 50 30 54
> OFBiz France  | réseau Libre-Entreprise
> 
>
>


Re: Misuse of the ASF's OFBiz trademark

2017-01-04 Thread Jacopo Cappellato
On Tue, Jan 3, 2017 at 11:44 AM, Pierre Smits <pierre.sm...@gmail.com>
 wrote:

>
> 1. [...] HotWax Systems, which violates the Apache trademark by owning the
> top level domain ‘ofbiz.us’ [1] (Us OFBiz) since 2010.

2. [...] several ‘ofbiz-community’ top level domains [2] which don’t
> (re)direct towards ofbiz.apache.org
> 3. [...] several top level domains which don’t (re)direct towards
> ofbiz.apache.org
> 4. [...] Nereide (in France) which owns the domain ‘ofbiz.fr’ [4].
>
>
(Moving dev@/user@ to bcc: to avoid mixing public/private lists)

Users should report potential trademark misuses of the OFBiz marks to the
private list as explained here:

http://www.apache.org/foundation/marks/reporting#users

The OFBiz PMC, with the help of the Apache Trademarks group, is actively
working at protecting the project's marks by researching for and logging
potential misuses (the ones you have reported above will be added to the
list if not already there), reviewing and analyzing them and then privately
contacting the third parties for which the violations have been confirmed
(like we did with your site).

Jacopo Cappellato
Vice President, Apache OFBiz
The Apache Software Foundation
http://ofbiz.apache.org


Re: Demos will stop to get more memory

2016-12-27 Thread Jacopo Cappellato
I think this should be documented somewhere in the public space, except of
course the login credentials.

Jacopo

On Tue, Dec 27, 2016 at 6:06 PM, Jacques Le Roux <
jacques.le.r...@les7arts.com> wrote:

> I'm not against personally. For now only the PMC and ASF members are aware
> of the login procedure. So I think it's a PMC decision, but I could be
> wrong.
>
> BTW It's not yet done...
>
> Jacques
>
>
> Le 27/12/2016 à 11:01, Pierre Smits a écrit :
>
>> Maybe you should invite more contributors to be able to restart the demos,
>> in stead of maintaining SPOFs.
>>
>> Best regards,
>>
>> Pierre
>>
>> On Tuesday, December 27, 2016, Jacques Le Roux <
>> jacques.le.r...@les7arts.com>
>> wrote:
>>
>> Hi,
>>>
>>> I have asked the infra team to increase our demos VM memory from 4GB to
>>> 5GB (because of the Gradle wrappers). They agreed and will proceed soon.
>>> Since I might be absent at this moment to restart manually the instances,
>>> you will maybe face an outage.
>>>
>>> Jacques
>>>
>>>
>>
>


Re: [ANNOUNCE] Directions to limit excessive or unfair marketing messages in the OFBiz mailing lists

2016-12-26 Thread Jacopo Cappellato
On Sun, Dec 25, 2016 at 12:41 PM, Jacques Le Roux <
jacques.le.r...@les7arts.com> wrote:

>
> Long ago, I created the OFBiz Nabble forum with as many sub-forums as we
> have mailing lists.
>

I have started a new thread to discuss Nabble in the dev listwith subject:
"Review the configuration of the OFBiz forums at Nabble".

Cheers
Jacopo


Re: [ANNOUNCE] Directions to limit excessive or unfair marketing messages in the OFBiz mailing lists

2016-12-26 Thread Jacopo Cappellato
On Sat, Dec 17, 2016 at 9:14 AM, Jacopo Cappellato <jaco...@apache.org>
wrote:

> [...] the OFBiz PMC has published some
> directions to govern how third parties can announce their
> products/services/initiatives on the OFBiz user list:
>
> http://ofbiz.apache.org/mailing-lists.html#3rd-party-marketing
>
>
With my PMC hat on:
- the policy is effective from now on (i.e. what happened in the past is
not important)
- third parties that are planning to use this list for a marketing related
initiative, and are unsure if the format is compliant with the new policy,
are invited to contact the PMC (at priv...@ofbiz.apache.org and optionally
cc tradema...@apache.org)
- as it is already a prerogative of the PMC, repeated violations will be
treated similarly to any other behavior potentially harmful for the
community: any case will be carefully evaluated and the minimal and most
effective action for the specific case will be taken with the goal of
correcting rather than punishing


[ANNOUNCE] Directions to limit excessive or unfair marketing messages in the OFBiz mailing lists

2016-12-17 Thread Jacopo Cappellato
Over the past weeks a few individuals have posted several messages
sponsoring their company's products/services/initiatives and, at the same
time, criticized OFBiz and interfered with several threads in which OFBiz
related topics were discussed.These unfair marketing messages are
distracting for our community and detrimental to the project's image.

In order to cope with this behavior the OFBiz PMC has published some
directions to govern how third parties can announce their
products/services/initiatives on the OFBiz user list:

http://ofbiz.apache.org/mailing-lists.html#3rd-party-marketing

Please consider that users repeatedly violating these directions will be
unsubscribed from the OFBiz lists.

The OFBiz PMC


Re: [FYI] Trunk demo crashed

2016-12-13 Thread Jacopo Cappellato
On Tue, Dec 13, 2016 at 9:43 PM, Jacques Le Roux <
jacques.le.r...@les7arts.com> wrote:

> Hi Taher,
>
> I don't see the need to discuss about this, I have expressed facts, that's
> all
>
> Jacques


but we need more facts to identify the core cause of the crash and fix it
:-)
I think that Craig asked the right question: if there was enough memory to
start the instances and run them for 12 hours then the memory, under the
same load, should be enough to run them forever. If on the other hand the
memory usage slowly goes up then there is a memory leak or something else
that needs to be fixed.
Better move this conversation to the dev list where we can do a thorough
analysis together.

Jacopo


Re: [ANNOUNCE] Plugin components for OFBiz and OFBizBase

2016-11-30 Thread Jacopo Cappellato
In this case, the announcement is more suited for the "user" list where
adopters, end users, integrators, service providers meet and discuss.
The "dev" list should only be used to discuss changes to the official
codebase (i.e. hosted in the ASF svn); the "private" list is used by the
PMC to discuss new invitations and very few other topics.

Kind regards,

Jacopo


On Wed, Nov 30, 2016 at 9:43 AM, Scott Gray 
wrote:

