[ANN] Apache Syncope 2.1.3

2019-01-21 Thread Francesco Chicchiriccò
The Apache Syncope team is pleased to announce the release of Syncope 2.1.3 Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: http://syncope.apache.org/downloads

[ANN] Apache Syncope 2.0.12

2019-01-21 Thread Francesco Chicchiriccò
The Apache Syncope team is pleased to announce the release of Syncope 2.0.12. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: http://syncope.apache.org/downlo

[RESULT] [VOTE] Apache Syncope 2.1.3

2019-01-20 Thread Francesco Chicchiriccò
[Re-sending with corrected subject] Hi all, after 72 hours, the vote for Syncope 2.1.3 [1] *passes* with 6 PMC + 2 non-PMC votes. +1 (PMC / binding) * Fabio Martelli * Andrea Patricelli * Jean-Baptiste Onofré * Marco Di Sabatino * Matteo Alessandroni * Francesco Chicchiriccò +1 (non binding

Re: [VOTE] Apache Syncope 2.1.3

2019-01-20 Thread Francesco Chicchiriccò
Hi all, after 72 hours, the vote for Syncope 2.1.3 [1] *passes* with 6 PMC + 2 non-PMC votes. +1 (PMC / binding) * Fabio Martelli * Andrea Patricelli * Jean-Baptiste Onofré * Marco Di Sabatino * Matteo Alessandroni * Francesco Chicchiriccò +1 (non binding) * Lorenzo Di Cola * Dima Ayash 0

[RESULT] [VOTE] Apache Syncope 2.0.12

2019-01-20 Thread Francesco Chicchiriccò
Hi all, after 72 hours, the vote for Syncope 2.0.12 [1] *passes* with 6 PMC + 2 non-PMC votes. +1 (PMC / binding) * Fabio Martelli * Andrea Patricelli * Jean-Baptiste Onofré * Marco Di Sabatino * Matteo Alessandroni * Francesco Chicchiriccò +1 (non binding) * Lorenzo Di Cola * Dima Ayash 0

[VOTE] Apache Syncope 2.0.12

2019-01-17 Thread Francesco Chicchiriccò
igned using 273DF287): http://www.apache.org/dist/syncope/KEYS Vote will be open for 72 hours. [ ] +1 approve [ ] +0 no opinion [ ] -1 disapprove (and reason why) Here's my +1 Regards. -- Francesco Chicchiriccò Tirasa - Open Source Excellence http://www.tirasa.net/ Member at The Apach

[VOTE] Apache Syncope 2.1.3

2019-01-17 Thread Francesco Chicchiriccò
e.org/dist/syncope/KEYS Vote will be open for 72 hours. [ ] +1 approve [ ] +0 no opinion [ ] -1 disapprove (and reason why) Here's my +1 Regards. -- Francesco Chicchiriccò Tirasa - Open Source Excellence http://www.tirasa.net/ Member at The Apache Software Foundation Syncope, Cocoon, O

[DISCUSS] Apache Syncope 3.0

2018-12-03 Thread Francesco Chicchiriccò
pache+Syncope+3.0+Architecture [2] https://cwiki.apache.org/confluence/display/SYNCOPE/%5BDISCUSS%5D+Access+Management+features -- Francesco Chicchiriccò Tirasa - Open Source Excellence http://www.tirasa.net/ Member at The Apache Software Foundation Syncope, Cocoon, Olingo, CXF, OpenJPA, PonyMail

Re: [DISCUSS] Manage millions of identities

2018-11-27 Thread Francesco Chicchiriccò
On 26/11/18 08:29, Francesco Chicchiriccò wrote: On 07/11/18 13:48, Francesco Chicchiriccò wrote: On 29/10/18 11:27, Francesco Chicchiriccò wrote: [...] I am currently in the middle of a spike which leverages PostgreSQL's JSONB data type to replace *PlainAttr / * PlainAttrValue, and

Re: [DISCUSS] Manage millions of identities

2018-11-25 Thread Francesco Chicchiriccò
On 07/11/18 13:48, Francesco Chicchiriccò wrote: On 29/10/18 11:27, Francesco Chicchiriccò wrote: [...] I am currently in the middle of a spike which leverages PostgreSQL's JSONB data type to replace *PlainAttr / * PlainAttrValue, and I am around 90% feature-wise. https://issues.apach

