[jira] [Updated] (OFBIZ-11259) SOAPService does not work

2019-10-30 Thread Jacques Le Roux (Jira)


 [ 
https://issues.apache.org/jira/browse/OFBIZ-11259?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Jacques Le Roux updated OFBIZ-11259:

Description: 
https://demo-stable.ofbiz.apache.org/webtools/control/SOAPService/createPerson?WSDL

works, but

https://demo-trunk.ofbiz.apache.org/webtools/control/SOAPService/createPerson?WSDL

Same for R18

  was:
https://demo-stable.ofbiz.apache.org/webtools/control/SOAPService/createPerson?WSDL

works, but

https://demo-trunk.ofbiz.apache.org/webtools/control/SOAPService/createPerson?WSDL

Same for R17 and R18


> SOAPService does not work
> -
>
> Key: OFBIZ-11259
> URL: https://issues.apache.org/jira/browse/OFBIZ-11259
> Project: OFBiz
>  Issue Type: Bug
>  Components: framework, framework/webtools
>Affects Versions: Trunk, Release Branch 17.12, Release Branch 18.12
>Reporter: Jacques Le Roux
>Assignee: Jacques Le Roux
>Priority: Major
>
> https://demo-stable.ofbiz.apache.org/webtools/control/SOAPService/createPerson?WSDL
> works, but
> https://demo-trunk.ofbiz.apache.org/webtools/control/SOAPService/createPerson?WSDL
> Same for R18



--
This message was sent by Atlassian Jira
(v8.3.4#803005)


[jira] [Assigned] (OFBIZ-11259) SOAPService does not work

2019-10-30 Thread Jacques Le Roux (Jira)


 [ 
https://issues.apache.org/jira/browse/OFBIZ-11259?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Jacques Le Roux reassigned OFBIZ-11259:
---

Assignee: Jacques Le Roux

> SOAPService does not work
> -
>
> Key: OFBIZ-11259
> URL: https://issues.apache.org/jira/browse/OFBIZ-11259
> Project: OFBiz
>  Issue Type: Bug
>  Components: framework, framework/webtools
>Affects Versions: Trunk, Release Branch 17.12, Release Branch 18.12
>Reporter: Jacques Le Roux
>Assignee: Jacques Le Roux
>Priority: Major
>
> https://demo-stable.ofbiz.apache.org/webtools/control/SOAPService/createPerson?WSDL
> works, but
> https://demo-trunk.ofbiz.apache.org/webtools/control/SOAPService/createPerson?WSDL
> Same for R17 and R18



--
This message was sent by Atlassian Jira
(v8.3.4#803005)


[jira] [Updated] (OFBIZ-11259) SOAPService does not work

2019-10-30 Thread Jacques Le Roux (Jira)


 [ 
https://issues.apache.org/jira/browse/OFBIZ-11259?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Jacques Le Roux updated OFBIZ-11259:

Affects Version/s: (was: Release Branch 17.12)

> SOAPService does not work
> -
>
> Key: OFBIZ-11259
> URL: https://issues.apache.org/jira/browse/OFBIZ-11259
> Project: OFBiz
>  Issue Type: Bug
>  Components: framework, framework/webtools
>Affects Versions: Trunk, Release Branch 18.12
>Reporter: Jacques Le Roux
>Assignee: Jacques Le Roux
>Priority: Major
>
> https://demo-stable.ofbiz.apache.org/webtools/control/SOAPService/createPerson?WSDL
> works, but
> https://demo-trunk.ofbiz.apache.org/webtools/control/SOAPService/createPerson?WSDL
> Same for R18



--
This message was sent by Atlassian Jira
(v8.3.4#803005)


[jira] [Commented] (OFBIZ-11259) SOAPService does not work

2019-10-30 Thread Jacques Le Roux (Jira)


[ 
https://issues.apache.org/jira/browse/OFBIZ-11259?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16962840#comment-16962840
 ] 

Jacques Le Roux commented on OFBIZ-11259:
-

This was broken by r1839451 committed at the bottom of OFBIZ-10438 to fix 
another issue from OFBIZ-10438.