> Hi Pierre,
>
> Could you please stop cross-posting?
>
> http://apache.org/dev/contrib-email-tips.html#rightlist
> http://directory.apache.org/mailing-lists-and-irc.html
>
> I understand you're a PMC member of the Apache Directory project so I would
> assume you're familiar with ASF email etiquette.
>
> Many thanks
> Scott
>
> On 30 November 2016 at 21:32, Pierre Smits  wrote:
>
> > Hi all,
> >
> > It pleases me to be abel to announce the availability of following plugin
> > components on GITHUB.
> > These plugins components are disentangled from the OFBiz trunk repository
> > and can be used as hot-deploy add-ons/replacements in your
> implementation.
> >
> > accounting https://github.com/OFBizCI/accounting
> > assetmaint https://github.com/OFBizCI/assetmaint
> > bi https://github.com/OFBizCI/bi
> > birt https://github.com/OFBizCI/birt
> > bluelight https://github.com/OFBizCI/bluelight
> > cmssite https://github.com/OFBizCI/cmssite
> > common https://github.com/OFBizCI/common
> > commonext https://github.com/OFBizCI/commonext
> > content https://github.com/OFBizCI/content
> > datamodel https://github.com/OFBizCI/datamodel
> > ebay https://github.com/OFBizCI/ebay
> > ebaystore https://github.com/OFBizCI/ebaystore
> > ecommerce https://github.com/OFBizCI/ecommerce
> > entity https://github.com/OFBizCI/entity
> > flatgrey https://github.com/OFBizCI/flatgrey
> > hhfacility https://github.com/OFBizCI/hhfacility
> > humanres https://github.com/OFBizCI/humanres
> > ldap https://github.com/OFBizCI/ldap
> > lucene https://github.com/OFBizCI/lucene
> > manufacturing https://github.com/OFBizCI/manufacturing
> > myportal https://github.com/OFBizCI/myportal
> > oagis https://github.com/OFBizCI/oagis
> > order https://github.com/OFBizCI/order
> > party https://github.com/OFBizCI/party
> > passport https://github.com/OFBizCI/passport
> > product https://github.com/OFBizCI/product
> > projectmgr https://github.com/OFBizCI/projectmgr
> > rainbowstone https://github.com/OFBizCI/rainbowstone
> > scrum https://github.com/OFBizCI/scrum
> > securityext https://github.com/OFBizCI/securityext
> > service https://github.com/OFBizCI/service
> > solr https://github.com/OFBizCI/solr
> > webpos https://github.com/OFBizCI/webpos
> > webtools https://github.com/OFBizCI/webtools
> > widget https://github.com/OFBizCI/widget
> > workeffort https://github.com/OFBizCI/workeffort
> > More information (WIP) on these components and other optional plugin
> > componens can be found via https://oem.ofbizci.net/oci-2
> >
> > Should you have any questions and/or remarks, feel free to post these to
> > this mailing list.
> >
> > Best regards,
> >
> > Pierre Smits
> >
> > ORRTIZ.COM 
> > OFBiz based solutions & services
> >
> > OFBiz Extensions Marketplace
> > http://oem.ofbizci.net/oci-2/
> >
>


[SECURITY] CVE-2016-6800 Apache OFBiz blog stored XSS vulnerability

2016-11-28 Thread Jacopo Cappellato
Vendor:
The Apache Software Foundation

Versions Affected:
OFBiz 13.07.*
OFBiz 12.04.*
OFBiz 11.04.*

Description:
The default configuration of the OFBiz framework offers a blog
functionality. Different users are able to operate blogs which are
related to specific parties. In the form field for the creation of new
blog articles the user input of the summary field as well as the article
field is not properly sanitized. It is possible to inject arbitrary
JavaScript code in these form fields. This code gets executed from the
browser of every user who is visiting this article.

Mitigation:
Upgrade to 16.11.01

Credit: Robert Scholz, ERNW GmbH

References:
http://ofbiz.apache.org/download.html#vulnerabilities


[SECURITY] CVE-2016-4462 OFBiz template remote code vulnerability

2016-11-28 Thread Jacopo Cappellato
Vendor:
The Apache Software Foundation

Versions Affected:
OFBiz 13.07.*
OFBiz 12.04.*
OFBiz 11.04.*

Description:
By manipulating the URL parameter externalLoginKey, a malicious, logged in
user could pass valid Freemarker directives to the Template Engine that are
reflected on the webpage; a specially crafted Freemarker template could be
used for remote code execution.

Mitigation:
Upgrade to 16.11.01

Credit: Rick Radewagen, ERNW GmbH

References:
http://ofbiz.apache.org/download.html#vulnerabilities


[ANNOUNCE] Apache OFBiz 16.11.01 released

2016-11-28 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache
OFBiz 16.11.01".

Apache OFBiz® is an open source product for the automation of enterprise
processes that includes framework components and business applications.

http://ofbiz.apache.org/

"Apache OFBiz 16.11.01" is the latest and greatest release of OFBiz. The
highlights of this release include:

* Switch of the build system to Gradle
* Removal of all libraries from OFBiz
* Introduction of a plugin management system
* Introduction of a unit testing framework
* Conversion of all namespaces to org.apache.ofbiz
* Inclusion of all "specialpurpose" components
* Refactoring of source file layouts to be more compliant with project
standards https://cwiki.apache.org/confluence/x/C4B2
* Simplification of the code base by leveraging various framework tools
(e.g. "entity-auto" services)
* Numerous features, bug fixes and refactoring of the code base.

For more details please refer to the release notes,
http://ofbiz.apache.org/release-notes-16.11.01.html .

All users of previous releases including:

* Apache OFBiz 13.07.*
* Apache OFBiz 12.04.*
* Apache OFBiz 11.04.*

are encouraged to upgrade to this last version and to get in touch with the
community (at user@ofbiz.apache.org) to provide feedback or to receive help
in the upgrade.

The release file can be downloaded following the instructions in the OFBiz
download page:

http://ofbiz.apache.org/download.html
http://ofbiz.apache.org/download.html#vulnerabilities

*Special Dedication*

The 16.11 releases are all dedicated to the memory of OFBiz Committer and
ex PMC member Adrian Crum. Adrian passed away on 1st January 2016 and his
loss is strongly felt. He was a valued member of the OFBiz community and
his legacy will live on in the OFBiz codebase and in the lives of everyone
he touched.

The OFBiz community.


Re: New fork available on GITHUB

2016-11-28 Thread Jacopo Cappellato
On Mon, Nov 28, 2016 at 12:26 PM, Pierre Smits 
wrote:

> Thank you for the suggestion and recommendation, Jacopo.
>

You are most welcome, and I wish you good luck for your initiative.

Jacopo


Re: New fork available on GITHUB

2016-11-28 Thread Jacopo Cappellato
On Mon, Nov 28, 2016 at 11:14 AM, Pierre Smits 
wrote:

> ...
> Should you have any questions and/or remarks, feel free to post these to
> this mailing list.
>

Since there are more than 400 forks of the official OFBiz mirror in GitHub
[*], it is not feasible to use these mailing lists to discuss
questions/remarks specific to them. If all the owners of each fork would do
the same then the discussions in this list would be very confusing. I
recommend you use other tools to communicate with interested users like for
examples the ones provided by GitHub (e.g. pull requests).

Thanks,

Jacopo


[*] https://github.com/apache/ofbiz


Re: OFBiz setup process can't be completed

2016-10-12 Thread Jacopo Cappellato
On Wed, Oct 12, 2016 at 6:37 PM, Mike  wrote:

> Easy for you to say because you are an expert.  What about a complete
> beginner who is trying to setup a new system.  I have never really known
> (for sure) if my system was setup properly because of this error.  Errors
> spewing in the logs promotes a lack of confidence in the product.


I agree with you Mike: a tool/feature that is available but incomplete or
broken cause confusion and lack of confidence.

Jacopo


Re: OFBiz setup process can't be completed

2016-10-12 Thread Jacopo Cappellato
On Wed, Oct 12, 2016 at 4:30 PM, Jacques Le Roux <
jacques.le.r...@les7arts.com> wrote:

> The problem is we don't know if it's really broken.
>
> We also don't know if users are really using it, and even who really
> cares...
>
> Jacques


For me a simple rule of thumb is: if the code is broken/incomplete since a
long time and no one is reporting bugs and providing patches then the
feature is not used and/or maintained and should be dropped.

Jacopo


Re: OFBiz setup process can't be completed

2016-10-12 Thread Jacopo Cappellato
If that feature is broken and no one is maintaining it, I would suggest to
remove it to avoid confusion on users.

