Re: [Framework-Team] HTTP parameter polution

2009-05-20 Thread Ricardo Newbery
On May 19, 2009, at 9:23 PM, Steve McMahon wrote: The paper mentions Plone, but all they found is that Plone rejects the bad input but Since this error generates ~100 lines in the log file, it may be used to obfuscate other attacks. I found no serious vulnerability claim. How odd. Just did

Re: [Framework-Team] Re: Plone 2009: Going from here

2009-05-12 Thread Ricardo Newbery
On May 12, 2009, at 4:23 PM, Steve McMahon wrote: Ideally, a framework team should have an odd number of members in order to avoid tie votes. However, in watching the last couple of voting sessions for Plone 3, I noticed that there were not that many PLIPS on which every person voted. So, I

Re: [Framework-Team] PLIP #187: Working out-of-the-box WebDAV

2008-10-28 Thread Ricardo Newbery
On Oct 28, 2008, at 5:20 AM, Alan Runyan wrote: Andreas, Please confirm, the outstanding questions are: - Wichert asking, How are the marshallers configured via GenericSetup This is a great question. - Ricardo asking, how the OS X resource fork issue was resolved. We should not

Re: [Framework-Team] PLIP #187: Working out-of-the-box WebDAV

2008-10-28 Thread Ricardo Newbery
On Oct 28, 2008, at 2:21 PM, Alan Runyan wrote: If the OSX webdav support was dropped from this PLIP, then perhaps the PLIP should be updated to make that clear. At the moment, it clearly suggests that the OSX behavior was specifically targeted. I will leave that up to Sidnei. Having a

Re: [Framework-Team] Re: preliminary results for PLIP selection call for votes!

2007-12-24 Thread Ricardo Newbery
On Dec 23, 2007, at 3:14 PM, Sidnei da Silva wrote: To be clear, I believe the only -1 vote on #187 was primarily due to some concerns about the shortage of detail in the PLIP text. A concern I share. I'm hoping Sidnei fleshes out the details soon. :-) I would gladly answer any

Re: [Framework-Team] Re: preliminary results for PLIP selection call for votes!

2007-12-24 Thread Ricardo Newbery
Thanks again Sidnei, [note to framework list: let me know if I should take this discussion off list] Maybe I'm missing something but there doesn't seem to be any reason to return a 404 (Not Found) or 403 (Forbidding) response. Why not just silently discard the offending files, along

Re: [Framework-Team] Re: preliminary results for PLIP selection call for votes!

2007-12-23 Thread Ricardo Newbery
On Dec 23, 2007, at 12:47 PM, Raphael Ritz wrote: Andreas Zeidler wrote: [..] * Rapahel on #187 please also try to cast those asap. that said, how long do we want to wait for those missing votes and do we have a plan on how to proceed if they don't arrive? i'd suggest waiting