Build failed in Jenkins: Struts-JDK6-features #24

2014-03-06 Thread Apache Jenkins Server
See Changes: [Lukasz Lenart] Updates I18N note after @sbenitez review [Lukasz Lenart] Adds I18N note to all archetypes [Lukasz Lenart] Adds I18N note to all example apps -- [...truncated 252

Re: New logo

2014-03-06 Thread Lukasz Lenart
Maybe some of these https://www.google.com/fonts#ReviewPlace:refine/Collection:Alegreya+Sans+SC|Flamenco|Cambo|Esteban|Audiowide|Carrois+Gothic+SC|Alef|Prosto+One|Varela+Round|Roboto|Nobile|Inconsolata 2014-03-07 7:47 GMT+01:00 Matthew Panetta : > My thoughts exactly. Needs a different font. > On

Re: New logo

2014-03-06 Thread Matthew Panetta
My thoughts exactly. Needs a different font. On 07/03/2014 5:41 pm, "i...@flyingfischer.ch" wrote: > The Logo looks nice. Has a slight reference to the art work of M.C. > Escher. Great work. > > Blue is always nice ;-) > > The typography however gives the whole logo a not too modern touch, > beca

Re: New logo

2014-03-06 Thread Chris Pratt
I like it, and I agree a nice Cobalt Blue would rock. (*Chris*) On Thu, Mar 6, 2014 at 10:40 PM, i...@flyingfischer.ch < i...@flyingfischer.ch> wrote: > The Logo looks nice. Has a slight reference to the art work of M.C. > Escher. Great work. > > Blue is always nice ;-) > > The typography howe

Re: New logo

2014-03-06 Thread i...@flyingfischer.ch
The Logo looks nice. Has a slight reference to the art work of M.C. Escher. Great work. Blue is always nice ;-) The typography however gives the whole logo a not too modern touch, because it uses letters with serifs. I wonder if this will match nicely with the serif free home page of struts 2

Re: New logo

2014-03-06 Thread Lukasz Lenart
Link if attachment is missing https://copy.com/MXrnIYz8KajY 2014-03-07 0:01 GMT+01:00 Chris Pratt : > I must have missed it, I don't see anything?? > (*Chris*) > > > On Thu, Mar 6, 2014 at 2:00 PM, Lukasz Lenart wrote: > >> Work continues, 3rd version of logo, wdyt? I think dark-blue version >>

Build failed in Jenkins: Struts-JDK6-master #885

2014-03-06 Thread Apache Jenkins Server
See -- [...truncated 4586 lines...] Generating Generating

Build failed in Jenkins: Struts-JDK6-features #23

2014-03-06 Thread Apache Jenkins Server
See -- [...truncated 2527 lines...] Mar 7, 2014 12:48:31 AM com.opensymphony.xwork2.util.profiling.UtilTimerStack info INFO: [7ms] - execute: [7ms] - invoke: [7ms] - interceptor: staticParams

Build failed in Jenkins: Struts-JDK7-master #278

2014-03-06 Thread Apache Jenkins Server
See Changes: [Lukasz Lenart] Reverts version to -SNAPSHOT [Lukasz Lenart] Upgrades Commons File Upload to the latest version [Lukasz Lenart] Adds additional exclude params [Lukasz Lenart] Updates tag [Lukasz Lenart] Updates versi

Build failed in Jenkins: Struts-JDK6-master #884

2014-03-06 Thread Apache Jenkins Server
See Changes: [Lukasz Lenart] Reverts version to -SNAPSHOT [Lukasz Lenart] Upgrades Commons File Upload to the latest version [Lukasz Lenart] Adds additional exclude params [Lukasz Lenart] Updates tag [Lukasz Lenart] Updates versi

Re: New logo

2014-03-06 Thread Chris Pratt
I must have missed it, I don't see anything?? (*Chris*) On Thu, Mar 6, 2014 at 2:00 PM, Lukasz Lenart wrote: > Work continues, 3rd version of logo, wdyt? I think dark-blue version > would be also nice. > > 2013-11-26 8:59 GMT+01:00 Lukasz Lenart : > > I have passed your comment to designer - a

Re: New logo

2014-03-06 Thread Lukasz Lenart
Work continues, 3rd version of logo, wdyt? I think dark-blue version would be also nice. 2013-11-26 8:59 GMT+01:00 Lukasz Lenart : > I have passed your comment to designer - anyway we have time and we > can always start over when the first logo won't be good enough ;-) > > > Reagrds > -- > Łukasz

Advices needed of native speaker

2014-03-06 Thread Lukasz Lenart
Hi, Can someone take a look on this note? https://issues.apache.org/jira/browse/WW-4248?focusedCommentId=13923086&page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel#comment-13923086 Thanks in advance -- Łukasz + 48 606 323 122 http://www.lenart.org.pl/ -

Time to start new release

2014-03-06 Thread Lukasz Lenart
Hi, Time to start work on new release, any important issues to solve and include in the release? Thus probably will be the last 2.3.x - next will be 2.5.x (minor code cleanup) or 3.0 (large refactorings) Regards -- Łukasz + 48 606 323 122 http://www.lenart.org.pl/ -