Jacopo



On Wed, Oct 12, 2016 at 10:04 AM, Scott Gray 
wrote:

> It was an unreasonable proposition and I think you know that.
>
> I've never looked at the tarpit code to be honest, it was just the first
> example of an old contribution from you that came to mind.
>
> Regards
> Scott
>
> On 12/10/2016 19:13, "Jacques Le Roux" 
> wrote:
>
> > Le 11/10/2016 à 23:59, Scott Gray a écrit :
> >
> >> I hope the committer who introduced this feature will take care of the
> >>>
> >> rest. Else maybe we should remove it...
> >>
> >> Jacques I think you've been around long enough to know that a
> committer's
> >> responsibility to a contribution doesn't extend to years of support.
> If I
> >> found a bug in your tarpit/ProtectedView code I wouldn't suddenly expect
> >> you to fix it nor would I threaten to remove it.
> >>
> >> Regards
> >> Scott
> >>
> >
> > Scott,
> >
> > It was only a proposition, not even sure there is a bug. I see no Jira
> and
> > I did not check. Funny that you evoke the tarpit/ProtectedView code,
> would
> > you secretly want me to remove it? :)
> >
> > Jacques
> >
> >
>


Re: Proposal: sending the specialpurpose/oagis component to Attic

2016-10-05 Thread Jacopo Cappellato
The component has been removed in rev. 1763454

Thanks,

Jacopo

On Wed, Oct 5, 2016 at 11:16 AM, Jacopo Cappellato <
jacopo.cappell...@hotwaxsystems.com> wrote:

> On Wed, Sep 28, 2016 at 11:22 PM, Mike <mz4whee...@gmail.com> wrote:
>
>> Great.  So everyone seems to agree to dump oagis.  Obviously someone took
>> the time to create this component.  My understanding it is used for
>> automating B2B communication for purchase orders, inventory, etc.  If you
>> want ofbiz to play with the big boys, you need this TYPE of Electronic
>> Data
>> Interchange (EDI) functionality.
>>
>> So:  If you want to dump oagis, please propose alternatives to make ofbiz
>> integrate with EDI.  All ERPs have this.
>>
>>
> Thank you for the feedback Mike.
> I do agree that providing some EDI functionality out of the box is very
> important for an ERP system. OFBiz already has a few mechanisms for data
> exchange that can be leveraged to implement specific or custom
> integrations. The concept of an universal data interchange standard is
> great, but, as far as I know, OAGIS has never reached the critical mass to
> make it a viable solution for all integration needs. By experience I have
> noticed that such standards tend to gain more tractions when they address
> specific industries (e.g. parts interchange formats for the auto parts
> aftermarket industry etc...).
> Most importantly, when it was adopted by OFBiz, the OAGIS license allowed
> us to include its xsd files; but after that, they have been relicensed
> under an incompatible license: as a consequence this component is stuck to
> an years old and unmaintained version making even more difficult to be used
> to integrate with an external system.
>
> Kind regards,
>
> Jacopo
>
>
>


Re: Proposal: sending the specialpurpose/oagis component to Attic

2016-10-04 Thread Jacopo Cappellato
On Wed, Sep 28, 2016 at 11:22 PM, Mike  wrote:

> Great.  So everyone seems to agree to dump oagis.  Obviously someone took
> the time to create this component.  My understanding it is used for
> automating B2B communication for purchase orders, inventory, etc.  If you
> want ofbiz to play with the big boys, you need this TYPE of Electronic Data
> Interchange (EDI) functionality.
>
> So:  If you want to dump oagis, please propose alternatives to make ofbiz
> integrate with EDI.  All ERPs have this.
>
>
Thank you for the feedback Mike.
I do agree that providing some EDI functionality out of the box is very
important for an ERP system. OFBiz already has a few mechanisms for data
exchange that can be leveraged to implement specific or custom
integrations. The concept of an universal data interchange standard is
great, but, as far as I know, OAGIS has never reached the critical mass to
make it a viable solution for all integration needs. By experience I have
noticed that such standards tend to gain more tractions when they address
specific industries (e.g. parts interchange formats for the auto parts
aftermarket industry etc...).
Most importantly, when it was adopted by OFBiz, the OAGIS license allowed
us to include its xsd files; but after that, they have been relicensed
under an incompatible license: as a consequence this component is stuck to
an years old and unmaintained version making even more difficult to be used
to integrate with an external system.

Kind regards,

Jacopo


Proposal: sending the specialpurpose/oagis component to Attic

2016-09-23 Thread Jacopo Cappellato
Hi all,

my proposal is to remove the "oagis" specialpurpose component from the
trunk and record the event in our Attic page [*].
If we will do this, the consequence will be that the component will no more
be available in future releases: if you are using it, or plan to use it,
speak up now! :-)
Otherwise, its source code and interesting concepts will be always
available in our source repository and interested parties could easily
retrieve its sources following the instructions in our Attic page.
The main motivation for this proposal is because of the tricky license of
the XML schema files under specialpurpose/oagis/dtd/
These files are an old and unmaintained version and we could not upgrade
them because since their inclusion in OFBiz the newer versions have been
re-licensed under an incompatible license. Even in they current license,
they require special handling and mention in our LICENSE file and,
considering the complexity of the subject, and the fact that the component
has never attracted much attention (based on the questions or contributions
received in the years), I think it would be safer if we remove it from the
trunk.

Kind regards,

Jacopo

[*] https://cwiki.apache.org/confluence/display/OFBADMIN/OFBiz+Attic


Re: Issue with Increasing tomcat Threads

2016-08-22 Thread Jacopo Cappellato
Hi Ganesh,

there are a few things that can improve the situation, but the proper
solution depends on the specific usage and components involved, so it is
difficult to be precise.

However, here are a few miscellaneous ideas you could consider while you
test:

1) try to (temporarily) move out of the mix the web server and ajp
protocol/connector; let the Tomcat instances communicate directly with the
load balancer; if you experience the same issue then we can exclude that
the problem is in the setup of the ajp connectors; to be noted that recent
versions of Tomcat are very efficient as web servers too

2) are you noticing this in production? are you running some load tests to
recreate the issue? (i.e. with JMeter)

3) are you using the http or https connections (or both)? If both, would it
be possible for you to initially try with http (or https) only, then fine
tune the Tomcat's connector to work properly before testing with https (or
http)? again, this would help to focus the scope of the research and
optimizations

4) the behavior you are noticing (grow, under load, of thread count that
are destroyed after some minutes) may indicate that these threads are
created to maintain the user's session, that if ide are destroyed after the
number of minutes set in the web.xml file of your webapp (see
session-timeout element); how many users/browsers are hitting the system
versus the number of hits each performs? Does your load balancer supports
sticky sessions?

5) the file that is relevant for the proper setup of Tomcat connectors is
in framework/catalina/ofbiz-component.xml

6) when you setup multiple instances of OFBiz in a cluster please make sure
you configure them properly; this blog post may be useful as an
introduction http://www.hotwaxsystems.com/ofbiz/apache-ofbiz-performance/

I will stop for now; based on your feedback I may ask further questions or
may be able to be more precise.

Good luck,

Jacopo


On Mon, Aug 22, 2016 at 9:31 AM, Ganesh Bawne <ganesh4of...@gmail.com>
wrote:

