Re: buildbot failure in on ofbizTrunkFramework

2020-05-06 Thread Jacques Le Roux
twax.co/>* On Tue, May 5, 2020 at 9:07 PM Jacques Le Roux < jacques.le.r...@les7arts.com> wrote: Hi Suraj, This is due to OFBIZ-11621, OFBIZ-11627, OFBIZ-11637 and OFBIZ-11624 which are all conversion of CRUD simple services to entity-auto Notably checkStatusCustRequest servi

Re: buildbot failure in on ofbizTrunkFramework

2020-05-05 Thread Jacques Le Roux
issues. TIA Jacques Le 05/05/2020 à 11:08, Jacques Le Roux a écrit : Hi, I fixed 2 cases with (but not related to) OFBIZ-11620 Remains the 3 custrequesttests and testCreateTimeEntry failures in both framework only and framework+plugins integration tests. Not sure when they appeared as things

Re: buildbot failure in on ofbizTrunkFramework

2020-05-05 Thread Jacques Le Roux
Hi, I fixed 2 cases with (but not related to) OFBIZ-11620 Remains the 3 custrequesttests and testCreateTimeEntry failures in both framework only and framework+plugins integration tests. Not sure when they appeared as things got blurred. Jacques Le 04/05/2020 à 19:28, Jacques Le Roux a écrit

Re: buildbot failure in on ofbizTrunkFramework

2020-05-04 Thread Jacques Le Roux
Buildbot URL: https://ci.apache.org/ Buildslave for this Build: asf947_ubuntu Build Reason: The AnyBranchScheduler scheduler named 'onTrunkFrameworkCommit' triggered this build Build Source Stamp: [branch trunk] 649614507bab6ff955e243a5858c1353150dfd42 Blamelist: Jacques Le Roux BUILD FAILED

Re: Add notice on previous repository

2020-05-04 Thread Jacques Le Roux
Le 04/05/2020 à 15:16, James Yong a écrit : Hi all, I saw some recent PR from https://github.com/apache/ofbiz Suggest to add a notice to indicate the repository is old and for user to use https://github.com/apache/ofbiz-framework instead. Regards, James +1 Jacques

Re: Upgrade Gradle and Groovy

2020-05-04 Thread Jacques Le Roux
Hi James, I trust a Jira fits Thanks Jacques Le 04/05/2020 à 14:54, James Yong a écrit : Hi all, Current Gradle version used in OFBiz trunk is 5.0. Propose to update to Gradle 6.3 which is the current stable version. Gradle 6.3 requires groovy 2.5.10., but Groovy version used in OFBiz

Site and obsolete Svn info

2020-05-04 Thread Jacques Le Roux
Hi, As I wrote in OFBIZ-11269 at https://s.apache.org/pf2ty, please consider: We should change in the  "Committer Access" section of source-repositories.tpl.php When you first connect you will be prompted to accept the SSL certificate. Verify the certificate is for svn.apache.org. After

Re: OFBIZ-9826 & "Duplicate Service ECA" warning

2020-05-04 Thread Jacques Le Roux
and it seems there is no duplicate seca rule. There are no duplicate seca warning on ./gradlew loadAll or on ./gradlew ofbiz Thanks & Regards -- Deepak Dixit ofbiz.apache.org On Sun, May 3, 2020 at 3:34 PM Jacques Le Roux wrote: Hi, With OFBIZ-9826 we have introduced a "Duplicate Se

OFBIZ-9826 & "Duplicate Service ECA" warning

2020-05-03 Thread Jacques Le Roux
Hi, With OFBIZ-9826 we have introduced a "Duplicate Service ECA" warning. I see a lot of them in log when running integration test[1]. Is it not time to take care of removing those duplicates, or is it a side effect due to tests? Thanks [1]

Re: encrypted columns

2020-05-01 Thread Jacques Le Roux
Le 30/04/2020 à 14:08, Werner Brasch a écrit : Hallo I have set the column jdbcPassword In the entity TenantDataSource to encrypt="true" and it seems to work. It is possible to work on the new tenant. But I don't know how the Security works, is the jdbcPassword now save, how does it works?

Re: OutOfMemoryError: Java heap space

2020-05-01 Thread Jacques Le Roux
Hi Vemula, Your message has been moderated, else it would not have reach this Mailing List. Please subscribe to the user ML for such questions and then use your email client. See why here http://ofbiz.apache.org/mailing-lists.html. You will get a better support, people can answer you on the

[CVE-2019-12425] Apache OFBiz Host Header Injection

2020-04-30 Thread Jacques Le Roux
Severity: Important Vendor: The Apache Software Foundation Versions Affected: OFBiz 17.12.01 Description: Apache OFBiz is vulnerable to Host header injection by accepting arbitrary hosts Mitigation: Upgrade to 17.12.03 or manually apply the commit at OFBIZ-11583 Credit: Pradeep