> SOAPService does not work
> -
>
> Key: OFBIZ-11259
> URL: https://issues.apache.org/jira/browse/OFBIZ-11259
> Project: OFBiz
>  Issue Type: Bug
>  Components: framework, framework/webtools
>Affects Versions: Trunk, Release Branch 17.12, Release Branch 18.12
>Reporter: Jacques Le Roux
>Assignee: Jacques Le Roux
>Priority: Major
>
> https://demo-stable.ofbiz.apache.org/webtools/control/SOAPService/createPerson?WSDL
> works, but
> https://demo-trunk.ofbiz.apache.org/webtools/control/SOAPService/createPerson?WSDL
> Same for R18



--
This message was sent by Atlassian Jira
(v8.3.4#803005)


[jira] [Closed] (OFBIZ-11259) SOAPService does not work

2019-10-30 Thread Jacques Le Roux (Jira)


 [ 
https://issues.apache.org/jira/browse/OFBIZ-11259?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Jacques Le Roux closed OFBIZ-11259.
---
Fix Version/s: 18.12.01
   Resolution: Fixed

Fixed in trunk and R18 at r1869155

> SOAPService does not work
> -
>
> Key: OFBIZ-11259
> URL: https://issues.apache.org/jira/browse/OFBIZ-11259
> Project: OFBiz
>  Issue Type: Bug
>  Components: framework, framework/webtools
>Affects Versions: Trunk, Release Branch 18.12
>Reporter: Jacques Le Roux
>Assignee: Jacques Le Roux
>Priority: Major
> Fix For: 18.12.01
>
>
> https://demo-stable.ofbiz.apache.org/webtools/control/SOAPService/createPerson?WSDL
> works, but
> https://demo-trunk.ofbiz.apache.org/webtools/control/SOAPService/createPerson?WSDL
> Same for R18



--
This message was sent by Atlassian Jira
(v8.3.4#803005)


[jira] [Commented] (OFBIZ-11167) Use Codenarc to test Groovy code

2019-10-30 Thread Jacques Le Roux (Jira)


[ 
https://issues.apache.org/jira/browse/OFBIZ-11167?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16962873#comment-16962873
 ] 

Jacques Le Roux commented on OFBIZ-11167:
-

Looks quite promising, thanks Gil!

> Use Codenarc to test Groovy code
> 
>
> Key: OFBIZ-11167
> URL: https://issues.apache.org/jira/browse/OFBIZ-11167
> Project: OFBiz
>  Issue Type: New Feature
>  Components: framework
>Reporter: Jacques Le Roux
>Assignee: Gil Portenseigne
>Priority: Minor
> Attachments: OFBIZ-11167.patch, main.html, test.html
>
>
> Now that we use Groovy more and more, I think we should really have a look a 
> Codenarc
> https://docs.gradle.org/current/userguide/codenarc_plugin.html
> We already discussed it at https://markmail.org/message/uigcpnxqgizhd2oi and 
> https://markmail.org/message/rp6njoiohkkiodbe
> We know it's a crucial task but not an easy but rather a long term one
> Here are some interesting links (before I delete my FF tabs group about it)
> http://codenarc.sourceforge.net/codenarc-other-tools-frameworks.html
> http://codenarc.sourceforge.net/codenarc-creating-ruleset.html
> https://github.com/gradle/gradle/tree/master/config
> https://stackoverflow.com/questions/14358471/how-to-generate-codenarc-report-for-main-and-test-classes-using-different-rule-s
> https://mrhaki.blogspot.com/2011/01/gradle-goodness-use-groovy-ruleset-file.html



--
This message was sent by Atlassian Jira
(v8.3.4#803005)