> Hi Jacopo,
>
> Thank for your reply.
>
> Somehow, Satish is not getting the mails of this thread. He is working with
> me.
> Yes, the Tomcat instance is embedded one and we have to tune it to close
> idle threads relatively quickly.
>
> One machine is running an Apache Web server with mod_jk setup to
> communicate with different instances of Ofbiz. Though, the OFbiz instances
> are sometime unresponsive. We observed that the thread count is more when
> this happens. After 10-15 mins the thread counts become normal and
> application run smoothly. So looks like Tomcat is not clearing either idle
> threads or something wrong with configuration in the setup.
>
> If anyone suggest, optimal configurations setting that we can use for OFbiz
> instance running on machine with 2 core processor having 4 GB RAM. The
> machine is dedicated to run only 1 Ofbiz instance.
>
> Thanks,
>
> On Mon, Aug 22, 2016 at 12:18 PM, Jacopo Cappellato <
> jacopo.cappell...@hotwaxsystems.com> wrote:
>
> > Jacques,
> >
> > I don't see how the old appserver component could help Satish to solve
> his
> > problem: Satish, could you please confirm if you are looking to configure
> > the Tomcat instance embedded in OFBiz to handle the load in a cluster?
> >
> > Thanks
> >
> > Jacopo
> >
> > On Mon, Aug 22, 2016 at 8:19 AM, Jacques Le Roux <
> > jacques.le.r...@les7arts.com> wrote:
> >
> > > Hi Satish,
> > >
> > > There is still the appserver component in the R14.12 branch (note that
> > the
> > > R14.12 was not and will never be released
> http://ofbiz.apache.org/downlo
> > > ad.html "Special Notice Regarding Branches 14.12 and 15.12:" section).
> > >
> > > This component was originally in the framework part but we stopped to
> > > support it already years ago and decided to downgrade it and move it to
> > > specialpurpose, then recently in Attic.
> > >
> > > I'd love to see it resurrected but it's not an effort the community
> > > decided to pursue.
> > >
> > > So the best you have is this component and the documentation at
> > > https://cwiki.apache.org/confluence/display/OFBIZ/Run+OFBiz+
> > > under+outside+Application+Servers
> > >
> > > In other words you are on your own on this; though I'd personally, and
> I
> > > guess the community too, appreciate a shareable success in this area!
> > >
> > > Jacques
> > >
> > >
> > >
> > > Le 22/08/2016 à 07:55, satish a écrit :
> > >
> > >> Hi All,
> > >>
> > >> Is there any doc to configure tomcat server on production server.
> > >> Actual

Re: Issue with Increasing tomcat Threads

2016-08-22 Thread Jacopo Cappellato
Jacques,

I don't see how the old appserver component could help Satish to solve his
problem: Satish, could you please confirm if you are looking to configure
the Tomcat instance embedded in OFBiz to handle the load in a cluster?

Thanks

Jacopo

On Mon, Aug 22, 2016 at 8:19 AM, Jacques Le Roux <
jacques.le.r...@les7arts.com> wrote:

> Hi Satish,
>
> There is still the appserver component in the R14.12 branch (note that the
> R14.12 was not and will never be released http://ofbiz.apache.org/downlo
> ad.html "Special Notice Regarding Branches 14.12 and 15.12:" section).
>
> This component was originally in the framework part but we stopped to
> support it already years ago and decided to downgrade it and move it to
> specialpurpose, then recently in Attic.
>
> I'd love to see it resurrected but it's not an effort the community
> decided to pursue.
>
> So the best you have is this component and the documentation at
> https://cwiki.apache.org/confluence/display/OFBIZ/Run+OFBiz+
> under+outside+Application+Servers
>
> In other words you are on your own on this; though I'd personally, and I
> guess the community too, appreciate a shareable success in this area!
>
> Jacques
>
>
>
> Le 22/08/2016 à 07:55, satish a écrit :
>
>> Hi All,
>>
>> Is there any doc to configure tomcat server on production server.
>> Actually,
>> We have multi instance OFBiz setup which is load balanced by separate
>> apache
>> via ajp. We are facing issue on OFBiz instance server having increasing
>> thread randomly and because of this server and application become
>> unresponsive. Usually, this happen with increasing OFBiz instance threads
>> count. We are  using OFBiz version 14.12
>>
>> Thanks
>> Satish Kumar
>>
>>
>>
>> --
>> View this message in context: http://ofbiz.135035.n4.nabble.
>> com/Issue-with-Increasing-tomcat-Threads-tp4691056.html
>> Sent from the OFBiz - User mailing list archive at Nabble.com.
>>
>>
>


Re: Vendor credit memo

2016-08-18 Thread Jacopo Cappellato
Hi,

an alternative approach (that would require some enhancements to the
system) is that of creating a special (non-cash) payment for the credit
memo amount that is applied to the outstanding invoice together with the
cash payment.
For example:
invoice from vendor: $100
credit memo from vendor: $20

then the buyer could create two payment:
cash payment: $80
non cash payment (from credit memo): $20

the two payments can be applied to the original invoice of $100 to fully
pay it.
The cash payment will Credit the Cash Account; the non cash payment will
Credit a special (Asset) account whose balance represents the total amount
of credit memos received from seller and not yet applied.

Thanks for the interesting topic,

Jacopo


On Wed, Aug 10, 2016 at 4:01 PM, Sharan Foga  wrote:

> Hi Oleg
>
> I would use an invoice adjustment for the difference. The purchase invoice
> that is generated from the purchase order assumes that the invoice will be
> the same as the purchase order. When the real invoice appears it may be
> different so you need to be able to handle any variances and at the moment
> I think a invoice adjustment is an easy way to do it.
>
> Sometimes I struggle a little with how payments have been implemented
> because I think they are being used to for 2 slightly different things. One
> is the amount that needs to be paid, and the other is the application of an
> amount to an invoice.  As OFBiz automatically generates the payment and the
> amount to be paid from the purchase order – it gives you the audit trail of
> the original transaction, so if you start adjusting the payment itself, you
> start to lose a bit of that visibility.
>
> It is your choice and depending on how you want to work, it's flexible
> enough to do both.
>
> I'd be interested to hear what other people have done in this situation
> too.
>
> Thanks
> Sharan
>
> On 2016-08-10 14:58 (+0200), Oleg Andreyev 
> wrote:
> > Hi All,
> >
> > I am working with project based on 13.07 and stuck trying to figure out
> how to apply vendor credit memo properly. I don’t mean accounting
> transactions. It’s clear. I mean how to get purchase invoice fully applied
> if it is issued for the full price but vendor issued a credit memo and
> buyer should apply payment with amount less than invoice because this memo.
> It seems this case does not have special solution in OFBiz. What’s come to
> mind is either negative invoice item adjustment or payment that equals to
> credit memo amount. However I think about credit memo as a kind of invoice
> rather than kind of payment.
> >
> > What do you folks think of this case?
> >
> > Thanks,
> > Oleg Andreyev
> >
> >
>


Re: Ofbiz Cookbook

2016-08-13 Thread Jacopo Cappellato
On Fri, Aug 12, 2016 at 12:13 PM, Jacques Le Roux <
jacques.le.r...@les7arts.com> wrote:

> +1
>
> I think Jacopo has more to say about that :)
>
> https://cwiki.apache.org/confluence/display/OFBIZ/Groovy+
> DSL+for+OFBiz+business+logic
>
> Jacques
>
>
Agreed. We could improve the ideas outlined in the current "Groovy DSL for
OFBiz", for which we have in trunk a "plugin" for Eclipse and IntelliJ
(that provides autocompletion); and start converting existing Minilang code
to it.

Jacopo


Re: [jira] Subscription: Patch Available in OFBiz

2016-07-29 Thread Jacopo Cappellato
I would be interested to know if our users are really interested in getting
these weekly emails.
I find these emails useless and unnecessarily long: who is really going
thru the list of tickets that Pierre sends every week and that only shows a
subset of the data (this week 200 of 282 tickets)?
Since this is simply a forward, without any work done to add value to it,
of an automatically generated report I think it would be better to let
individual users decide if they want to subscribe to these notifications
(as Pierre did).
In order to subscribe to these notifications, go to:

https://issues.apache.org/jira/browse/OFBIZ-7933?filter=12314132#

then click on "Details" and then Subscriptions.

Kind regards,

Jacopo


On Fri, Jul 29, 2016 at 8:02 AM, Pierre Smits 
wrote:

> FYI
>
> -- Doorgestuurde bericht --
> Van: 
> Datum: vrijdag 29 juli 2016
> Onderwerp: [jira] Subscription: Patch Available in OFBiz
> Aan: pierre.sm...@gmail.com
>
>
> Issue Subscription
> Filter: Patch Available in OFBiz (200 of 282 issues)
> Patch Available issues in OFBiz
> Subscriber: pfm.smits
>
>


Re: Add tax to billed hours

2016-07-27 Thread Jacopo Cappellato
I agree that the creation of a new ticket is a better idea because that was
probably a different thing, at least accordingly to the last comment on it
posted by Jacques, in which he stated that Pierre and him had an off list
conversation in which Pierre reported that the error was gone in 2010.