Re: Welcome Rishi Solanki as new PMC member

2020-04-28 Thread Jacques Le Roux
Felicitations Rishi! Jacques Le 28/04/2020 à 17:46, Swapnil M Mane a écrit : Many congratulations Rishi, welcome on board! - Best regards, Swapnil M Mane, ofbiz.apache.org On Tue, Apr 28, 2020 at 7:53 PM Jacopo Cappellato < jacopo.cappell...@gmail.com> wrote: The OFBiz PMC has invited

Re: svn commit: r1867927 - in /ofbiz/ofbiz-framework/trunk/applications/order: minilang/test/OrderTests.xml src/main/groovy/org/apache/ofbiz/order/OrderTests.groovy

2020-04-27 Thread Jacques Le Roux
version we are not sending these fields. Tests will pass for sure, as they are not mandatory to send. -- Best Regards, Suraj Khurana Senior Technical Consultant On Mon, Apr 27, 2020 at 2:52 PM Jacques Le Roux < jacques.le.r...@les7arts.com> wrote: Hi Suraj, If you mean that there i

Re: Update OFBiz Plugin Stack Wiki page

2020-04-27 Thread Jacques Le Roux
Hi Ravi, I agree with Michael, Most of "that" you should go to Wiki Attic. By "that" I mean not only the pages you spotted Ravi. Should remain in wiki only what can't get to .adoc files. Worse than no documentation is a documentation that is not maintained. That's confusing as hell! So we

Re: Remove the references to R16 in Jira

2020-04-27 Thread Jacques Le Roux
ache OFBiz 16.11.07" is the latest release of OFBiz and it is probably going to be the last one in the 16.11 series" So I think we are good and you can proceed. Jacopo On Mon, Apr 27, 2020 at 11:20 AM Jacques Le Roux < jacques.le.r...@les7arts.com> wrote: Thanks Jacopo, Bu

Re: svn commit: r1867927 - in /ofbiz/ofbiz-framework/trunk/applications/order: minilang/test/OrderTests.xml src/main/groovy/org/apache/ofbiz/order/OrderTests.groovy

2020-04-27 Thread Jacques Le Roux
Hi Suraj, If you mean that there is no explanation but "Tests pass", as it's Svn we can still amend it, what would you suggest? Thanks Jacques Le 27/04/2020 à 08:47, Suraj Khurana a écrit : Hello Jacques, I think we missed the note, comments field during conversion in this commit. Is it

Re: Remove the references to R16 in Jira

2020-04-27 Thread Jacques Le Roux
r 26, 2020 at 2:39 PM Jacques Le Roux < jacques.le.r...@les7arts.com> wrote: Hi, I think we should clearly/officially states that R16 is no longer supported. How did we do that the last time, Jacopo? If nobody is against I'll then remove the references to R16 in Jira Thanks Jacques

Re: OFBiz-Shopify Integration

2020-04-26 Thread Jacques Le Roux
+1 just wonder about the REST and GraphQL part. GirishI know you have some knowledge about that. What do you think? Jacques Le 26/04/2020 à 17:29, Girish Vasmatkar a écrit : Hi Ritesh - This is certainly going to be a great initiative. +1 Best, Girish On Sun, Apr 26, 2020 at 8:49 PM

Remove the references to R16 in Jira

2020-04-26 Thread Jacques Le Roux
Hi, I think we should clearly/officially states that R16 is no longer supported. How did we do that the last time, Jacopo? If nobody is against I'll then remove the references to R16 in Jira Thanks Jacques

Re: Default constructors in JAVA classes

2020-04-26 Thread Jacques Le Roux
, not much changes to be done after this information from Rishi. Thanks everyone. -- Best Regards, Suraj Khurana SENIOR TECHNICAL CONSULTANT mobile: +91 9669750002 email: suraj.khur...@hotwax.co *www.hotwax.co <http://www.hotwax.co/>* On Fri, Apr 24, 2020 at 3:22 PM Jacques Le Roux < jac

Re: Demos are down

2020-04-25 Thread Jacques Le Roux
Hi All, Please follow rather the similar user thread Swapnil M Mane created https://issues.apache.org/jira/browse/INFRA-20189 for the demos issue Jacques Le 25/04/2020 à 11:57, Dikpal Kanungo a écrit : Yes, not able to access demo instances. https://demo-trunk.ofbiz.apache.org/

Re: Ofbiz Apache CRM Request

2020-04-24 Thread Jacques Le Roux
Le 24/04/2020 à 13:37, Jacques Le Roux a écrit : Le 21/04/2020 à 16:16, Jacques Le Roux a écrit : -On which word processing software (WORD, EXCEL) is it possible to export data to the CRM? Forgot to answer this one, this should help https://cwiki.apache.org/confluence/display/OFBIZ/Export

Re: Ofbiz Apache CRM Request

2020-04-24 Thread Jacques Le Roux
Le 21/04/2020 à 16:16, Jacques Le Roux a écrit : -On which word processing software (WORD, EXCEL) is it possible to export data to the CRM? Forgot to answer this one, this should help https://cwiki.apache.org/confluence/display/OFBIZ/Export+to+Excel Jacques

Re: Default constructors in JAVA classes

2020-04-24 Thread Jacques Le Roux
On Thu, Apr 23, 2020 at 12:39 PM Jacques Le Roux < jacques.le.r...@les7arts.com> wrote: Hi, It was mate, actually there was a missing word in my saying, I meant: I agree about changing only non idempotent classes in a 1st approach. That's obviously _NOT_ service and events, but c

Welcome Swapnil M Mane as new PMC member

2020-04-23 Thread Jacques Le Roux
The OFBiz PMC has invited Swapnil M Mane to become member of the committee and we are glad to announce that he has accepted the nomination. On behalf of the OFBiz PMC, welcome on board!

