[jira] [Commented] (OFBIZ-11306) POC for CSRF Token (CVE-2019-0235)

2020-07-08 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17153476#comment-17153476 ] James Yong commented on OFBIZ-11306: Thanks Jacques for making the documentation clear. > POC for

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token (CVE-2019-0235)

2020-07-08 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17153349#comment-17153349 ] ASF subversion and git services commented on OFBIZ-11306: - Commit

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token (CVE-2019-0235)

2020-07-08 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17153346#comment-17153346 ] Jacques Le Roux commented on OFBIZ-11306: - Forgot to push, doing so... > POC for CSRF Token

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token (CVE-2019-0235)

2020-07-07 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17152900#comment-17152900 ] Jacques Le Roux commented on OFBIZ-11306: - Done (only in XSD was needed) > POC for CSRF Token

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token (CVE-2019-0235)

2020-07-07 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17152559#comment-17152559 ] Jacques Le Roux commented on OFBIZ-11306: - Thanks James, I'll document that in

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token (CVE-2019-0235)

2020-07-06 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17152130#comment-17152130 ] James Yong commented on OFBIZ-11306: Hi Jacques, When csrf-token is empty or not set, the behaviour

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token (CVE-2019-0235)

2020-07-05 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17151517#comment-17151517 ] Jacques Le Roux commented on OFBIZ-11306: - Hi James, I want to clarify the documentation for

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token (CVE-2019-0235)

2020-04-27 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17093709#comment-17093709 ] ASF subversion and git services commented on OFBIZ-11306: - Commit

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token (CVE-2019-0235)

2020-04-12 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17081753#comment-17081753 ] ASF subversion and git services commented on OFBIZ-11306: - Commit

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token (CVE-2019-12425)

2020-04-06 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17076205#comment-17076205 ] ASF subversion and git services commented on OFBIZ-11306: - Commit

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token (CVE-2019-12425)

2020-04-05 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17075768#comment-17075768 ] ASF subversion and git services commented on OFBIZ-11306: - Commit

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token (CVE-2019-12425)

2020-04-05 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17075765#comment-17075765 ] ASF subversion and git services commented on OFBIZ-11306: - Commit

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token (CVE-2019-12425)

2020-04-05 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17075769#comment-17075769 ] ASF subversion and git services commented on OFBIZ-11306: - Commit

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token (CVE-2019-12425)

2020-04-05 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17075766#comment-17075766 ] ASF subversion and git services commented on OFBIZ-11306: - Commit

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token (CVE-2019-12425)

2020-04-05 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17075763#comment-17075763 ] ASF subversion and git services commented on OFBIZ-11306: - Commit

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-04-04 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17075198#comment-17075198 ] ASF subversion and git services commented on OFBIZ-11306: - Commit

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-04-04 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17075193#comment-17075193 ] ASF subversion and git services commented on OFBIZ-11306: - Commit

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-04-04 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17075194#comment-17075194 ] ASF subversion and git services commented on OFBIZ-11306: - Commit

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-03-28 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17069418#comment-17069418 ] Jacques Le Roux commented on OFBIZ-11306: - Hi James, I have posted my answers to the 2

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-03-27 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17068956#comment-17068956 ] Jacques Le Roux commented on OFBIZ-11306: - For those tempted to use the last patches. Those are

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-03-27 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17068951#comment-17068951 ] Jacques Le Roux commented on OFBIZ-11306: - Hi James, All, I have updated my branch

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-03-23 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17064870#comment-17064870 ] Jacques Le Roux commented on OFBIZ-11306: - James, bq. eCommence is using

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-03-23 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17064837#comment-17064837 ] James Yong commented on OFBIZ-11306: eCommence is using /getAssociatedStateList from both ecommerce

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-03-23 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17064786#comment-17064786 ] Jacques Le Roux commented on OFBIZ-11306: - Hi James, I had still some notes not verified or

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-27 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17046645#comment-17046645 ] Jacques Le Roux commented on OFBIZ-11306: - The test issue is OFBIZ-11425, let's go! > POC for

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-27 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17046632#comment-17046632 ] Jacques Le Roux commented on OFBIZ-11306: - Actually to not scramble minds of others, I'll create

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-27 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17046630#comment-17046630 ] Jacques Le Roux commented on OFBIZ-11306: - Hi James I have deleted the remote branches in

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-26 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17045635#comment-17045635 ] Jacques Le Roux commented on OFBIZ-11306: - I removed the [remote "origin"] block from my local

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-26 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17045625#comment-17045625 ] Jacques Le Roux commented on OFBIZ-11306: - Hi James, Despite having this local Git config:

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-26 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17045609#comment-17045609 ] ASF subversion and git services commented on OFBIZ-11306: - Commit

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-26 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17045319#comment-17045319 ] Jacques Le Roux commented on OFBIZ-11306: - Here is the last patch before forking:

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-26 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17045251#comment-17045251 ] Jacques Le Roux commented on OFBIZ-11306: - I'll not for the plugins repo because the change is

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-25 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17045150#comment-17045150 ] Jacques Le Roux commented on OFBIZ-11306: - Hi James, Easy stuff, it was just a matter of

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-25 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17044776#comment-17044776 ] Jacques Le Roux commented on OFBIZ-11306: - I just tested

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-25 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17044505#comment-17044505 ] Jacques Le Roux commented on OFBIZ-11306: - OK, it's not an issue related to this efffort. There

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-25 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17044354#comment-17044354 ] Jacques Le Roux commented on OFBIZ-11306: - Actually the same issue happens w/your last patch.