Jacopo

On Wed, Jul 27, 2016 at 2:33 PM, gil portenseigne <
gil.portensei...@nereide.fr> wrote:

> Hi,
>
> I agree that creating a new Jira is better.
> Gil
>
>


Re: What IDE for Ofbiz

2016-07-27 Thread Jacopo Cappellato
+1

IntelliJ IDEA is a great tool!

Jacopo

On Wed, Jul 27, 2016 at 7:58 AM, Forrest Rae  wrote:

> IntelliJ IDEA, hands down.  The Java/Groovy debugging support is
> superior.  The IntelliJ Platform SDK is amazing, though not for the
> faint of heart.  There is a learning curve, but it's worth it.  There is
> a reason Google picked it to be the base for Android Studio.
>
> On 07/19/2016 12:13 AM, Pranay Pandey wrote:
> >> Eclipse or IntelliJ IDEA(Free version )
> >
> > Both of these work well. I started using IntelliJ since last 6 months and
> > personally I like it very much.
> >
> > Best regards,
> >
> > Pranay Pandey
> > HotWax Systems
> > http://www.hotwaxsystems.com/
> >
> > On Tue, Jul 19, 2016 at 5:05 AM, james yong 
> wrote:
> >
> >> Hi Puwanat,
> >>
> >> Please make sure that you are registered with OFBiz's mailing list. Else
> >> your post at Nabble will not reach the mailing list.
> >>
> >> Regards,
> >> James
> >>
> >> puwanat_sr wrote
> >>> Dear All
> >>>
> >>> I'm new with OFBIZ
> >>> May I ask you about the best IDE I should use for OFBIZ project
> >>>
> >>> Eclipse or IntelliJ IDEA(Free version )
> >>>
> >>> Thank you very much
> >>
> >>
> >>
> >>
> >>
> >> --
> >> View this message in context:
> >>
> http://ofbiz.135035.n4.nabble.com/What-IDE-for-Ofbiz-tp4688352p4689453.html
> >> Sent from the OFBiz - User mailing list archive at Nabble.com.
> >>
> >
>


Re: [COMMUNITY VOTE] New OFBiz Logo - Please Vote for Your Preferred Choice

2016-07-22 Thread Jacopo Cappellato
For the record, I prefer option 2.
I have casted my vote as well on the survey but there is a chance that I
have messed it up: I have selected Yes for option 2 but didn't select No
for option 1 and 3 (left them empty).

Jacopo

On Fri, Jul 22, 2016 at 3:13 PM, Sharan Foga  wrote:

> Hi Everyone
>
> As mentioned I'd like to have a community vote for our new logo as the
> discussion threads were becoming a little difficult to follow. Essentially
> this vote is about selecting which design style you like the best that we
> want to move ahead with. This means that if for example the majority choose
> the existing logo then that's what we will try to refine and make into our
> official logo.
>
> _IMPORTANT NOTE_: The link to the vote is at the bottom of my email and
> clearly labelled: “*Link to Logo Vote*:”
>
> Kenneth has spent some time preparing some examples of each of the logos
> printed in different situations to give us a better idea of what it could
> look like. This means that whatever design we choose we still have options
> to change the colour of the logo for printing.
>
> I've selected the following 3 options for the vote (as there were some
> ideas in the last round that no-one liked:-).
>
> _*Option 1 : Our Existing Logo with Updated 'Registered' Symbol*_
> I've included this option in the vote as we have a couple of people that
> strongly support this one. One thing to be aware of is that the quality of
> our existing logo is not very good, it is blurry and doesn't resize well so
> Kenneth has mentioned that some cleanup work will need to done to try and
> correct this.
>
> It looks like this:
> https://cwiki.apache.org/confluence/download/attachments/61317052/Original-Ofbiz.png?api=v2
>
> _*Option 2: Corrected OFBiz Name with New Feather *_
> I've included this option in the vote as many people requested that we
> correct the spelling of OFBiz in our logo to match our project name. Also
> as Apache has rebranded their feather, this new feather was added to the
> logo.
>
> It looks like this:
> https://cwiki.apache.org/confluence/download/attachments/61317052/NewFeather-OFBiz.png?api=v2
>
> _*Option 3: Power OFBiz*_
> I've included this option with its original colour gradient as some people
> liked the style, and others liked the style but not the colour. BTW I found
> out that the circle was meant to represent a power button (ie for switching
> on something on or off).  One concern that was noted was that the gradient
> would be difficult to print. Kenneth mentioned that he didn't think this
> would be an issue for a professional printer.
>
> Some people liked this option with a blue power button instead so if you
> were one of those then please add in the comments box that you prefer the
> power button to be blue.
>
> It looks like this:
> https://cwiki.apache.org/confluence/download/attachments/61317052/Power-OFBiz.png?api=v2
>
> *_Making Your Choice_*
> The survey vote contains images of each of these logos so you will be able
> to see them when you vote. Please vote for only one of the options. For
> each option in the survey I've also added a comment box for any additional
> feedback.
>
> Please use the following link to vote:
>
> *Link to Logo Vote: https://www.surveymonkey.com/r/3J2H3RX
> *
>
> I'll keep the survey open until the next Wednesday so hopefully that will
> give everyone time to respond. Once complete I will summarise and post the
> results to both user and dev lists.
>
> As an additional note – whichever we choose, the ASF will pay for us to
> get some stickers etc professionally printed so hopefully we will have some
> available for Apachecon later in the year.
>
> Anyway Happy Voting Everyone!
>
> Thanks
> Sharan
>
>


Re: Is a single GeronimoTransactionManager shared between all tenants in a multi-tenant setup?

2016-07-21 Thread Jacopo Cappellato
I am glad to hear you have at least a plan of action and you can move on.

Good luck

Jacopo

On Thu, Jul 21, 2016 at 9:16 AM, Justin Robinson <
ofbiz-10.04-downst...@fluidnotions.com> wrote:

> It was a chicken egg case. The transaction manger wasn't the problem. But I
> am getting time outs now with tomcat nio exec threads being blocked in
> UtilCache and CachedClassloader those are major synchronization bottle
> necks but I have already updated then both to ofbiz 14. Anyway I suppose I
> should search the mail archive and then try a new thread.
>
>
>
> On Wed, Jul 20, 2016 at 6:32 PM, Jacopo Cappellato <
> jacopo.cappell...@hotwaxsystems.com> wrote:
>
> > Is it possible that your code is creating EntityListIterator objects and
> > not properly closing them? This may cause connections to stay open until
> > the SqlProcessor objects are finalized.
> > My guess is that the connection leaks are happening before the
> > finalization, and not as a consequence of it, because EntityListIterator
> > are not properly closed, and a db transaction is active when the finalize
> > method attempts to close the connection.
> > Based on the above assumptions, that could be wrong, I don't think that
> > there is an interference of transactions for different tenants, but
> rather
> > data that you would expect to see is rolled back when the connection is
> > closed before a commit.
> > Please try to investigate in this direction and let me know if you do any
> > progress.
> >
> > Good luck!
> >
> > Jacopo
> >
> > On Wed, Jul 20, 2016 at 1:51 PM, Jacopo Cappellato <
> > jacopo.cappell...@hotwaxsystems.com> wrote:
> >
> > > Hi Justin,
> > >
> > > On Wed, Jul 20, 2016 at 12:37 PM, Justin Robinson <
> > > ofbiz-10.04-downst...@fluidnotions.com> wrote:
> > >
> > >> I am really just interested in the architecture, it's no so much an
> > issue
> > >> with any version of ofbiz. (In fact I am working on a system based on
> > >> ofbiz, it would be better to replace it with pure ofbiz, but that is
> not
> > >> my
> > >> decision to make). I hope you will still be willing to discuss your
> > >> implementation regardless of that fact.
> > >>
> > >
> > > Definitely!
> > >
> > >
> > >>
> > >> Yes org.ofbiz.geronimo.GeronimoTransactionFactory
> > >> calls ConnectionFactoryLoader.getInstance().getConnection(helperInfo,
> > >> datasourceInfo.getInlineJdbc());
> > >> which is implemented
> > >> through
> > >>
> >
> org.ofbiz.entity.connection.DBCPConnectionFactory.getConnection(GenericHelperInfo,
> > >> Element) which uses a
> > >> ConcurrentHashMap to store a connection pool per tenant datasource and
> > it
> > >> seems to work very well, the correct pool is provided to the
> appropriate
> > >> tenant threads.
> > >>
> > >> This is an intermittent issue when testing with 50-100 tenants,
> > >> transactions across tenants seem to collide occasionally. At least
> that
> > >> seems to be the case, I have stepped through the code in a debugger.
> > >>
> > >> It seem to happen in SqlProcessor finalize method, the gc calls
> finalize
> > >> and when the connection is closed (returned to the pool) it calls
> commit
> > >> first and then rolls back because a transaction is in progress as a
> > result
> > >> the connection is leaked and doesn't return to the pool. This is
> clearly
> > >> seen on a massive scale in jprofiler on the jdbc probe page.
> > >>
> > >
> > > Hmmm... this is an interesting detail, there could be an issue in the
> > > SqlProcessor class or maybe in the way that is used in your framework.
> > >
> > > I will dig into this more and let you know if I find something
> > interesting.
> > >
> > > Jacopo
> > >
> > >
> > >>
> > >> Is it a limitation of the architecture? Is it possible to provide a
> > >> TransactionManger per tenant in ThreadLocal or would that not work?
> > >>
> > >> Or am I missing something here? I realise it's a complex issue, but I
> am
> > >> trying to stay as close to ofbiz as I can I hope one day we can
> replace
> > >> the
> > >> framework with a pure ofbiz implementation. I'd rather not make a
> change
> > >> like this which diverges from ofbiz

Re: Is a single GeronimoTransactionManager shared between all tenants in a multi-tenant setup?

2016-07-20 Thread Jacopo Cappellato
Is it possible that your code is creating EntityListIterator objects and
not properly closing them? This may cause connections to stay open until
the SqlProcessor objects are finalized.
My guess is that the connection leaks are happening before the
finalization, and not as a consequence of it, because EntityListIterator
are not properly closed, and a db transaction is active when the finalize
method attempts to close the connection.
Based on the above assumptions, that could be wrong, I don't think that
there is an interference of transactions for different tenants, but rather
data that you would expect to see is rolled back when the connection is
closed before a commit.
Please try to investigate in this direction and let me know if you do any
progress.

Good luck!

Jacopo

On Wed, Jul 20, 2016 at 1:51 PM, Jacopo Cappellato <
jacopo.cappell...@hotwaxsystems.com> wrote:

> Hi Justin,
>
> On Wed, Jul 20, 2016 at 12:37 PM, Justin Robinson <
> ofbiz-10.04-downst...@fluidnotions.com> wrote:
>
>> I am really just interested in the architecture, it's no so much an issue
>> with any version of ofbiz. (In fact I am working on a system based on
>> ofbiz, it would be better to replace it with pure ofbiz, but that is not
>> my
>> decision to make). I hope you will still be willing to discuss your
>> implementation regardless of that fact.
>>
>
> Definitely!
>
>
>>
>> Yes org.ofbiz.geronimo.GeronimoTransactionFactory
>> calls ConnectionFactoryLoader.getInstance().getConnection(helperInfo,
>> datasourceInfo.getInlineJdbc());
>> which is implemented
>> through
>> org.ofbiz.entity.connection.DBCPConnectionFactory.getConnection(GenericHelperInfo,
>> Element) which uses a
>> ConcurrentHashMap to store a connection pool per tenant datasource and it
>> seems to work very well, the correct pool is provided to the appropriate
>> tenant threads.
>>
>> This is an intermittent issue when testing with 50-100 tenants,
>> transactions across tenants seem to collide occasionally. At least that
>> seems to be the case, I have stepped through the code in a debugger.
>>
>> It seem to happen in SqlProcessor finalize method, the gc calls finalize
>> and when the connection is closed (returned to the pool) it calls commit
>> first and then rolls back because a transaction is in progress as a result
>> the connection is leaked and doesn't return to the pool. This is clearly
>> seen on a massive scale in jprofiler on the jdbc probe page.
>>
>
> Hmmm... this is an interesting detail, there could be an issue in the
> SqlProcessor class or maybe in the way that is used in your framework.
>
> I will dig into this more and let you know if I find something interesting.
>
> Jacopo
>
>
>>
>> Is it a limitation of the architecture? Is it possible to provide a
>> TransactionManger per tenant in ThreadLocal or would that not work?
>>
>> Or am I missing something here? I realise it's a complex issue, but I am
>> trying to stay as close to ofbiz as I can I hope one day we can replace
>> the
>> framework with a pure ofbiz implementation. I'd rather not make a change
>> like this which diverges from ofbiz architecture. How would you solve this
>> issue?
>>
>>
>> On Wed, Jul 20, 2016 at 1:17 PM, Jacopo Cappellato <
>> jacopo.cappell...@hotwaxsystems.com> wrote:
>>
>> > Hi Justin,
>> >
>> > your understanding of the class implementation is correct and there may
>> be
>> > a chance that some code may need to be improved, but I am not sure as I
>> > could only give a cursory look at the code.
>> > By the way, I see that the code in GeronimoTransactionManager calls a
>> > "tenant-aware" method in DBCPConnectionFactory and this should provide
>> the
>> > correct connection to every thread.
>> >
>> > Could you please elaborate more on your concern? If you could share a
>> > usage/failure scenario to recreate the issue it would be great too.
>> >
>> > Thanks,
>> >
>> > Jacopo
>> >
>> > On Wed, Jul 20, 2016 at 6:38 AM, Justin Robinson <
>> > ofbiz-10.04-downst...@fluidnotions.com> wrote:
>> >
>> > > I am trying to understand the database connection pooling in ofbiz 14,
>> > > which uses dbcp2.
>> > >
>> > > In the class org.ofbiz.entity.connection.DBCPConnectionFactory there
>> is a
>> > > static ConcurrentHashMap which provides a ManagedDataSource for each
>> > > tenant.
>> > >
>> > > But when it comes to obtaining a transaction manager reference, it
>> looks
>> > > like there is one global instance for all tenants.
>> > >
>> > > getTransactionManager in org.ofbiz.geronimo.GeronimoTransactionFactory
>> > > returns the static reference to a single GeronimoTransactionManager.
>> > >
>> > > In multi tenant testing overlapping from different tenants seem like
>> they
>> > > interact with eachother.
>> > >
>> > > Can you explain how the implementation is supposed to work in with
>> multi
>> > > tenancy ?
>> > >
>> >
>>
>
>


Re: Is a single GeronimoTransactionManager shared between all tenants in a multi-tenant setup?

2016-07-20 Thread Jacopo Cappellato
Hi Justin,

On Wed, Jul 20, 2016 at 12:37 PM, Justin Robinson <
ofbiz-10.04-downst...@fluidnotions.com> wrote:

> I am really just interested in the architecture, it's no so much an issue
> with any version of ofbiz. (In fact I am working on a system based on
> ofbiz, it would be better to replace it with pure ofbiz, but that is not my
> decision to make). I hope you will still be willing to discuss your
> implementation regardless of that fact.
>

Definitely!