[jira] [Reopened] (OFBIZ-9988) Remove unused services from party/services_view.xml and PartyServices.java/.xml

2019-10-30 Thread Jacques Le Roux (Jira)


 [ 
https://issues.apache.org/jira/browse/OFBIZ-9988?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Jacques Le Roux reopened OFBIZ-9988:

  Assignee: Jacques Le Roux  (was: Michael Brohl)

> Remove unused services from party/services_view.xml and 
> PartyServices.java/.xml
> ---
>
> Key: OFBIZ-9988
> URL: https://issues.apache.org/jira/browse/OFBIZ-9988
> Project: OFBiz
>  Issue Type: Improvement
>  Components: party
>Affects Versions: Trunk
>Reporter: Michael Brohl
>Assignee: Jacques Le Roux
>Priority: Minor
> Fix For: 17.12.01
>
>
> PartyServices.java contains several service which are not used anywhere in 
> the system for more than 10 years. It should be removed.
> See discussion at 
> https://lists.apache.org/thread.html/fa5c44c3c0d672c720c31ef58926f5bb407224c97fd5acde952e790b@%3Cdev.ofbiz.apache.org%3E



--
This message was sent by Atlassian Jira
(v8.3.4#803005)


[jira] [Comment Edited] (OFBIZ-9988) Remove unused services from party/services_view.xml and PartyServices.java/.xml

2019-10-30 Thread Jacques Le Roux (Jira)


[ 
https://issues.apache.org/jira/browse/OFBIZ-9988?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16962097#comment-16962097
 ] 

Jacques Le Roux edited comment on OFBIZ-9988 at 10/30/19 10:00 AM:
---

Hi

We heavily rely of webservices for our products. I was surprised to see it 
disappear and git log
 brings me here. I was particularly looking for getPartiesByRelationship. 
 Kindly bring it back if it does not break  things.

If there is an alternate please indicate.

 

regds
 mallah.


was (Author: rmallah):
 

Hi

We heavily rely of webservices for our products. I was surprised to see it 
disappear and git log
 brings me here. I was particularly looking for getPartiesByRelationship. 
 Kindly bring it back if it does not break  things.

 

If there is an alternate please indicate.

 

regds
 mallah.

> Remove unused services from party/services_view.xml and 
> PartyServices.java/.xml
> ---
>
> Key: OFBIZ-9988
> URL: https://issues.apache.org/jira/browse/OFBIZ-9988
> Project: OFBiz
>  Issue Type: Improvement
>  Components: party
>Affects Versions: Trunk
>Reporter: Michael Brohl
>Assignee: Jacques Le Roux
>Priority: Minor
> Fix For: 17.12.01
>
>
> PartyServices.java contains several service which are not used anywhere in 
> the system for more than 10 years. It should be removed.
> See discussion at 
> https://lists.apache.org/thread.html/fa5c44c3c0d672c720c31ef58926f5bb407224c97fd5acde952e790b@%3Cdev.ofbiz.apache.org%3E



--
This message was sent by Atlassian Jira
(v8.3.4#803005)


[jira] [Commented] (OFBIZ-9988) Remove unused services from party/services_view.xml and PartyServices.java/.xml

2019-10-30 Thread Jacques Le Roux (Jira)


[ 
https://issues.apache.org/jira/browse/OFBIZ-9988?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16962899#comment-16962899
 ] 

Jacques Le Roux commented on OFBIZ-9988:


Hi Rajesh,

Because I believe we should take into acount our users even if they don't speak 
at the time, as the discussion shows, I was to rename the services. Getting 
back to that is now a bit harder :/ Fortunately reverting r1819138 is easy. So 
I'll do that and rename the file as I then suggested.