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-25 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17044346#comment-17044346 ] James Yong commented on OFBIZ-11306: HI Jacques, {quote}I have merged your changes and my pending

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-25 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17044338#comment-17044338 ] Jacques Le Roux commented on OFBIZ-11306: - Mmm no, after a "gradlew clean" your patch test and

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-25 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17044307#comment-17044307 ] Jacques Le Roux commented on OFBIZ-11306: - Actually when I apply your last patch

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-25 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17044295#comment-17044295 ] Jacques Le Roux commented on OFBIZ-11306: - James, I missed to check again Check/Update Database

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-25 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17044218#comment-17044218 ] Jacques Le Roux commented on OFBIZ-11306: - Hi James, I have merged your changes and my pending

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-24 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17043372#comment-17043372 ] Jacques Le Roux commented on OFBIZ-11306: - bq. Why not using your own repo on GitHub and share

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-24 Thread Michael Brohl (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17043347#comment-17043347 ] Michael Brohl commented on OFBIZ-11306: --- {quote}I'll take care of that ASAP... At this stage of

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-24 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17043255#comment-17043255 ] Jacques Le Roux commented on OFBIZ-11306: - James, No worries, it was more that I waited too

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-24 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17043252#comment-17043252 ] Jacques Le Roux commented on OFBIZ-11306: - Michael, bq. I would suggest a PR which can easily

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-24 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17043238#comment-17043238 ] James Yong commented on OFBIZ-11306: Hi Jacques, {quote}This is where using a shared feature branch

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-24 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17043225#comment-17043225 ] Jacques Le Roux commented on OFBIZ-11306: - Hi James, This is where using a shared feature

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-24 Thread Michael Brohl (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17043212#comment-17043212 ] Michael Brohl commented on OFBIZ-11306: --- Thanks Jacques! {quote}Yes eventually, this is still a

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-24 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17043206#comment-17043206 ] Jacques Le Roux commented on OFBIZ-11306: - Hi Michael, bq. A general question: is the change

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-23 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17043181#comment-17043181 ] James Yong commented on OFBIZ-11306: Hi Jacques, {quote}Check/Update Database: can't be accessed.

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-23 Thread Michael Brohl (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17042868#comment-17042868 ] Michael Brohl commented on OFBIZ-11306: --- {quote}Entity Reference - Interactive Version (also it's

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-23 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17042834#comment-17042834 ] Jacques Le Roux commented on OFBIZ-11306: - I wrote in a comment above: {quote} We have several

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-22 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17042781#comment-17042781 ] James Yong commented on OFBIZ-11306: Hi Jacques, bq. OK, I'll do in the patch to come. Better to

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-21 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17042404#comment-17042404 ] Jacques Le Roux commented on OFBIZ-11306: - Hi James, bq. I think csrf-defense-enabled can be

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-21 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17041863#comment-17041863 ] James Yong commented on OFBIZ-11306: Hi Jacques, {quote}What is the purpose of NoCsrfDefenseStrategy

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-21 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17041686#comment-17041686 ] Jacques Le Roux commented on OFBIZ-11306: - I get the same in git-bash on Windows: {noformat}

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-21 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17041685#comment-17041685 ] Jacques Le Roux commented on OFBIZ-11306: - For entityref, I have an issue which is maybe only on

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-20 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17041637#comment-17041637 ] Jacques Le Roux commented on OFBIZ-11306: - Hi James, What is the purpose of

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-19 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17040196#comment-17040196 ] James Yong commented on OFBIZ-11306: Thanks Jacques. Hi Jacques, Updated 

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-18 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17039239#comment-17039239 ] James Yong commented on OFBIZ-11306: Hi Jacques, Updated [^OFBIZ-11306-alternative.patc(] with the

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-16 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17037899#comment-17037899 ] James Yong commented on OFBIZ-11306: Hi Jacques, Updated [^OFBIZ-11306-alternative.patch] with the

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-16 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17037850#comment-17037850 ] James Yong commented on OFBIZ-11306: Hi Jacques, I made some mistakes while creating a patch and

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-16 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17037842#comment-17037842 ] Jacques Le Roux commented on OFBIZ-11306: - Yes, please do James, there is no hurry to create a

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-16 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17037837#comment-17037837 ] James Yong commented on OFBIZ-11306: Hi Jacques, bq.Also I think we should now stop to share

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-16 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17037824#comment-17037824 ] Jacques Le Roux commented on OFBIZ-11306: - Hi James, As I said: {quote}When in the webtools you

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-16 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17037745#comment-17037745 ] James Yong commented on OFBIZ-11306: Hi Jacques, May I know how to reproduce the tuple issue where

