Re: Time to cut 2.1.6 / 2.0.15?

2020-04-23 Thread Francesco Chicchiriccò
On 23/04/20 11:41, Francesco Chicchiriccò wrote: > On 23/04/20 11:27, Colm O hEigeartaigh wrote: >> Hi Francesco, >> >> +1, but could we look at updating a few more security vulnerabilities? >> >> - CVE-2018-8036 could be fixed by updating XML Graphics 2.3 -> 2.4 > This can be done both for 2_0_X

Errored: apache/syncope#6376 (2_0_X - 2f4b898)

2020-04-23 Thread Travis CI
Build Update for apache/syncope - Build: #6376 Status: Errored Duration: 18 mins and 40 secs Commit: 2f4b898 (2_0_X) Author: Francesco Chicchiriccò Message: Upgrading Guava and FOP View the changeset:

Broken: apache/syncope#6375 (2_1_X - d2f742d)

2020-04-23 Thread Travis CI
Build Update for apache/syncope - Build: #6375 Status: Broken Duration: 34 mins and 20 secs Commit: d2f742d (2_1_X) Author: Francesco Chicchiriccò Message: Upgrading Guava and FOP View the changeset:

Errored: apache/syncope#6376 (2_0_X - 2f4b898)

2020-04-23 Thread Travis CI
Build Update for apache/syncope - Build: #6376 Status: Errored Duration: 18 mins and 48 secs Commit: 2f4b898 (2_0_X) Author: Francesco Chicchiriccò Message: Upgrading Guava and FOP View the changeset:

Errored: apache/syncope#6373 (master - 8ca124a)

2020-04-23 Thread Travis CI
Build Update for apache/syncope - Build: #6373 Status: Errored Duration: 1 hr, 4 mins, and 22 secs Commit: 8ca124a (master) Author: Francesco Chicchiriccò Message: [SYNCOPE-1554] Adding missing @JsonAnySetter View the changeset:

Passed: apache/syncope#6377 (2_0_X - f5b54b7)

2020-04-23 Thread Travis CI
Build Update for apache/syncope - Build: #6377 Status: Passed Duration: 18 mins and 44 secs Commit: f5b54b7 (2_0_X) Author: Francesco Chicchiriccò Message: Fixing after FOP upgrade View the changeset:

Fixed: apache/syncope#6378 (2_1_X - 9b4fb76)

2020-04-23 Thread Travis CI
Build Update for apache/syncope - Build: #6378 Status: Fixed Duration: 34 mins and 49 secs Commit: 9b4fb76 (2_1_X) Author: Francesco Chicchiriccò Message: Fixing after FOP upgrade View the changeset:

Re: Time to cut 2.1.6 / 2.0.15?

2020-04-23 Thread Colm O hEigeartaigh
Awesome, thanks :-) Colm. On Thu, Apr 23, 2020 at 11:00 AM Francesco Chicchiriccò wrote: > On 23/04/20 11:41, Francesco Chicchiriccò wrote: > > On 23/04/20 11:27, Colm O hEigeartaigh wrote: > >> Hi Francesco, > >> > >> +1, but could we look at updating a few more security vulnerabilities? > >>

[jira] [Resolved] (SYNCOPE-1554) Generated default admin role layout doesn't work

2020-04-23 Thread Jira
[ https://issues.apache.org/jira/browse/SYNCOPE-1554?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Francesco Chicchiriccò resolved SYNCOPE-1554. - Resolution: Fixed > Generated default admin role layout doesn't work >

Re: Time to cut 2.1.6 / 2.0.15?

2020-04-23 Thread Francesco Chicchiriccò
FYI I had to push an additional commit both on 2_0_X and 2_1_X to complete FOP upgrade, but now tests seem to be fine again. Regards. On 23/04/20 12:40, Colm O hEigeartaigh wrote: > Awesome, thanks :-) > > Colm. > > On Thu, Apr 23, 2020 at 11:00 AM Francesco Chicchiriccò > wrote: > >> On

Re: Jquery version on 2.1.x/2.0.x

2020-04-23 Thread Francesco Chicchiriccò
On 23/04/20 08:58, Francesco Chicchiriccò wrote: > On 23/04/20 08:51, Colm O hEigeartaigh wrote: >> Is it possible to update the JQuery version on 2.1.x/2.0.x to the same >> version as on master? (3.4.1). It seems the existing version is vulnerable >> to

Re: Jquery version on 2.1.x/2.0.x

2020-04-23 Thread Colm O hEigeartaigh
That's great, thanks! Colm. On Thu, Apr 23, 2020 at 8:35 AM Francesco Chicchiriccò wrote: > On 23/04/20 08:58, Francesco Chicchiriccò wrote: > > On 23/04/20 08:51, Colm O hEigeartaigh wrote: > >> Is it possible to update the JQuery version on 2.1.x/2.0.x to the same > >> version as on master?