>
> Yes org.ofbiz.geronimo.GeronimoTransactionFactory
> calls ConnectionFactoryLoader.getInstance().getConnection(helperInfo,
> datasourceInfo.getInlineJdbc());
> which is implemented
> through
> org.ofbiz.entity.connection.DBCPConnectionFactory.getConnection(GenericHelperInfo,
> Element) which uses a
> ConcurrentHashMap to store a connection pool per tenant datasource and it
> seems to work very well, the correct pool is provided to the appropriate
> tenant threads.
>
> This is an intermittent issue when testing with 50-100 tenants,
> transactions across tenants seem to collide occasionally. At least that
> seems to be the case, I have stepped through the code in a debugger.
>
> It seem to happen in SqlProcessor finalize method, the gc calls finalize
> and when the connection is closed (returned to the pool) it calls commit
> first and then rolls back because a transaction is in progress as a result
> the connection is leaked and doesn't return to the pool. This is clearly
> seen on a massive scale in jprofiler on the jdbc probe page.
>

Hmmm... this is an interesting detail, there could be an issue in the
SqlProcessor class or maybe in the way that is used in your framework.

I will dig into this more and let you know if I find something interesting.

Jacopo


>
> Is it a limitation of the architecture? Is it possible to provide a
> TransactionManger per tenant in ThreadLocal or would that not work?
>
> Or am I missing something here? I realise it's a complex issue, but I am
> trying to stay as close to ofbiz as I can I hope one day we can replace the
> framework with a pure ofbiz implementation. I'd rather not make a change
> like this which diverges from ofbiz architecture. How would you solve this
> issue?
>
>
> On Wed, Jul 20, 2016 at 1:17 PM, Jacopo Cappellato <
> jacopo.cappell...@hotwaxsystems.com> wrote:
>
> > Hi Justin,
> >
> > your understanding of the class implementation is correct and there may
> be
> > a chance that some code may need to be improved, but I am not sure as I
> > could only give a cursory look at the code.
> > By the way, I see that the code in GeronimoTransactionManager calls a
> > "tenant-aware" method in DBCPConnectionFactory and this should provide
> the
> > correct connection to every thread.
> >
> > Could you please elaborate more on your concern? If you could share a
> > usage/failure scenario to recreate the issue it would be great too.
> >
> > Thanks,
> >
> > Jacopo
> >
> > On Wed, Jul 20, 2016 at 6:38 AM, Justin Robinson <
> > ofbiz-10.04-downst...@fluidnotions.com> wrote:
> >
> > > I am trying to understand the database connection pooling in ofbiz 14,
> > > which uses dbcp2.
> > >
> > > In the class org.ofbiz.entity.connection.DBCPConnectionFactory there
> is a
> > > static ConcurrentHashMap which provides a ManagedDataSource for each
> > > tenant.
> > >
> > > But when it comes to obtaining a transaction manager reference, it
> looks
> > > like there is one global instance for all tenants.
> > >
> > > getTransactionManager in org.ofbiz.geronimo.GeronimoTransactionFactory
> > > returns the static reference to a single GeronimoTransactionManager.
> > >
> > > In multi tenant testing overlapping from different tenants seem like
> they
> > > interact with eachother.
> > >
> > > Can you explain how the implementation is supposed to work in with
> multi
> > > tenancy ?
> > >
> >
>


Re: Is a single GeronimoTransactionManager shared between all tenants in a multi-tenant setup?

2016-07-20 Thread Jacopo Cappellato
Hi Justin,

your understanding of the class implementation is correct and there may be
a chance that some code may need to be improved, but I am not sure as I
could only give a cursory look at the code.
By the way, I see that the code in GeronimoTransactionManager calls a
"tenant-aware" method in DBCPConnectionFactory and this should provide the
correct connection to every thread.

Could you please elaborate more on your concern? If you could share a
usage/failure scenario to recreate the issue it would be great too.

Thanks,

Jacopo

On Wed, Jul 20, 2016 at 6:38 AM, Justin Robinson <
ofbiz-10.04-downst...@fluidnotions.com> wrote:

> I am trying to understand the database connection pooling in ofbiz 14,
> which uses dbcp2.
>
> In the class org.ofbiz.entity.connection.DBCPConnectionFactory there is a
> static ConcurrentHashMap which provides a ManagedDataSource for each
> tenant.
>
> But when it comes to obtaining a transaction manager reference, it looks
> like there is one global instance for all tenants.
>
> getTransactionManager in org.ofbiz.geronimo.GeronimoTransactionFactory
> returns the static reference to a single GeronimoTransactionManager.
>
> In multi tenant testing overlapping from different tenants seem like they
> interact with eachother.
>
> Can you explain how the implementation is supposed to work in with multi
> tenancy ?
>


Re: [DISCUSSION] Anticipate the end of life of the 13.07 branch and backport some non-bug related changes to the 14.12 and 15.12 branches

2016-06-29 Thread Jacopo Cappellato
On Wed, Jun 29, 2016 at 11:49 AM, Christian Geisert <
christian.geis...@isu-gmbh.de> wrote:

> ...
> My proposal is to release 14.12 ASAP, after that dropping 13.07 and then
> trying to do a release 16.x with Gradle. And a release of 15.12in
> between wouldn't be bad either ;)
>
>
Thank you Christian.
Your proposal makes sense but the problem is that we will not be able to
release (14.12, 15.12 etc...) until we have removed all the jars from the
distribution, and implementing this in the branches will require some
layout changes that will bring instability: the releases will be delayed
regardless and if we want to implement two different mechanisms for
downloading the jars for 14.12 vs the trunk and 16.x etc... than the
codebases will become rather different and more difficult to maintain; and
the extra effort will have to be backed up by the interested users. We have
to consider these aspects and do a reality check on resources before moving
in any direction.

Jacopo


[DISCUSSION] Anticipate the end of life of the 13.07 branch and backport some non-bug related changes to the 14.12 and 15.12 branches

2016-06-28 Thread Jacopo Cappellato
Hi all,

as you may know we are working at migrating the build scripts of the OFBiz
trunk from Ant to Gradle.
Together with this important change we are also modifying, for policy
reasons, the way we distribute the external dependencies (i.e., the jar
files needed by OFBiz): the required jars will be downloaded at build time.
Since these changes are not bug fixes, the current plan is to do these
changes only in the trunk and do not backport them to the active branches,
that are currently:

* 13.07
* 14.12
* 15.12

However, we will still have to modify these branches by removing the
external jar files and download them using Ivy.

The first concern is that we will have to work on and stabilize two fronts:
Ivy for the 3 current release branches and Gradle for the trunk and the
future branches.
The second concern is that, as a consequence, we will have, for several
years, significant differences in the setup/build steps between the old
releases and the new ones that could cause confusion and regressions when
bugs are backported.

We have already issued 3 releases from the 13.07 branch and we have a
tentative plan to issue one more release around February 2017 that would be
the last release of this series.
As regards 14.12 and 15.12 branches, no releases have been issued yet.

Based on these details I would like you to consider the following decisions:

1) anticipate the end of life of the release branch 13.07 at now; we would
not issue the fourth release as initially planned
2) once stabilized, backport to 14.12 and 15.12 all the changes required to
build the system and download its dependencies with Gradle

Please express your opinion on each of them separately, since they are
independent (i.e., you could agree/disagree on the first/second/both).

Thanks,

Jacopo


Re: [MARKETING] New Version of Updated OFBiz Logo

2016-06-27 Thread Jacopo Cappellato
Thanks, they were good to me.
However I think we should use the name "Apache OFBiz" because this is the
official name that was registered.