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-15 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17037739#comment-17037739 ] James Yong commented on OFBIZ-11306: Hi Jacques, I have updated [^OFBIZ-11306-alternative.patch]

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-14 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17037272#comment-17037272 ] Jacques Le Roux commented on OFBIZ-11306: - Yes, please do > POC for CSRF Token >

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-14 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17037093#comment-17037093 ] James Yong commented on OFBIZ-11306: Hi Jacques, Thanks. Will look into this tomorrow if you

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-14 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17037001#comment-17037001 ] Jacques Le Roux commented on OFBIZ-11306: - HI James, Good news about getRequestUri: if you

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-13 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17036639#comment-17036639 ] James Yong commented on OFBIZ-11306: Hi Jacques, Thanks for the explanation. Will look at the tuple

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-13 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17036346#comment-17036346 ] Jacques Le Roux commented on OFBIZ-11306: - Thanks James, I'll adapt the test About the cache:

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-13 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17036159#comment-17036159 ] James Yong commented on OFBIZ-11306: Hi Jacques, Encountered the following error when running

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-11 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17034784#comment-17034784 ] Jacques Le Roux commented on OFBIZ-11306: - Hi James, Regarding the issue related to "segmented

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-10 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17034118#comment-17034118 ] James Yong commented on OFBIZ-11306: {quote}I used no modifier ([hence between protected and

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-10 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17033764#comment-17033764 ] Jacques Le Roux commented on OFBIZ-11306: - bq. Sorry about error in the test case. Can you

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-10 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17033735#comment-17033735 ] James Yong commented on OFBIZ-11306: Hi Jacques, Sorry about error in the test case. Can you

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-10 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17033683#comment-17033683 ] Jacques Le Roux commented on OFBIZ-11306: - Just got this one also running {{gradlew

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-10 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17033680#comment-17033680 ] Jacques Le Roux commented on OFBIZ-11306: - I suggest to add "If you are in dev mode you may set

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-10 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17033463#comment-17033463 ] Jacques Le Roux commented on OFBIZ-11306: - I get this in log, wich seems better than before:

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-10 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17033462#comment-17033462 ] Jacques Le Roux commented on OFBIZ-11306: - Hi James, I'm looking at your changes now... > POC

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-09 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17033305#comment-17033305 ] Jacques Le Roux commented on OFBIZ-11306: - Thanks James, {noformat} I get this (despite a

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-09 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17033243#comment-17033243 ] James Yong commented on OFBIZ-11306: Hi Jacques, I am fine with not using UtilCache for storing the

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-09 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17033206#comment-17033206 ] Jacques Le Roux commented on OFBIZ-11306: - Note that you can't not use brower history either

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-09 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17033203#comment-17033203 ] Jacques Le Roux commented on OFBIZ-11306: - Something annoying when you lose your session

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-09 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17033186#comment-17033186 ] Jacques Le Roux commented on OFBIZ-11306: - Please find attached an alternative patch which is

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-09 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17033185#comment-17033185 ] Jacques Le Roux commented on OFBIZ-11306: - Yes, though it's easy to point that a CSRF

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-09 Thread Michael Brohl (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17033173#comment-17033173 ] Michael Brohl commented on OFBIZ-11306: --- It's an improvement, not a security fix. The priority

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-09 Thread Pierre Smits (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17033172#comment-17033172 ] Pierre Smits commented on OFBIZ-11306: -- I wonder why the priority of this ticket is set to

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-08 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17032897#comment-17032897 ] Jacques Le Roux commented on OFBIZ-11306: - Indeed, I wondered after picking request, better in

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-08 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17032870#comment-17032870 ] James Yong commented on OFBIZ-11306: Hi Jacques, Thanks for the work so far. I think

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-07 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17032823#comment-17032823 ] Jacques Le Roux commented on OFBIZ-11306: - Hi James, Please try this one: [^OFBIZ-11306.patch]

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-07 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17032817#comment-17032817 ] James Yong commented on OFBIZ-11306: Hi Jacques, Applying the current patch gives me the followng

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-07 Thread James Yong (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17032541#comment-17032541 ] James Yong commented on OFBIZ-11306: Hi Michael, {quote}Yes, my main point is that we should avoid

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-07 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17032510#comment-17032510 ] Jacques Le Roux commented on OFBIZ-11306: - Agreed, I'll rather use OFBIZ-11301 and

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-07 Thread Michael Brohl (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17032479#comment-17032479 ] Michael Brohl commented on OFBIZ-11306: --- Hi Jacques, we should stop hijacking the issue for these

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-07 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17032478#comment-17032478 ] Jacques Le Roux commented on OFBIZ-11306: - Sorry to make this issue more confusing, but since we

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-07 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17032457#comment-17032457 ] Jacques Le Roux commented on OFBIZ-11306: - Michael, Pierre, If you read James's 20/Dec/19 12:21

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-07 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17032455#comment-17032455 ] Jacques Le Roux commented on OFBIZ-11306: - I just noticed that my yesterday path is in the Git

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token

2020-02-07 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17032452#comment-17032452 ] Jacques Le Roux commented on OFBIZ-11306: - bq. Yes, my main point is that we should avoid

  1   2   >