> Remove unused services from party/services_view.xml and 
> PartyServices.java/.xml
> ---
>
> Key: OFBIZ-9988
> URL: https://issues.apache.org/jira/browse/OFBIZ-9988
> Project: OFBiz
>  Issue Type: Improvement
>  Components: party
>Affects Versions: Trunk
>Reporter: Michael Brohl
>Assignee: Jacques Le Roux
>Priority: Minor
> Fix For: 17.12.01
>
>
> PartyServices.java contains several service which are not used anywhere in 
> the system for more than 10 years. It should be removed.
> See discussion at 
> https://lists.apache.org/thread.html/fa5c44c3c0d672c720c31ef58926f5bb407224c97fd5acde952e790b@%3Cdev.ofbiz.apache.org%3E



--
This message was sent by Atlassian Jira
(v8.3.4#803005)


[jira] [Commented] (OFBIZ-9988) Remove unused services from party/services_view.xml and PartyServices.java/.xml

2019-10-30 Thread Jacques Le Roux (Jira)


[ 
https://issues.apache.org/jira/browse/OFBIZ-9988?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16962900#comment-16962900
 ] 

Jacques Le Roux commented on OFBIZ-9988:


I think I'll try to refactor the whole also...

> Remove unused services from party/services_view.xml and 
> PartyServices.java/.xml
> ---
>
> Key: OFBIZ-9988
> URL: https://issues.apache.org/jira/browse/OFBIZ-9988
> Project: OFBiz
>  Issue Type: Improvement
>  Components: party
>Affects Versions: Trunk
>Reporter: Michael Brohl
>Assignee: Jacques Le Roux
>Priority: Minor
> Fix For: 17.12.01
>
>
> PartyServices.java contains several service which are not used anywhere in 
> the system for more than 10 years. It should be removed.
> See discussion at 
> https://lists.apache.org/thread.html/fa5c44c3c0d672c720c31ef58926f5bb407224c97fd5acde952e790b@%3Cdev.ofbiz.apache.org%3E



--
This message was sent by Atlassian Jira
(v8.3.4#803005)


[jira] [Assigned] (OFBIZ-6377) Add WorkEffortAssoc screen

2019-10-30 Thread Aditya Sharma (Jira)


 [ 
https://issues.apache.org/jira/browse/OFBIZ-6377?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Aditya Sharma reassigned OFBIZ-6377:


Assignee: Aditya Sharma

> Add WorkEffortAssoc screen
> --
>
> Key: OFBIZ-6377
> URL: https://issues.apache.org/jira/browse/OFBIZ-6377
> Project: OFBiz
>  Issue Type: Improvement
>  Components: workeffort
>Affects Versions: Trunk
>Reporter: Christian Carlow
>Assignee: Aditya Sharma
>Priority: Major
> Attachments: OFBIZ-6377.patch
>
>
> WorkEffort menu lacks an associations tab which should be added and modeled 
> after the product association tab.



--
This message was sent by Atlassian Jira
(v8.3.4#803005)


[jira] [Comment Edited] (OFBIZ-9988) Remove unused services from party/services_view.xml and PartyServices.java/.xml

2019-10-30 Thread Jacques Le Roux (Jira)


[ 
https://issues.apache.org/jira/browse/OFBIZ-9988?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16962899#comment-16962899
 ] 

Jacques Le Roux edited comment on OFBIZ-9988 at 10/30/19 11:11 AM:
---

Hi Rajesh,

Because I believe we should take into acount our users even if they don't speak 
at the time, as the discussion shows, I was to rename the services. Getting 
back to that is now a bit harder :/ Fortunately reverting r1819138 is easy. So 
I'll do that and rename the services as I then suggested.


was (Author: jacques.le.roux):
Hi Rajesh,

Because I believe we should take into acount our users even if they don't speak 
at the time, as the discussion shows, I was to rename the services. Getting 
back to that is now a bit harder :/ Fortunately reverting r1819138 is easy. So 
I'll do that and rename the file as I then suggested.