[GitHub] struts pull request: Restricts direct access to JSP files

2014-03-06 Thread lukaszlenart
Github user lukaszlenart closed the pull request at: https://github.com/apache/struts/pull/2 --- If your project is set up for it, you can reply to this email and have your reply appear on GitHub as well. If your project does not have this feature enabled and wishes so, or if the feature is

Re: [ANN] Struts 2.3.16.1 GA release available - security fix

2014-03-06 Thread Lukasz Lenart
Ok, thanks! 2014-03-06 18:23 GMT+01:00 Mark Thomas : > On 06/03/2014 17:08, Lukasz Lenart wrote: >> So who's the reporter? > > We (the ASF) know who discovered CVE-2014-0050 but they have not given > permission to be named. The only public credit information is that which > was published for CVE-2

Re: [ANN] Struts 2.3.16.1 GA release available - security fix

2014-03-06 Thread Lukasz Lenart
So who's the reporter? 2014-03-06 16:54 GMT+01:00 Mark Thomas : > On 06/03/2014 09:04, Lukasz Lenart wrote: >> This release includes important security fixes: >> - S2-020 - ClassLoader manipulation via request parameters >> - upgraded Commons FileUpload library to prevent DoS attacks >> >> * http:

Re: [Full-disclosure] [ANN] Struts 2.3.16.1 GA release available - security fix

2014-03-06 Thread Lukasz Lenart
No, rather no. You gain access to ClassLoader. 2014-03-06 16:43 GMT+01:00 Tim : > >> This release includes important security fixes: >> - S2-020 - ClassLoader manipulation via request parameters > > What is the ultimate impact of this manipulation? Another RCE bug? > > tim --

Re: LocalizedTextUtil mods

2014-03-06 Thread Lukasz Lenart
2014-03-06 17:51 GMT+01:00 Greg Huber : > Following this http://struts.apache.org/git-for-struts.html > > url https://github.com/apachestruts/struts don't look correct? 404 >> > apache/struts It suppose to be https://github.com/apache/struts - where did f

Re: [Full-disclosure] [ANN] Struts 2.3.16.1 GA release available - security fix

2014-03-06 Thread Tim
> This release includes important security fixes: > - S2-020 - ClassLoader manipulation via request parameters What is the ultimate impact of this manipulation? Another RCE bug? tim - To unsubscribe, e-mail: dev-unsubscr...@st

Re: [ANN] Struts 2.3.16.1 GA release available - security fix

2014-03-06 Thread Mark Thomas
On 06/03/2014 09:04, Lukasz Lenart wrote: > This release includes important security fixes: > - S2-020 - ClassLoader manipulation via request parameters > - upgraded Commons FileUpload library to prevent DoS attacks > > * http://struts.apache.org/release/2.3.x/docs/s2-020.html Please remove my na

Re: LocalizedTextUtil mods

2014-03-06 Thread Greg Huber
Following this http://struts.apache.org/git-for-struts.html url https://github.com/apachestruts/struts don't look correct? 404 >> apache/struts On 6 March 2014 13:34, Lukasz Lenart wrote: > 2014-03-06 13:38 GMT+01:00 Greg Huber : > > Seeing this mod t

Re: LocalizedTextUtil mods

2014-03-06 Thread Greg Huber
Every will scan up the package hierarchy ie is does these getMessage(..) findText(..) calls: ListEvents.title : org.events.ui.struts2.editor.Events ListEvents.title : org.events.ui.struts2.editor.EventBase ListEvents.title : org.events.ui.struts2.util.ActionBase ListEvents.title : com.opensymph

Re: LocalizedTextUtil mods

2014-03-06 Thread Lukasz Lenart
2014-03-06 13:38 GMT+01:00 Greg Huber : > Seeing this mod the other day has reminded me that I do a local change on > LocalizedTextUtil to speed up the screens. > > What I do is to add a check to see if the property comes from the > getDefaultMessage(..) method (ie from ApplicationResources.propert

Re: LocalizedTextUtil mods

2014-03-06 Thread Dave Newton
What's the actual speedup? It might be nice if it was configurable; I'm not sure what the stats would be regarding how many apps use S2 vs. "regular" localization. Dave On Thu, Mar 6, 2014 at 7:38 AM, Greg Huber wrote: > Seeing this mod the other day has reminded me that I do a local change

LocalizedTextUtil mods

2014-03-06 Thread Greg Huber
Seeing this mod the other day has reminded me that I do a local change on LocalizedTextUtil to speed up the screens. What I do is to add a check to see if the property comes from the getDefaultMessage(..) method (ie from ApplicationResources.properties) and if it does skip all the checking that it

[ANN] Struts 2.3.16.1 GA release available - security fix

2014-03-06 Thread Lukasz Lenart
The Apache Struts group is pleased to announce that Struts 2.3.16.1 is available as a "General Availability" release.The GA designation is our highest quality grade. Apache Struts 2 is an elegant, extensible framework for creating enterprise-ready Java web applications. The framework is designed t