[jira] [Created] (SYNCOPE-1558) Configure WA delegated authn module to SAML IdPs via REST

2020-04-23 Thread Misagh Moayyed (Jira)
Misagh Moayyed created SYNCOPE-1558: --- Summary: Configure WA delegated authn module to SAML IdPs via REST Key: SYNCOPE-1558 URL: https://issues.apache.org/jira/browse/SYNCOPE-1558 Project: Syncope

Broken: apache/syncope#6369 (master - 2186050)

2020-04-23 Thread Travis CI
Build Update for apache/syncope - Build: #6369 Status: Broken Duration: 21 mins and 43 secs Commit: 2186050 (master) Author: Francesco Chicchiriccò Message: No need to check admin rights on Resource when only listing connector objects View the changeset:

Re: Jquery version on 2.1.x/2.0.x

2020-04-23 Thread Francesco Chicchiriccò
On 23/04/20 08:51, Colm O hEigeartaigh wrote: > Is it possible to update the JQuery version on 2.1.x/2.0.x to the same > version as on master? (3.4.1). It seems the existing version is vulnerable > to https://nvd.nist.gov/vuln/detail/CVE-2019-11358 Hi Colm, I don't see issue. Let me do some local

Re: Time to cut 2.1.6 / 2.0.15?

2020-04-23 Thread Francesco Chicchiriccò
Hi all, resuming this thread after one week: shall we proceed with releases? Regards. On 16/04/20 14:17, Andrea Patricelli wrote: > Hi all, > > we are going to develop last improvement that consists in a custom layout for > linked account wizard. Thus we would like to wait for this last

[jira] [Assigned] (SYNCOPE-1554) Generated default admin role layout doesn't work

2020-04-23 Thread Jira
[ https://issues.apache.org/jira/browse/SYNCOPE-1554?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Francesco Chicchiriccò reassigned SYNCOPE-1554: --- Assignee: Francesco Chicchiriccò > Generated default admin role

Re: Time to cut 2.1.6 / 2.0.15?

2020-04-23 Thread Francesco Chicchiriccò
On 23/04/20 11:27, Colm O hEigeartaigh wrote: > Hi Francesco, > > +1, but could we look at updating a few more security vulnerabilities? > > - CVE-2018-8036 could be fixed by updating XML Graphics 2.3 -> 2.4 This can be done both for 2_0_X and 2_1_X as FOP 2.4 retains Java 7 compatibility, as

Jquery version on 2.1.x/2.0.x

2020-04-23 Thread Colm O hEigeartaigh
Is it possible to update the JQuery version on 2.1.x/2.0.x to the same version as on master? (3.4.1). It seems the existing version is vulnerable to https://nvd.nist.gov/vuln/detail/CVE-2019-11358 Colm.

[jira] [Resolved] (SYNCOPE-1553) Fetch WA auth modules & map to properties during bootstrap

2020-04-23 Thread Misagh Moayyed (Jira)
[ https://issues.apache.org/jira/browse/SYNCOPE-1553?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Misagh Moayyed resolved SYNCOPE-1553. - Resolution: Fixed > Fetch WA auth modules & map to properties during bootstrap >

[jira] [Commented] (SYNCOPE-1554) Generated default admin role layout doesn't work

2020-04-23 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/SYNCOPE-1554?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17090426#comment-17090426 ] ASF subversion and git services commented on SYNCOPE-1554: -- Commit

[jira] [Commented] (SYNCOPE-1554) Generated default admin role layout doesn't work

2020-04-23 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/SYNCOPE-1554?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17090427#comment-17090427 ] ASF subversion and git services commented on SYNCOPE-1554: -- Commit

[jira] [Commented] (SYNCOPE-1553) Fetch WA auth modules & map to properties during bootstrap

2020-04-23 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/SYNCOPE-1553?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17090368#comment-17090368 ] ASF subversion and git services commented on SYNCOPE-1553: -- Commit

[jira] [Commented] (SYNCOPE-1553) Fetch WA auth modules & map to properties during bootstrap

2020-04-23 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/SYNCOPE-1553?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17090369#comment-17090369 ] ASF subversion and git services commented on SYNCOPE-1553: -- Commit

[jira] [Commented] (SYNCOPE-1553) Fetch WA auth modules & map to properties during bootstrap

2020-04-23 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/SYNCOPE-1553?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17090367#comment-17090367 ] ASF subversion and git services commented on SYNCOPE-1553: -- Commit

[jira] [Commented] (SYNCOPE-1553) Fetch WA auth modules & map to properties during bootstrap

2020-04-23 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/SYNCOPE-1553?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17090366#comment-17090366 ] ASF subversion and git services commented on SYNCOPE-1553: -- Commit

Re: Time to cut 2.1.6 / 2.0.15?

2020-04-23 Thread Colm O hEigeartaigh
Hi Francesco, +1, but could we look at updating a few more security vulnerabilities? - CVE-2018-8036 could be fixed by updating XML Graphics 2.3 -> 2.4 - CVE-2018-10237 could be fixed by updating Guava >= 2.24.x Colm. On Thu, Apr 23, 2020 at 8:47 AM Francesco Chicchiriccò wrote: > Hi all,

Re: Jquery version on 2.1.x/2.0.x

2020-04-23 Thread Francesco Chicchiriccò
On 23/04/20 15:31, Misagh Moayyed wrote: > In the same vein, I'd like to update the master branch to use jQuery 3.5.0. > While optional for now, this will soon (1-2 days) become a requirement for > the WA module to function correctly. Local testing shows that the upgrade is > innocuous. If

Re: Jquery version on 2.1.x/2.0.x

2020-04-23 Thread Misagh Moayyed
In the same vein, I'd like to update the master branch to use jQuery 3.5.0. While optional for now, this will soon (1-2 days) become a requirement for the WA module to function correctly. Local testing shows that the upgrade is innocuous. --Misagh - Original Message - > From: "Colm O