> Remove unused services from party/services_view.xml and 
> PartyServices.java/.xml
> ---
>
> Key: OFBIZ-9988
> URL: https://issues.apache.org/jira/browse/OFBIZ-9988
> Project: OFBiz
>  Issue Type: Improvement
>  Components: party
>Affects Versions: Trunk
>Reporter: Michael Brohl
>Assignee: Jacques Le Roux
>Priority: Minor
> Fix For: 17.12.01
>
>
> PartyServices.java contains several service which are not used anywhere in 
> the system for more than 10 years. It should be removed.
> See discussion at 
> https://lists.apache.org/thread.html/fa5c44c3c0d672c720c31ef58926f5bb407224c97fd5acde952e790b@%3Cdev.ofbiz.apache.org%3E



--
This message was sent by Atlassian Jira
(v8.3.4#803005)


[jira] [Created] (OFBIZ-11264) Refactor Component loading

2019-10-30 Thread Mathieu Lirzin (Jira)
Mathieu Lirzin created OFBIZ-11264:
--

 Summary: Refactor Component loading
 Key: OFBIZ-11264
 URL: https://issues.apache.org/jira/browse/OFBIZ-11264
 Project: OFBiz
  Issue Type: Improvement
  Components: framework
Affects Versions: Trunk
Reporter: Mathieu Lirzin
Assignee: Mathieu Lirzin






--
This message was sent by Atlassian Jira
(v8.3.4#803005)


[jira] [Assigned] (OFBIZ-9804) Link in verification email for Newsletter gives security error

2019-10-30 Thread Jacques Le Roux (Jira)


 [ 
https://issues.apache.org/jira/browse/OFBIZ-9804?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Jacques Le Roux reassigned OFBIZ-9804:
--

Assignee: Jacques Le Roux  (was: Aditya Sharma)

> Link in verification email for Newsletter gives security error
> --
>
> Key: OFBIZ-9804
> URL: https://issues.apache.org/jira/browse/OFBIZ-9804
> Project: OFBiz
>  Issue Type: Sub-task
>  Components: ecommerce
>Affects Versions: Trunk, Release Branch 16.11
>Reporter: Aditya Sharma
>Assignee: Jacques Le Roux
>Priority: Major
> Attachments: screenshot-1.png
>
>
> Steps to generate:
> 1. Go to Ecommerce store https://localhost:8443/ecommerce/control/main
> 2. In "Sign Up For Contact List" panel from the left menu, select Newsletter, 
> provide email and click on subscribe button.(Here you should have email 
> configuration to receive email)
> 3.  Click on the verification link in the email.
> It gives following error message
> {quote}The Following Errors Occurred:
> Error calling event: org.apache.ofbiz.webapp.event.EventHandlerException: 
> Found URL parameter [contactListId] passed to secure (https) request-map with 
> uri [updateContactListPartyNoUserLogin] with an event that calls service 
> [updateContactListPartyNoUserLogin]; this is not allowed for security 
> reasons! The data should be encrypted by making it part of the request body 
> (a form field) instead of the request URL. Moreover it would be kind if you 
> could create a Jira sub-task of 
> https://issues.apache.org/jira/browse/OFBIZ-2330 (check before if a sub-task 
> for this error does not exist). If you are not sure how to create a Jira 
> issue please have a look before at 
> https://cwiki.apache.org/confluence/display/OFBIZ/OFBiz+Contributors+Best+Practices
>  Thank you in advance for your help.{quote}
> Try with the trunk link:
> https://demo-trunk.ofbiz.apache.org/ecommerce/control/updateContactListPartyNoUserLogin?contactListId=9000&partyId=_NA_&fromDate=2017-10-04%2010:48:46.531&statusId=CLPT_ACCEPTED&optInVerifyCode=9084207171&baseLocation=/ecommerce&preferredContactMechId=10010
> Stable 16 link:
> https://demo-stable.ofbiz.apache.org/ecommerce/control/updateContactListPartyNoUserLogin?contactListId=9000&partyId=_NA_&fromDate=2017-10-04%2010:48:46.531&statusId=CLPT_ACCEPTED&optInVerifyCode=9084207171&baseLocation=/ecommerce&preferredContactMechId=10010