Re: Default constructors in JAVA classes

2020-04-23 Thread Jacques Le Roux
Roux < jacques.le.r...@les7arts.com> wrote: Le 22/04/2020 à 19:58, Jacques Le Roux a écrit : I have still to read the articles an understand the Lombok project and how we could possibly use it I'm thinking about https://projectlombok.org/setup/gradle but I have no ideas yet to what it e

Re: Default constructors in JAVA classes

2020-04-22 Thread Jacques Le Roux
Le 22/04/2020 à 19:58, Jacques Le Roux a écrit : I have still to read the articles an understand the Lombok project and how we could possibly use it I'm thinking about https://projectlombok.org/setup/gradle but I have no ideas yet to what it entails, someone knows? Jacques

Re: Default constructors in JAVA classes

2020-04-22 Thread Jacques Le Roux
Hi, I agree about changing only non idempotent classes in a 1st approach. That's obviously service and events, but could be also few helper and worker classes. We need to check the later and decide one by one. And if they are not idempotent then they should not be called helper or worker. Or

Re: Welcome to Girish Vasmatkar as new committer!

2020-04-22 Thread Jacques Le Roux
Sorry I missed Girish 1st name in subject :/ Le 22/04/2020 à 11:37, Jacques Le Roux a écrit : The OFBiz PMC has invited Girish to become a new committer and we are pleased  to announce that he has accepted. Girish is part of the community for near 2 years and has proposed several smart

Welcome to Vasmatkar as new committer!

2020-04-22 Thread Jacques Le Roux
The OFBiz PMC has invited Girish to become a new committer and we are pleased  to announce that he has accepted. Girish is part of the community for near 2 years and has proposed several smart propositions notably related to security and GraphQL, but not only. Please join me in welcoming and

Welcome James Young as new PMC member

2020-04-22 Thread Jacques Le Roux
The OFBiz PMC has invited James Young to become member of the committee and we are glad to announce that he has accepted the nomination. On behalf of the OFBiz PMC, welcome on board!

Re: Ofbiz Apache CRM Request

2020-04-21 Thread Jacques Le Roux
Le 21/04/2020 à 16:16, Jacques Le Roux a écrit : Also have a look at https://demo-trunk.ofbiz.apache.org/example/control/ExampleOsmGeoLocationPointSet1 Forgot credential: admin/ofbiz

Re: Ofbiz Apache CRM Request

2020-04-21 Thread Jacques Le Roux
Hi Paul, Your message has been moderated. Please subscribe to the user ML for such questions and then use your email client. See why here http://ofbiz.apache.org/mailing-lists.html. You will get a better support, people can answer you on the ML. The wider the audience the better the answers

Re: [VOTE] [RELEASE] Apache OFBiz 17.12.03

2020-04-21 Thread Jacques Le Roux
+1, works for me on Windows 7 verify-ofbiz-release.sh OK init-gradle-wrapper OK Both UIs (back and front ends) OK Integration tests OK (no errors at all after a second test, had in 1st) Jacques Le 21/04/2020 à 10:35, Deepak Dixit a écrit : +1 Thanks & Regards -- Deepak Dixit

Re: [VOTE] [RESULT] Apache OFBiz 17.12.02

2020-04-20 Thread Jacques Le Roux
Hi Taher, I did not understand the points as options but as a sequence of actions, Jacopo? Jacques Le 20/04/2020 à 14:04, Taher Alkhateeb a écrit : I would recommend options 2/3. There is no need for a vote, just a release with a note about 17.12.0 and archive it On Monday, April 20, 2020

Re: [VOTE] [RESULT] Apache OFBiz 17.12.02

2020-04-20 Thread Jacques Le Roux
BTW, I'm disappointed that montastic.com did not send an alert. I even tried when it was done from their UI, to no avail :/ I thought it was working OK since we received number of alerts when old was R13 and not stable. Jacques Le 20/04/2020 à 10:22, Christian Geisert a écrit : Uh, that's

Re: [VOTE] [RESULT] Apache OFBiz 17.12.02

2020-04-20 Thread Jacques Le Roux
+1 Thanks Deepak, crossed that yesterday evening too. It was just published then: https://plugins.gradle.org/plugin/at.bxm.svntools Jacques Le 20/04/2020 à 09:36, Deepak Dixit a écrit : +1 sounds good to me. Thanks & Regards -- Deepak Dixit ofbiz.apache.org On Mon, Apr 20, 2020 at 12:58

Increase the size of http.upload.max.sizethreshold to 1MB

2020-04-19 Thread Jacques Le Roux
Hi, With OFBIZ-11598 I have refactored to avoid to have the size hardcoded in several places. I see no reasons to use the default size (10KB) when we have now machines with GBs and need at least 1GB for OFBiz to run. If it's OK for everyone to increase the size to 1MB I'll do in a week.

