Re: Groovy Migration : createRequirementFromItemATP

2020-03-06 Thread Pierre Smits
Hi Gil, If that other function ( createATPRequirementsForOrder service) has been in play since 2007, we can, i would say safely, assume that the createRequirementFromItemATP function/service can be removed from the codebase immediately and port its removal to the 18.11 branch. No need to slate it

Re: OFBIZ-11415: Backport request - Using FlexibleStringExpander in form widget field's parameter names

2020-03-06 Thread Jacques Le Roux
Hi Daniel, All, At https://markmail.org/message/ahu6kz7dihcyp45z you asked "How do committers decide which features to backport to 18.12?" I (roughly) answered     "The rule is normally we only backport bug fixes, obviously to avoid regression.  But if nobody disagree for simple new

Groovy Migration : createRequirementFromItemATP

2020-03-06 Thread Gil Portenseigne
Hello ! While migrating createRequirementFromItemATP, i stumbled upon a comment from David Jones : > NOTE DEJ20090902: this service is not called > anywhere, instead the createATPRequirementsForOrder service (written in > Java) is called; why this is the case I don't know... --> I investigate a

Re: buildbot failure in on ofbizTrunkFramework

2020-03-06 Thread Gil Portenseigne
I introduced a test error with my new test, i'll look into it. Gil On Fri, Mar 06, 2020 at 03:48:10PM +, build...@apache.org wrote: > The Buildbot has detected a new failure on builder ofbizTrunkFramework while > building ofbiz-framework. Full details are available at: >

Re: Demo instance for OFBiz 17.12 release and remove 13.07 demo

2020-03-06 Thread Pierre Smits
We could also decide to reduce the burden (on INRA - cost wise, and on contributors - maintenance wise ) to only have 1 demo implementation. That against latest release. With current enhancement under https://github.com/apache/ofbiz-framework/pull/43 (potential) adopters can evaluate and/or test

Demo instance for OFBiz 17.12 release and remove 13.07 demo

2020-03-06 Thread Swapnil M Mane
Hello team, Current we have three demo instances [1] for OFBiz. -- Current Stable Release 16.11 - Demo https://demo-stable.ofbiz.apache.org/ordermgr/control/main -- Developer Trunk - Demo https://demo-trunk.ofbiz.apache.org/ordermgr/control/main -- Previous Stable Release 13.07 - Demo

Re: OFBiz releases are failing verification checks

2020-03-06 Thread Pierre Smits
Furthermore, With recent https://github.com/apache/ofbiz-framework/pull/43 we don't need to deliver a convenience package containing both the base and the extensions anymore. This will enable (potential) adopters to evaluate/testdrive a fully operational OFBiz implementation in a contained

[CVE-2020-1943] Apache OFBiz XSS Vulnerability

2020-03-06 Thread Jacopo Cappellato
Severity: Important Vendor: The Apache Software Foundation Versions Affected: OFBiz 16.11.01 to 16.11.07 Description: Data sent with "contentId" to "/control/stream" is not sanitized, allowing XSS attacks. Mitigation: Upgrade to 17.12.01 or manually apply the commits at OFBIZ-10753

[ANNOUNCE] Apache OFBiz 17.12.01 release

2020-03-06 Thread Jacopo Cappellato
The Apache OFBiz community is pleased to announce the new release "Apache OFBiz 17.12.01". Apache OFBiz® is an open source product for the automation of enterprise processes that includes framework components and business applications. http://ofbiz.apache.org/ "Apache OFBiz 17.12.01" is the

Re: OFBiz releases are failing verification checks

2020-03-06 Thread Pierre Smits
IMO, despite all the encouragements by the ASF and the project, people do what they like. And some even may not want to have all plugins included. Given that the project already voted favourably on the first convenience package of the 17.12 branch (which incorporates, and is based on, the