[jira] Updated: (OFBIZ-2000) Added check availability functionality on new create profile page of e commerce.

2009-02-18 Thread Richa Goyal (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-2000?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Richa Goyal updated OFBIZ-2000: --- Attachment: CheckAvailUsername.patch Updated the patch, Used fail-property instead of fail-message

[jira] Commented: (OFBIZ-2000) Added check availability functionality on new create profile page of e commerce.

2009-02-18 Thread Jacques Le Roux (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-2000?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=12674527#action_12674527 ] Jacques Le Roux commented on OFBIZ-2000: Hi Richa, I can't see how to test this

[jira] Commented: (OFBIZ-469) . Adding a specialised dialog box for PAID IN OUT (with seed data and perhaps a mechanism to update these data)

2009-02-18 Thread Jacques Le Roux (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-469?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=12674529#action_12674529 ] Jacques Le Roux commented on OFBIZ-469: --- Note : this now uses an enumeration for

Re: [jira] Commented: (OFBIZ-2000) Added check availability functionality on new create profile page of e commerce.

2009-02-18 Thread Richa Goyal
Hi Jacques, When the customer tries to enter existing username in New Customer Page, then on losing focus from the text field , associated js is called and message gets displayed using UI Label. Jacques Le Roux (JIRA) wrote: [

Content related error

2009-02-18 Thread Jacques Le Roux
I got this error using blogs in ECommerce D:\workspace\ofbizRun\applications\ecommerce\webapp\ecommerce\component:\ecommerce\widget\blog\BlogTemplates.xml#FloatLeft (Syntaxe du nom de fichier, de répertoire ou de volume incorrecte) stack trace

Re: [jira] Commented: (OFBIZ-2000) Added check availability functionality on new create profile page of e commerce.

2009-02-18 Thread Richa Goyal
One more thing this functionality has been done for NewCustomer.ftl (new) instead of newcustomer.ftl in ecommerce. For this,as we have double occurrence of newcustomer and viewprofile screens in CustomerScreens.xml, so please comment the former screens uncomment the later ones. Thanks --

Re: [jira] Commented: (OFBIZ-2000) Added check availability functionality on new create profile page of e commerce.

2009-02-18 Thread Jacques Le Roux
Sorry Richa, I'm surely missing something since I can't get it working in any browser (tried FF3, IE8, Opera, Chrome and Safari) Jacques From: Richa Goyal richa.go...@hotwaxmedia.com Hi Jacques, When the customer tries to enter existing username in New Customer Page, then on losing

[jira] Issue Comment Edited: (OFBIZ-2194) Password visible in URL query string hidden parameter (pre/post auth)

2009-02-18 Thread Michele Orru (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-2194?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=12674546#action_12674546 ] euronymous edited comment on OFBIZ-2194 at 2/18/09 1:29 AM: --

[jira] Commented: (OFBIZ-2194) Password visible in URL query string hidden parameter (pre/post auth)

2009-02-18 Thread Michele Orru (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-2194?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=12674546#action_12674546 ] Michele Orru commented on OFBIZ-2194: - Hi David Yes you're right. I'm sorry but I was

[jira] Resolved: (OFBIZ-2194) Password visible in URL query string hidden parameter (pre/post auth)

2009-02-18 Thread Michele Orru (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-2194?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Michele Orru resolved OFBIZ-2194. - Resolution: Fixed Confirmed fixed in rev. 742352 Password visible in URL query string hidden

[jira] Issue Comment Edited: (OFBIZ-2194) Password visible in URL query string hidden parameter (pre/post auth)

2009-02-18 Thread Michele Orru (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-2194?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=12674547#action_12674547 ] euronymous edited comment on OFBIZ-2194 at 2/18/09 1:35 AM: --

[jira] Commented: (OFBIZ-2000) Added check availability functionality on new create profile page of e commerce.

2009-02-18 Thread Rishi Solanki (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-2000?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=12674557#action_12674557 ] Rishi Solanki commented on OFBIZ-2000: -- Hi Jacques, To run this work you need to do

[jira] Commented: (OFBIZ-2000) Added check availability functionality on new create profile page of e commerce.