Re: service with entity engine= auto for invoke = read

2020-04-17 Thread Jacques Le Roux
Hi Vinay, Your message has been moderated. Please subscribe to the user ML for such questions and then use your email client. See why here http://ofbiz.apache.org/mailing-lists.html. You will get a better support, people can answer you on the ML. The wider the audience the better the answers

Re: [GitHub] [ofbiz-tools] swapnilmmane merged pull request #3: Documented: Updated instance details in README file

2020-04-14 Thread Jacques Le Roux
Hi Swapnil, It seems Infra missed tools in INFRA-20007? Thanks Jacques Le 14/04/2020 à 14:21, GitBox a écrit : swapnilmmane merged pull request #3: Documented: Updated instance details in README file URL: https://github.com/apache/ofbiz-tools/pull/3

Re: [VOTE] [RELEASE] Apache OFBiz 17.12.02

2020-04-10 Thread Jacques Le Roux
+1, works for me verify-ofbiz-release.sh OK Both UIs (back and front ends) OK Integration tests OK. I have just the same 4 failures I got recently with R17: 3 productPrice-tests and category-tests.testGetProductCategoryAndLimitedMembers fails. That's is only Windows, works on Buildbot.

Re: Why README.md AND README.adoc in R17?

2020-04-07 Thread Jacques Le Roux
Le 01/04/2020 à 14:08, Jacques Le Roux a écrit : Le 01/04/2020 à 10:21, Jacopo Cappellato a écrit : @Jacopo: also the final READMEs in 17.12.01 is adapted to the gradlew download thing, should the R17 not be so? IMO we should update R17 as well as all the relevant branches (including trunk

Re: [TEST] Test "POC for CSRF Token"

2020-04-05 Thread Jacques Le Roux
hides it. So I'll create another Jira for that. And last but not least I have created: OFBIZ-11585 "Update security.adoc with few words about our CSRF defense strategy" Jacques Le 04/04/2020 à 21:02, Jacques Le Roux a écrit : Hi James, The backports in R18 and R17 went well but for

Re: [TEST] Test "POC for CSRF Token"

2020-04-04 Thread Jacques Le Roux
Hi James, The backports in R18 and R17 went well but for RequestHandler.java We will need to do the merge by hand. I'll begin and let you know Later... Jacques Le 04/04/2020 à 19:19, Jacques Le Roux a écrit : Hi James, All, Done, the CSRF defense is in trunk and I'll backport it ASAP

Re: [TEST] Test "POC for CSRF Token"

2020-04-04 Thread Jacques Le Roux
. Regards, James On 2020/04/04 13:10:18, Jacques Le Roux wrote: Hi James, 1. I like the idea. Maybe we could create the class but let the implementation (with explanations) for those who really need it? 2. I did not mean there was a correlation between csrf-token check and auth check. My

Re: [TEST] Test "POC for CSRF Token"

2020-04-04 Thread Jacques Le Roux
, we can implement another ICsrfDefenseStrategy class or modify the existing CsrfDefenseStrategy class. Regards, James On 2020/03/27 18:16:58, Jacques Le Roux wrote: Hi All, Before I create a PR as a last opportunity to allow reviews and tests, I'd like to ask 2 last questions: 1. should we not

All commits should be available on MLs [was - Re: Why README.md AND README.adoc in R17?]

2020-04-01 Thread Jacques Le Roux
lot of Forbidden You don't have permission to access this resource. in GitBox, once Daniel (Gruno) told me it was "normal". So we are dependent on GitHub if we don't have a local clone at hand :/ Regards, Michael Am 01.04.20 um 10:33 schrieb Jacques Le Roux: Hi Michael, Yes

Re: Why README.md AND README.adoc in R17?

2020-04-01 Thread Jacques Le Roux
Le 01/04/2020 à 10:21, Jacopo Cappellato a écrit : @Jacopo: also the final READMEs in 17.12.01 is adapted to the gradlew download thing, should the R17 not be so? IMO we should update R17 as well as all the relevant branches (including trunk) AND remove the wrapper binaries from all of them.

Re: Why README.md AND README.adoc in R17?

2020-04-01 Thread Jacques Le Roux
Jacques Le 01/04/2020 à 10:23, Michael Brohl a écrit : Just look at your backport commit fad06400e26c9b557b90c88dda5914b89794347b and answer yourself ;-) Michael Am 01.04.20 um 10:17 schrieb Jacques Le Roux: Hi All, Is there a reason why we have README.md AND README.adoc in R17? @Jacopo: also

Why README.md AND README.adoc in R17?