--
This message was sent by Atlassian Jira
(v8.3.4#803005)


[jira] [Updated] (OFBIZ-11264) Refactor Component loading

2019-10-30 Thread Mathieu Lirzin (Jira)


 [ 
https://issues.apache.org/jira/browse/OFBIZ-11264?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Mathieu Lirzin updated OFBIZ-11264:
---
Attachment: 
OFBIZ-11264_0001-Improved-Import-ComponentDef-and-DependsOnInfo-inner.patch
OFBIZ-11264_0002-Remove-unnecessary-throws-declarations.patch

OFBIZ-11264_0003-Delay-the-construction-of-component-classpa.patch

OFBIZ-11264_0004-Rewrite-ComponentContainer-loadComponentsIn.patch

OFBIZ-11264_0005-Add-ComponentConfig-toString-to-ease-debugg.patch
OFBIZ-11264_0006-Turn-DependsOnInfo-into-a-String.patch

> Refactor Component loading
> --
>
> Key: OFBIZ-11264
> URL: https://issues.apache.org/jira/browse/OFBIZ-11264
> Project: OFBiz
>  Issue Type: Improvement
>  Components: framework
>Affects Versions: Trunk
>Reporter: Mathieu Lirzin
>Assignee: Mathieu Lirzin
>Priority: Major
> Attachments: 
> OFBIZ-11264_0001-Improved-Import-ComponentDef-and-DependsOnInfo-inner.patch, 
> OFBIZ-11264_0002-Remove-unnecessary-throws-declarations.patch, 
> OFBIZ-11264_0003-Delay-the-construction-of-component-classpa.patch, 
> OFBIZ-11264_0004-Rewrite-ComponentContainer-loadComponentsIn.patch, 
> OFBIZ-11264_0005-Add-ComponentConfig-toString-to-ease-debugg.patch, 
> OFBIZ-11264_0006-Turn-DependsOnInfo-into-a-String.patch
>
>




--
This message was sent by Atlassian Jira
(v8.3.4#803005)


[jira] [Commented] (OFBIZ-11264) Refactor Component loading

2019-10-30 Thread Mathieu Lirzin (Jira)


[ 
https://issues.apache.org/jira/browse/OFBIZ-11264?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16963134#comment-16963134
 ] 

Mathieu Lirzin commented on OFBIZ-11264:


Committed revision 1869180.
Committed revision 1869181.
Committed revision 1869182.
Committed revision 1869183.
Committed revision 1869184.
Committed revision 1869185.

> Refactor Component loading
> --
>
> Key: OFBIZ-11264
> URL: https://issues.apache.org/jira/browse/OFBIZ-11264
> Project: OFBiz
>  Issue Type: Improvement
>  Components: framework
>Affects Versions: Trunk
>Reporter: Mathieu Lirzin
>Assignee: Mathieu Lirzin
>Priority: Major
> Attachments: 
> OFBIZ-11264_0001-Improved-Import-ComponentDef-and-DependsOnInfo-inner.patch, 
> OFBIZ-11264_0002-Remove-unnecessary-throws-declarations.patch, 
> OFBIZ-11264_0003-Delay-the-construction-of-component-classpa.patch, 
> OFBIZ-11264_0004-Rewrite-ComponentContainer-loadComponentsIn.patch, 
> OFBIZ-11264_0005-Add-ComponentConfig-toString-to-ease-debugg.patch, 
> OFBIZ-11264_0006-Turn-DependsOnInfo-into-a-String.patch
>
>




--
This message was sent by Atlassian Jira
(v8.3.4#803005)


[jira] [Closed] (OFBIZ-11264) Refactor Component loading

2019-10-30 Thread Mathieu Lirzin (Jira)


 [ 
https://issues.apache.org/jira/browse/OFBIZ-11264?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Mathieu Lirzin closed OFBIZ-11264.
--
Fix Version/s: Upcoming Branch
   Resolution: Fixed

Thanks [~stregouet] for your contribution!