2009-02-18 Thread Rishi Solanki (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-2000?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=12674563#action_12674563 ] Rishi Solanki commented on OFBIZ-2000: -- Please do the changes in the ;

[jira] Commented: (OFBIZ-1959) Multiple Security Issues (XSRF, XSS, Session Hijacking): exploitation and mitigation

2009-02-18 Thread Michele Orru (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-1959?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=12674572#action_12674572 ] Michele Orru commented on OFBIZ-1959: - Hi David, Hi Jaques. I'm analyzing your patches

[jira] Issue Comment Edited: (OFBIZ-1959) Multiple Security Issues (XSRF, XSS, Session Hijacking): exploitation and mitigation

2009-02-18 Thread Michele Orru (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-1959?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=12674572#action_12674572 ] euronymous edited comment on OFBIZ-1959 at 2/18/09 3:14 AM: --

Re: Security Issues

2009-02-18 Thread euronymous
David E Jones-3 wrote: 2. security vulnerability tests: now we want to hit the public facing (ecommerce, cmssite, etc) apps and the back-end apps to check as many vulnerabilities as we can In reply to your find-bug-campaing: https://issues.apache.org/jira/browse/OFBIZ-1959 See

[jira] Commented: (OFBIZ-2000) Added check availability functionality on new create profile page of e commerce.

2009-02-18 Thread Jacques Le Roux (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-2000?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=12674578#action_12674578 ] Jacques Le Roux commented on OFBIZ-2000: Thanks for the reminder Rishi, I

[jira] Commented: (OFBIZ-2000) Added check availability functionality on new create profile page of e commerce.

2009-02-18 Thread Pranay Pandey (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-2000?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=12674591#action_12674591 ] Pranay Pandey commented on OFBIZ-2000: -- Hello Jacques, IMO your guess is right for

Some advise David about requests and portlets?

2009-02-18 Thread Hans Bakker
Hi David, perhaps you can give me some advice/help especially now you reorganized the request handler and it still fresh in your mind? I want to get away from the donePage stuff and i wonder if you can help me. What i need is to display a portlet, let the portlet call a view which in turn calls

[jira] Commented: (OFBIZ-2135) Dojo html editor problems

2009-02-18 Thread Michele Orru (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-2135?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=12674643#action_12674643 ] Michele Orru commented on OFBIZ-2135: - Mhh good question Jacques... well...If you're

[jira] Commented: (OFBIZ-736) Apache Internet bookshop

2009-02-18 Thread Ean Schuessler (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-736?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=12674693#action_12674693 ] Ean Schuessler commented on OFBIZ-736: -- special purpose component? Apache Internet

[jira] Commented: (OFBIZ-2118) Drop-down Applications Bar

2009-02-18 Thread Ryan Foster (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-2118?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=12674850#action_12674850 ] Ryan Foster commented on OFBIZ-2118: Bruno, I have worked up a relatively simple

[jira] Updated: (OFBIZ-2118) Drop-down Applications Bar

2009-02-18 Thread Ryan Foster (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-2118?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Ryan Foster updated OFBIZ-2118: --- Attachment: bluelightdropdownfix.patch patch to fix dropdown menu in bluelight theme for IE

[jira] Updated: (OFBIZ-2118) Drop-down Applications Bar

2009-02-18 Thread Ryan Foster (JIRA)
[ https://issues.apache.org/jira/browse/OFBIZ-2118?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Ryan Foster updated OFBIZ-2118: --- Attachment: dropdown.js Javascript file to fix dropdown menu in bluelight theme for IE. Drop-down

Re: Security Issues

2009-02-18 Thread David E Jones
On Feb 18, 2009, at 4:25 AM, euronymous wrote: David E Jones-3 wrote: 2. security vulnerability tests: now we want to hit the public facing (ecommerce, cmssite, etc) apps and the back-end apps to check as many vulnerabilities as we can In reply to your find-bug-campaing:

Re: svn commit: r745614 - /ofbiz/trunk/applications/party/servicedef/services.xml

2009-02-18 Thread David E Jones
It is better to not allow HTML in all of the attributes, and instead allow it only in the ones that need it. In other words, using allow- html on the auto-attributes tag is generally a bad practice and instead just use the override tag with allow-html for the specific