2020-04-01 Thread Jacques Le Roux
Hi All, Is there a reason why we have README.md AND README.adoc in R17? @Jacopo: also the final READMEs in 17.12.01 is adapted to the gradlew download thing, should the R17 not be so? Thanks Jacques

Re: OFBiz website / repository informations

2020-03-31 Thread Jacques Le Roux
https://issues.apache.org/jira/browse/OFBIZ-11269 HTH Jacques Le 31/03/2020 à 18:02, Pierre Smits a écrit : There is a ticket. Op di 31 mrt. 2020 17:50 schreef Michael Brohl : Hi everyone, is someone working on an update of the repository information at

Re: [TEST] Test "POC for CSRF Token"

2020-03-28 Thread Jacques Le Roux
haven't gone into too much detail, so my understanding on this is limited. However, from what I understood, same-site has the ability to become an all-in-one solution for CSRF attacks provided browsers honour it. Best, Girish On Sat, Mar 28, 2020 at 2:39 PM Jacques Le Roux < jacques.l

Re: [TEST] Test "POC for CSRF Token"

2020-03-28 Thread Jacques Le Roux
continue to work on the remaining 195 cases where auth="false"... HTH Jacques Le 27/03/2020 à 19:16, Jacques Le Roux a écrit : Hi All, Before I create a PR as a last opportunity to allow reviews and tests, I'd like to ask 2 last questions: 1. should we not use a JWT rather than a (pseudo)

Re: [TEST] Test "POC for CSRF Token"

2020-03-27 Thread Jacques Le Roux
Hi All, Before I create a PR as a last opportunity to allow reviews and tests, I'd like to ask 2 last questions: 1. should we not use a JWT rather than a (pseudo) random value for the CSRF token, this for timeout reason? Don't get me wrong I'm sure that the random values generated by

Re: [ofbiz-framework] branch trunk updated: Improved: no functional change

2020-03-25 Thread Jacques Le Roux
were added to refs/heads/trunk by this push:   new 11c0ce6  Improved: no functional change 11c0ce6 is described below commit 11c0ce6d55b9ffc0124354bae8f5d9746bf5681e Author: Jacques Le Roux AuthorDate: Tue Mar 24 18:31:54 2020 +0100 Improved: no functional change Adds /uploads/ i

Re: [TEST] Test "POC for CSRF Token"

2020-03-23 Thread Jacques Le Roux
Le 20/03/2020 à 08:44, Jacques Le Roux a écrit : If we do so, I have a question. With NoCsrfDefenseStrategy we have the possibility to bypass the CSRF defense. It's convenient for development, because else, in this mode, the CSRF defense is quite intrusive. * I propose to use it also in demo

Re: Demo instance for OFBiz 17.12 release and remove 13.07 demo

2020-03-23 Thread Jacques Le Roux
instance are mentioned in Jira comment at https://s.apache.org/o95vx Please have a look and let me know your kind feedback. Thank you so much Jacques Le Roux for your inputs and guidance in this. - Best regards, Swapnil M Mane, ofbiz.apache.org On Sun, Mar 15, 2020 at 9:29 PM Swapnil M Mane wrote

Re: [TEST] Test "POC for CSRF Token"

2020-03-20 Thread Jacques Le Roux
situation, a lot of people will have more urgent problems to solve at the moment. Thanks, Michael Am 20.03.20 um 08:44 schrieb Jacques Le Roux: Hi, I initially said I'd wait a month, it will be 24 days next Monday and I don't expect much more activity now. So, if nobody disagree, this weekend

Re: [TEST] Test "POC for CSRF Token"

2020-03-20 Thread Jacques Le Roux
not in development mode. Please verify it's OK with you before we apply the plan above. Here I want to thank James for his good work again Jacques Le 15/03/2020 à 19:35, Jacques Le Roux a écrit : Hi All, If you are interested to test, manually or with the tool of you choice, you can do so at https

Re: Weird error

2020-03-18 Thread Jacques Le Roux
Forget it, Was in the context of Qualys Le 18/03/2020 à 08:37, Jacques Le Roux a écrit : Hi, I got this weirs error somehow and I don't clearly remember when and where. So I don't want to create a Jira. Just asking if someone ever got the same or has an idea about it, else please neglect

Weird error

2020-03-18 Thread Jacques Le Roux
Hi, I got this weirs error somehow and I don't clearly remember when and where. So I don't want to create a Jira. Just asking if someone ever got the same or has an idea about it, else please neglect Note: maybe it was in the context of using a penetration tool. Like sending an abnormally

Re: [ofbiz-plugins] 01/02: Improved: "auth" should be true for all the request url used for Application components

2020-03-17 Thread Jacques Le Roux
ailto:jler...@apache.org>> wrote: This is an automated email from the ASF dual-hosted git repository. jleroux pushed a commit to branch trunk in repository https://gitbox.apache.org/repos/asf/ofbiz-plugins.git commit 9f87efe7ba035febcb5aa4f827a62de3316ecbab Author:

Re: Fwd: Re: [ofbiz-plugins] branch trunk updated: Improved: "auth" should be true for all the request url used for Application components