> Refactor Component loading
> --
>
> Key: OFBIZ-11264
> URL: https://issues.apache.org/jira/browse/OFBIZ-11264
> Project: OFBiz
>  Issue Type: Improvement
>  Components: framework
>Affects Versions: Trunk
>Reporter: Mathieu Lirzin
>Assignee: Mathieu Lirzin
>Priority: Major
> Fix For: Upcoming Branch
>
> Attachments: 
> OFBIZ-11264_0001-Improved-Import-ComponentDef-and-DependsOnInfo-inner.patch, 
> OFBIZ-11264_0002-Remove-unnecessary-throws-declarations.patch, 
> OFBIZ-11264_0003-Delay-the-construction-of-component-classpa.patch, 
> OFBIZ-11264_0004-Rewrite-ComponentContainer-loadComponentsIn.patch, 
> OFBIZ-11264_0005-Add-ComponentConfig-toString-to-ease-debugg.patch, 
> OFBIZ-11264_0006-Turn-DependsOnInfo-into-a-String.patch
>
>




--
This message was sent by Atlassian Jira
(v8.3.4#803005)


[jira] [Created] (OFBIZ-11265) Getting policy error while editing html text data using cms

2019-10-30 Thread Pradeep Choudhary (Jira)
Pradeep Choudhary created OFBIZ-11265:
-

 Summary: Getting policy error while editing html text data using 
cms
 Key: OFBIZ-11265
 URL: https://issues.apache.org/jira/browse/OFBIZ-11265
 Project: OFBiz
  Issue Type: Improvement
Reporter: Pradeep Choudhary
 Fix For: 17.12.01


Service parameter with allow-html="safe" does not check the OWASP sanitizer 
flag ie. enabled or not and perform sanitization which causing policy error 
while editing text data

getting following exception error:

"In field [textData] by our input policy, your input has not been accepted for 
security reason. Please check and modify accordingly, thanks."



--
This message was sent by Atlassian Jira
(v8.3.4#803005)


[jira] [Commented] (OFBIZ-11265) Getting policy error while editing html text data using cms

2019-10-30 Thread Pradeep Choudhary (Jira)


[ 
https://issues.apache.org/jira/browse/OFBIZ-11265?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16963696#comment-16963696
 ] 

Pradeep Choudhary commented on OFBIZ-11265:
---

As checked, data sanitization is done during the service validation in the 
following steps:
 # If the service parameter contains allow-html="safe", it calls 
*UtilCodec.checkStringForHtmlSafe* method for data sanitization.
 # It doesn't check the OWASP sanitizer configuration ie. sanitizer is enabled 
or disabled.
 # Perform policy checks and sanitization without entertaining the 
configuration flag.

 

IMO, UtilCodec.checkStringForHtmlSafe method should have proper checks to 
validate sanitizer configuration, which will perform the further operation only 
if the user enables the flag.

 

WDYT?

 

> Getting policy error while editing html text data using cms
> ---
>
> Key: OFBIZ-11265
> URL: https://issues.apache.org/jira/browse/OFBIZ-11265
> Project: OFBiz
>  Issue Type: Improvement
>Reporter: Pradeep Choudhary
>Priority: Major
> Fix For: 17.12.01
>
>
> Service parameter with allow-html="safe" does not check the OWASP sanitizer 
> flag ie. enabled or not and perform sanitization which causing policy error 
> while editing text data
> getting following exception error:
> "In field [textData] by our input policy, your input has not been accepted 
> for security reason. Please check and modify accordingly, thanks."



--
This message was sent by Atlassian Jira
(v8.3.4#803005)