Jacopo

On Mon, Jun 27, 2016 at 8:57 AM, Sharan Foga  wrote:

> Hi  Everyone
>
> Thank you all very much for your feedback. As it seems to have been a
> little mixed, some liking the general idea and others not, I'll go back to
> Kenneth and we'll see what other options we can come up with.
>
> Thanks
> Sharan
>
> On 2016-06-23 17:16 (+0200), "Sharan Foga" wrote:
> > Hi Everyone
> >
> > I've got an example of a proposed updated OFBiz logo to share with
> everyone.
> >
> >
> https://cwiki.apache.org/confluence/download/attachments/61317052/OFBiz%20Logo.png?api=v2
> >
> > In fact there are two of them, one with the word Apache and one without.
> I've uploaded the sample logo here and it's the first one (i.e. the top
> line) with the white background that we are looking at.
> >
> > For those who recognise it \u2013 we've gone a bit retro and picked up
> this circle icon from the original OFBiz logo when the project first came
> to Apache. Instead of using the original blue colour, we've incorporated
> the same (orange, red and purple) colour scheme as the new Apache feather.
>   http://apache.org/
> >
> > We've also changed the OFBiz lettering to orange as it seemed to go well
> with the new Apache colours.
> >
> > For information we've also included some examples of what it would look
> like on different coloured backgrounds with white and black lettering.
> >
> > Anyway please take a look and let me have your comments and feedback.
> >
> > Thanks
> > Sharan
> >
>


Re: The OFBiz application is now an ASF registered trademark.

2016-06-15 Thread Jacopo Cappellato
This is really important for our project and I am proud we have been
successful... it took more than one year but we did it :-)

To be precise, the registered trademark is not for the OFBiz *application*;
it is the "Apache OFBiz" trademark that has been registered.

Jacopo

On Wed, Jun 15, 2016 at 11:23 AM, Sharan-F  wrote:

> Hi Jacques
>
> I'm hoping that we might have some ideas for the new logo to share with the
> community later next week. We'll bear in mind the positioning of the
> registered trademark symbol.
>
> Thanks
> Sharan
>
>
>
> --
> View this message in context:
> http://ofbiz.135035.n4.nabble.com/The-OFBiz-application-is-now-an-ASF-registered-trademark-tp4683900p4683921.html
> Sent from the OFBiz - User mailing list archive at Nabble.com.
>


Re: {MARKETING] New OFBiz Logo for Website

2016-05-30 Thread Jacopo Cappellato
+1 for the second one.
I also like the idea of using the capitalization as in OFBiz

Jacopo


On Mon, May 30, 2016 at 1:55 PM, Pierre Smits 
wrote:

> I believe we have. A majority expressed a +1 for the second option. The
> comment were regarding a follow up on that. So these can be addressed after
> the implementation of #2.
>
> Or you can wait.
>
> Best regards,
>
> Pierre
>
> On Monday, May 30, 2016, Sharan-F  wrote:
>
> > Hi All
> >
> > It sounds like we havent reached a consensus after all :-)  and so maybe
> > need to discuss this some more.
> >
> > Thanks
> > Sharan
> >
> >
> >
> >
> >
> > --
> > View this message in context:
> >
> http://ofbiz.135035.n4.nabble.com/MARKETING-New-OFBiz-Logo-for-Website-tp4681769p4681835.html
> > Sent from the OFBiz - User mailing list archive at Nabble.com.
> >
>
>
> --
> Pierre Smits
>
> ORRTIZ.COM 
> OFBiz based solutions & services
>
> OFBiz Extensions Marketplace
> http://oem.ofbizci.net/oci-2/
>


Re: Apachecon NA 2016 - Summary Update

2016-05-19 Thread Jacopo Cappellato
Thanks Sharan,

this is a very useful summary; I am glad you and Jinghai Shi were there to
represent the OFBiz community!

Jacopo

On Wed, May 18, 2016 at 11:47 AM, Divesh Dutta <
divesh.du...@hotwaxsystems.com> wrote:

> Thanks for sharing your experience Sharan.
>
>
> Regards
> --
> Divesh Dutta
>
> On Tue, May 17, 2016 at 2:18 PM, Sharan-F  wrote:
>
> > Hi Everyone
> >
> > I'm still getting over the jetlag but here is a quick update of my
> > Apachecon
> > experience last week.
> >
> > I went as a TAC volunteer and volunteered to help out on the Apache
> booth.
> > I
> > think we had around 18 people on TAC from various countries including
> > India,
> > Brazil, Spain, Switzerland, China, Turkey, Egypt and various parts of the
> > US.
> >
> > My main duty was talking to people about Apache and handing out Apache
> > branded caps, stickers and swiss army knives (yes swiss army knives!).
> >
> > On the first day I saw a familiar name  - Jinghai Shi, one of our OFBiz
> > Committers from China! He had come over for both Apache Big Data and
> > Apachecon and throughout the week we spent quite a bit of time chatting
> > about OFBiz!
> > Unfortunately we didn't come across anyone else from the OFBiz community,
> > and I think that could be related to the conference location as I know we
> > have had good Apachecon attendance figures in the past.
> >
> > I did meet up with quite a few people including a team from NASA who are
> > using a lot of Apache projects from the big data side, and the conference
> > included a complete Geospatial Track.Big data seems to be a bit of a hot
> > topic so is getting quite a few more attendees. We captured the
> attendance
> > figures for the majority of the sessions and will pass them on to the
> > Apachecon team.
> >
> > On Wednesday I participated in some Media Analyst training. This was
> mainly
> > focussed on understanding techniques and tools about how to market and
> > promote your project in the media. Our final test was to promote  (or
> > 'pitch') our project to Stephen O'Grady, Industry Analyst from Red Monk
> > (http://redmonk.com/)  who was also one of the Apachecon keynote
> > speakers. I
> > did a pitch for 'OFBiz' which went OK but he said that I needed to also
> > include some minimum technical details so that he could see where OFBiz
> > sits
> > technically (and since I'm not too techie – I didnt know it!). Anyway
> this
> > is an action point that I need to work on so I need to find a simple
> > technical description of what OFBiz is...(so any feedback welcome)
> >
> > My Apachecon presentations were scheduled for the last day (Friday 13th).
> > My
> > first talk on consensus attracted 15 people and my OFBiz talk on
> > configuration attracted 5 people.
> >
> > I think that all the sessions from both conferences have audio recordings
> > and the keynotes also have video. There is some editing work going on at
> > the
> > moment to get all the audio recording published and you will find them on
> > feathercast (see link below)
> >
> > http://feathercast.apache.org/
> >
> > I really enjoyed my Apachecon experience and would recommend it to
> anyone.
> > It will be time to start thinking about Apachecon EU soon.
> >
> > Thanks
> > Sharan
> >
> >
> >
> >
> > --
> > View this message in context:
> >
> http://ofbiz.135035.n4.nabble.com/Apachecon-NA-2016-Summary-Update-tp4680675.html
> > Sent from the OFBiz - User mailing list archive at Nabble.com.
> >
>


[ANNOUNCE] Apache OFBiz 12.04.06 released

2016-04-05 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache
OFBiz 12.04.06".

Apache OFBiz™ is an open source product for the automation of enterprise
processes that includes framework components and business applications.

http://ofbiz.apache.org/

"Apache OFBiz 12.04.06" is a bug fix release for the 12.04 series; all
users of Apache OFBiz 12.04.* series are encouraged to upgrade to this
latest release because the new release contains several improvements and
bug fixes, including fixes for the following vulnerabilities:

CVE-2015-3268 - Information disclosure vulnerability
CVE-2016-2170 - Java deserialization vulnerability

For remediation steps please refer to:
https://cwiki.apache.org/confluence/x/ePmnAw

Release notes are available here:

http://ofbiz.apache.org/release-notes-12.04.06.html

Note: this is the last release of the 12.04 series so please consider to
upgrade to the 13.07 series.

The release file can be downloaded following the instructions in the OFBiz
download page:

http://ofbiz.apache.org/download.html
http://ofbiz.apache.org/download.html#vulnerabilities

The OFBiz Team.


  1   2   3   4   5   6   7   8   9   >