2020-03-16 Thread Jacques Le Roux
Oops, right indeed, I did not think about the anon checkout flow in ecommerce. I think I'll duplicate and make one only false in ecommerce Jacques Le 16/03/2020 à 09:21, Jacques Le Roux a écrit : Hi Deepak, Yes, I wondered about that too, but in which case/s do you think

Fwd: Re: [ofbiz-plugins] branch trunk updated: Improved: "auth" should be true for all the request url used for Application components

2020-03-16 Thread Jacques Le Roux
escribed below commit e72e1348c13f892cfbd3ffdb78f536c4e4aa6b68 Author: Jacques Le Roux mailto:jacques.le.r...@les7arts.com>> AuthorDate: Sat Mar 14 08:49:54 2020 +0100     Improved: "auth" should be true for all the request url used for Application     component

Re: [TEST] Test "POC for CSRF Token"

2020-03-15 Thread Jacques Le Roux
it :) Enjoy Jacques Le 09/03/2020 à 17:58, Jacques Le Roux a écrit : Hi Girish, I just had a look with Zap.  As a note: Zap reports missing CSRF tokens in forms when there are actually present in the URL. This is explained by the point 3 of OFBIZ-11306 description (Freemarker handling). Jacques

Re: Demo instance for OFBiz 17.12 release and remove 13.07 demo

2020-03-14 Thread Jacques Le Roux
Hi, Someone will handle it? Jacques Le 06/03/2020 à 10:34, Swapnil M Mane a écrit : Hello team, Current we have three demo instances [1] for OFBiz. -- Current Stable Release 16.11 - Demo https://demo-stable.ofbiz.apache.org/ordermgr/control/main -- Developer Trunk - Demo

Re: [ofbiz-plugins] branch trunk updated: Implemented: have a license

2020-03-14 Thread Jacques Le Roux
Le 14/03/2020 à 10:00, Jacopo Cappellato a écrit : Thank you Jacques, it looks good now apart from one detail; see inline: On Sat, Mar 14, 2020 at 8:29 AM wrote: [...] - Copyright [] [name of copyright owner] + Copyright 2001-2008 The Apache Software Foundation Since this section

Re: Adopting Github Workflow

2020-03-14 Thread Jacques Le Roux
lus+GIT+VS+JIRA+plus+GIT, read carefully, check, dicuss and ask questions to get to a good information base for an important decision to make. Thanks everyone, Michael Brohl ecomify GmbH - www.ecomify.de Am 12.03.20 um 17:28 schrieb Jacques Le Roux: You are all invited to review, discuss in

Re: Git history problem

2020-03-13 Thread Jacques Le Roux
o ask contributors to manually squash their commits before committing the lot again (always in a new PR?) and ask Infra to also remove this option. Opinions? Jacques Le 13/03/2020 à 14:48, Jacques Le Roux a écrit : Hi All, This is done, you may check with an open GH PR We will now ask Infra to ad

Re: Git history problem

2020-03-13 Thread Jacques Le Roux
Hi All, This is done, you may check with an open GH PR We will now ask Infra to add GH Issues[1]. It needs again a PMC agreement. [1] https://help.github.com/en/github/managing-your-work-on-github/creating-an-issue Jacques Le 10/03/2020 à 11:22, Jacques Le Roux a écrit : The infra team

Re: Adopting Github Workflow

2020-03-13 Thread Jacques Le Roux
Le 13/03/2020 à 11:40, Jacopo Cappellato a écrit : On Fri, Mar 13, 2020 at 11:33 AM Jacques Le Roux < jacques.le.r...@les7arts.com> wrote: [...] I have asked at https://issues.apache.org/jira/browse/INFRA-19950 if we could have GH issues. Yes, I saw your comment but I am wondering if t

Re: Adopting Github Workflow

2020-03-13 Thread Jacques Le Roux
Le 13/03/2020 à 11:29, Jacopo Cappellato a écrit : On Wed, Mar 11, 2020 at 10:20 PM Pierre Smits wrote: [...] As for PMC Members claiming that the Github services (repositories etc.) are not *official* ASF tools, I suggest these persons stop this kind of FUD (and maybe check back with the

Re: Adopting Github Workflow

2020-03-12 Thread Jacques Le Roux
, Jacques Le Roux a écrit : Le 12/03/2020 à 13:32, Jacques Le Roux a écrit : Le 12/03/2020 à 12:17, Jacopo Cappellato a écrit : On Thu, Mar 12, 2020 at 11:47 AM Jacques Le Roux < jacques.le.r...@les7arts.com> wrote: As I see no Jira references in "Release Distribution Policy&qu

Re: Adopting Github Workflow

2020-03-12 Thread Jacques Le Roux
Le 12/03/2020 à 13:32, Jacques Le Roux a écrit : Le 12/03/2020 à 12:17, Jacopo Cappellato a écrit : On Thu, Mar 12, 2020 at 11:47 AM Jacques Le Roux < jacques.le.r...@les7arts.com> wrote: As I see no Jira references in "Release Distribution Policy" I guess it's not an issue

