[Koha-devel] Next 16.11.x release scheduled for March 27

2017-03-20 Thread Katrin
Hi all, as we just had the security release on last Friday, I will do the next 16.11.x release which will be 16.11.x on Monday March 27 next week. This will give translators and the hackfesters in Marseille more time to work on translations and bug fixes to include. Katrin

[Koha-devel] Upgrading from koha 16.05 to 16.11

2017-03-20 Thread Rodrigo Santellan
Hi, I'm upgrading from koha 16.05 to 16.11 (I'm trying to keep up to date) and I see on the updatedatabase.pl this: *DBD::mysql::db do failed: Can't DROP 'isbn'; check that column/key exists [for Statement "ALTER TABLE biblioitems DROP INDEX isbn"] at

Re: [Koha-devel] CSRF token problem ?

2017-03-20 Thread Christopher Nighswonger
On Mar 20, 2017 7:54 AM, "Katrin Fischer" wrote: Hi all, please remember to file security bugs in the non-public area of bugzilla and also be careful with the discussion here: https://koha-community.org/security/ (we should probably update the list of names) The

Re: [Koha-devel] CSRF token problem ?

2017-03-20 Thread Katrin Fischer
Hi all,   please remember to file security bugs in the non-public area of bugzilla and also be careful with the discussion here: https://koha-community.org/security/ (we should probably update the list of names)   Katrin   Gesendet: Montag, 20. März 2017 um 12:27 Uhr Von: "Julian Maurice"

[Koha-devel] CSRF token problem ?

2017-03-20 Thread Julian Maurice
Hi, I think I found a problem with how we use CSRF tokens. If a token is discovered by an attacker, and if the user leaves their session open, the attacker can use the token to impersonate the user on every CSRF-protected form during 8 hours (Koha::Token::CSRF_EXPIRY_HOURS). Is this a known

[Koha-devel] Hackfest 2017, photos

2017-03-20 Thread Paul Poulain
Hello all, If you want to see pictures of the hackfest, or add some, it's here : https://photos.google.com/share/AF1QipPejV4Ai8Zw_wkFPsl4SDyy4zVIxuD6L6SMvwjYkvo5E2PTq8yVC_5UkEUPykbDCg?key=M0o1bFJ2eXdKUm9XcjBlNnFlRTlPWXg2R2k1Ul9R -- Paul Poulain, Associé-gérant / co-owner BibLibre, Services