Re: Adopting Github Workflow

2020-03-12 Thread Jacques Le Roux
Le 12/03/2020 à 12:17, Jacopo Cappellato a écrit : On Thu, Mar 12, 2020 at 11:47 AM Jacques Le Roux < jacques.le.r...@les7arts.com> wrote: As I see no Jira references in "Release Distribution Policy" I guess it's not an issue to no longer use Jira to manage versions and rele

Re: Adopting Github Workflow

2020-03-12 Thread Jacques Le Roux
Le 12/03/2020 à 11:46, Jacques Le Roux a écrit : Le 12/03/2020 à 10:30, Jacques Le Roux a écrit : Pro:  1. More devs know GH than Jira and it has been created for them (when using Git). They like it, we need them.  2. Simple things are easy to directly push with the PR commit button (w

Re: Adopting Github Workflow

2020-03-12 Thread Jacques Le Roux
Le 12/03/2020 à 10:30, Jacques Le Roux a écrit : Pro: 1. More devs know GH than Jira and it has been created for them (when using Git). They like it, we need them. 2. Simple things are easy to directly push with the PR commit button (w/ forced rebase and merge). For large or complicate

Re: Adopting Github Workflow

2020-03-12 Thread Jacques Le Roux
Le 12/03/2020 à 11:40, Jacopo Cappellato a écrit : On Thu, Mar 12, 2020 at 10:32 AM Jacques Le Roux < jacques.le.r...@les7arts.com> wrote: [...] 6. GH has intrinsically tools to version and release (it's a dev tool not a reporting tool). Please Jacopo confirm since you are the r

Re: Adopting Github Workflow

2020-03-12 Thread Jacques Le Roux
Le 12/03/2020 à 10:30, Jacques Le Roux a écrit : It then offers the same possibilities than Jira (which adapted) It then offers the same possibilities than Jira (which adapted during its evolution) Jacques

Re: Adopting Github Workflow

2020-03-12 Thread Jacques Le Roux
Le 12/03/2020 à 09:53, Samuel Trégouët a écrit : Hi Michael, To justify the need of making a change, to me the question is quite the opposite: what does GitHub offer which Jira does not in the domain of contributing/ project management/ issue tracking? Jira review process is awfull! I tried

Re: Adopting Github Workflow

2020-03-12 Thread Jacques Le Roux
Le 12/03/2020 à 09:12, Michael Brohl a écrit : Hi Jacques, I will just pick out one topic here, see inline: Am 12.03.20 um 08:32 schrieb Jacques Le Roux: The most important question to answer is: what does Jira offers that GH does not? To justify the need of making a change, to me

Re: Adopting Github Workflow

2020-03-12 Thread Jacques Le Roux
Le 11/03/2020 à 16:29, Mathieu Lirzin a écrit : Jacques Le Roux writes: Le 11/03/2020 à 12:33, Mathieu Lirzin a écrit : This said you certainly saw this thread started by Pierre Smits: https://markmail.org/message/so7ljoqxzuq7jplz and the related wiki document https://cwiki.apache.org

Re: Adopting Github Workflow

2020-03-11 Thread Jacques Le Roux
another story :). Le 11/03/2020 à 17:28, Jacques Le Roux a écrit : Le 11/03/2020 à 17:08, Michael Brohl a écrit : Hi Mathieu, inline... Inline too... Am 11.03.20 um 16:29 schrieb Mathieu Lirzin: - Adopt Github Pull Request (PR) as the unique channel for code contribution -1 I don't see

Re: Adopting Github Workflow

2020-03-11 Thread Jacques Le Roux
Le 11/03/2020 à 17:08, Michael Brohl a écrit : Hi Mathieu, inline... Inline too... Am 11.03.20 um 16:29 schrieb Mathieu Lirzin: - Adopt Github Pull Request (PR) as the unique channel for code contribution -1 I don't see a reason why we should not allow patches also. It will make it

Re: Git history problem

2020-03-11 Thread Jacques Le Roux
into the habit of linearizing history, meaning always rebasing and clean history before merging into trunk. I guess the GH merge button option "Rebase and merge" is what we are looking to enforce with the request to Infra, right? -- Jacques Le Roux 400E Chemin de la Mouline 34560 Poussan 04 67 5

Re: Git history problem

2020-03-11 Thread Jacques Le Roux
Le 11/03/2020 à 12:33, Mathieu Lirzin a écrit : This said you certainly saw this thread started by Pierre Smits: https://markmail.org/message/so7ljoqxzuq7jplz and the related wiki document https://cwiki.apache.org/confluence/display/OFBIZ/Contributing+via+Git+and+Github AIUI this page is

Re: Git commits email notification problem

2020-03-11 Thread Jacques Le Roux
Le 11/03/2020 à 11:46, Mathieu Lirzin a écrit : Hello Jacques, Here is a first answer on the specific point of the commit notification issue. Jacques Le Roux writes: I noticed that sometimes strange things happen when you use a PR. Consider this recent email for instance: https

Re: buildbot exception in on ofbizBranch17FrameworkPlugins

2020-03-11 Thread Jacques Le Roux
Hi Michael, To be totally honest, this time it's not an intrinsic Buidbot issue, it just could not grab a resource ;) This does not excuse the cases where it fails on integration tests when they pass locally. With machines working almost 100% all time it's not a surprise though. Jacques Le

Re: Git history problem

2020-03-10 Thread Jacques Le Roux
The infra team requires a PMC decision for this change, see https://issues.apache.org/jira/browse/INFRA-19950 Jacques Le 10/03/2020 à 10:57, Jacques Le Roux a écrit : Le 09/03/2020 à 17:58, Mathieu Lirzin a écrit : Hello, The history of OFBiz trunk with the adoption of the Pull Request

Re: Git history problem

2020-03-10 Thread Jacques Le Roux
Le 09/03/2020 à 17:58, Mathieu Lirzin a écrit : Hello, The history of OFBiz trunk with the adoption of the Pull Request based contribution process is getting less and less readable. Here is a snippet of `git log --oneline --graph` demonstrating that: --8<---cut

Re: [TEST] Test "POC for CSRF Token"

2020-03-09 Thread Jacques Le Roux
know how it goes with ZAP. Best, Girish On Sat, Mar 7, 2020 at 3:30 PM Jacques Le Roux wrote: Hi All, This is my 1st weekly reminder :) As you may know CSRF attacks are very bad. TL;DR: They are hard to provoke but once you are able to create one, mostly using social engineering

Re: OFBIZ-11415: Backport request - Using FlexibleStringExpander in form widget field's parameter names

2020-03-09 Thread Jacques Le Roux
uld explain why all the commits from PR31 were merged as well. Thanks, Dan. On Mon, 9 Mar 2020 at 13:32, Jacques Le Roux wrote: Hi Daniel, Done, please check I did not miss anything. I was a bit confused because when I merged PR31 it seem PR37 was automatically merged too. If all is OK I'll conti

Re: OFBIZ-11415: Backport request - Using FlexibleStringExpander in form widget field's parameter names

2020-03-09 Thread Jacques Le Roux
Hi Daniel, Done, please check I did not miss anything. I was a bit confused because when I merged PR31 it seem PR37 was automatically merged too. If all is OK I'll continue on OFBIZ-4035 Thanks Jacques Le 06/03/2020 à 18:03, Jacques Le Roux a écrit : Hi Daniel, All, At https

Re: Demo instance for OFBiz 17.12 release and remove 13.07 demo

2020-03-08 Thread Jacques Le Roux
Hi Swapnil, Exactly my thoughts, +1 Jacques Le 06/03/2020 à 10:34, Swapnil M Mane a écrit : Hello team, Current we have three demo instances [1] for OFBiz. -- Current Stable Release 16.11 - Demo https://demo-stable.ofbiz.apache.org/ordermgr/control/main -- Developer Trunk - Demo

Re: Solr Index Build Error on Demo Instance

2020-03-07 Thread Jacques Le Roux
Thanks Ravi, This is a demo configuration problem (not an issue locally). Please create a Jira for that, here is the related log on trunk demo: 2020-03-07 10:43:01,506 |27.0.0.1-8009-exec-1 |SolrProductSearch |E| Connect to localhost:8443 [localhost/127.0.0.1] failed: Connection

Re: Groovy Migration : createRequirementFromItemATP

2020-03-07 Thread Jacques Le Roux
Le 07/03/2020 à 10:42, Jacopo Cappellato a écrit : On Fri, Mar 6, 2020 at 7:31 PM Pierre Smits wrote: Hi Gil, If that other function ( createATPRequirementsForOrder service) has been in play since 2007, we can, i would say safely, assume that the createRequirementFromItemATP function/service

Re: [TEST] Test "POC for CSRF Token"

2020-03-07 Thread Jacques Le Roux
mber* Apache Incubator<https://incubator.apache.org>, committer Apache Steve<https://steve.apache.org>, committer On Sat, Feb 29, 2020 at 10:28 AM Jacques Le Roux < jacques.le.r...@les7arts.com> wrote: For those interested, it's maybe easier to test to simply apply the last patches (fram

Re: OFBIZ-11415: Backport request - Using FlexibleStringExpander in form widget field's parameter names

2020-03-06 Thread Jacques Le Roux
Hi Daniel, All, At https://markmail.org/message/ahu6kz7dihcyp45z you asked "How do committers decide which features to backport to 18.12?" I (roughly) answered     "The rule is normally we only backport bug fixes, obviously to avoid regression.  But if nobody disagree for simple new

Re: [jira] [Commented] (OFBIZ-10231) Convert ProductServices.xml mini lang to groovy

2020-03-05 Thread Jacques Le Roux
Le 05/03/2020 à 14:26, Nicolas Malin a écrit : Kelvin it's the nickname for Elvis ? Ah(?), OK Jacques

<    6   7   8   9   10   11   12   13   14   15   >