Re: [DISCUSS] Manage millions of identities

2018-11-07 Thread Francesco Chicchiriccò
On 29/10/18 11:27, Francesco Chicchiriccò wrote: [...] I am currently in the middle of a spike which leverages PostgreSQL's JSONB data type to replace *PlainAttr / * PlainAttrValue, and I am around 90% feature-wise. https://issues.apache.org/jira/browse/SYNCOPE-1395 After that, I

[SECURITY] CVE-2018-17186 Apache Syncope

2018-11-06 Thread Francesco Chicchiriccò
CVE-2018-17186: XXE on BPMN definitions Description: An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not limited to file read, file write, and code execution. Severity: Medium Vendor: The Apache Software Foundation Affects: R

[SECURITY] CVE-2018-17184 Apache Syncope

2018-11-06 Thread Francesco Chicchiriccò
CVE-2018-17184: Stored XSS Description: A malicious user with enough administration entitlements can inject html-like elements containing JavaScript statements into Connector names, Report names, AnyTypeClass keys and Policy descriptions. When another user with enough administration entitlements

[ANN] Apache Syncope 2.1.2

2018-11-06 Thread Francesco Chicchiriccò
The Apache Syncope team is pleased to announce the release of Syncope 2.1.2. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: http://syncope.apache.org/download

[ANN] Apache Syncope 2.0.11

2018-11-06 Thread Francesco Chicchiriccò
The Apache Syncope team is pleased to announce the release of Syncope 2.0.11. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: http://syncope.apache.org/downlo

[RESULT] [VOTE] Apache Syncope 2.1.2

2018-11-05 Thread Francesco Chicchiriccò
Hi all, after 72 hours, the vote for Syncope 2.1.2 [1] *passes* with 8 PMC + 1 non-PMC votes. +1 (PMC / binding) * Jean-Baptiste Onofré * Fabio Martelli * Massimiliano Perrone * Andrea Patricelli * Matteo Alessandroni * Marco Di Sabatino * Colm O hEigeartaigh * Francesco Chicchiriccò +1 (non

[RESULT] [VOTE] Apache Syncope 2.0.11

2018-11-05 Thread Francesco Chicchiriccò
Hi all, after 72 hours, the vote for Syncope 2.0.11 [1] *passes* with 8 PMC + 1 non-PMC votes. +1 (PMC / binding) * Jean-Baptiste Onofré * Fabio Martelli * Massimiliano Perrone * Andrea Patricelli * Matteo Alessandroni * Marco Di Sabatino * Colm O hEigeartaigh * Francesco Chicchiriccò +1 (non

[VOTE] Apache Syncope 2.0.11

2018-11-02 Thread Francesco Chicchiriccò
(yes, same as for 2.1.2, not a typo): http://syncope.apache.org/2.1.2/index.html PGP release keys (signed using 273DF287): http://www.apache.org/dist/syncope/KEYS Vote will be open for 72 hours. [ ] +1 approve [ ] +0 no opinion [ ] -1 disapprove (and reason why) Here's my +1 Regards. --

[VOTE] Apache Syncope 2.1.2

2018-11-02 Thread Francesco Chicchiriccò
http://syncope.apache.org/2.1.2/index.html PGP release keys (signed using 273DF287): http://www.apache.org/dist/syncope/KEYS Vote will be open for 72 hours. [ ] +1 approve [ ] +0 no opinion [ ] -1 disapprove (and reason why) Here's my +1 Regards. -- Francesco Chicchiriccò Tirasa - O

[ANN] Switch to GitBox

2018-10-31 Thread Francesco Chicchiriccò
website accordingly: http://syncope.apache.org/source-repository For committers, you need to first link your ASF and GitHub account: https://gitbox.apache.org/setup/ Regards. -- Francesco Chicchiriccò Tirasa - Open Source Excellence http://www.tirasa.net/ Member at The Apache Software Foundation

Re: [DISCUSS] Manage millions of identities

2018-10-29 Thread Francesco Chicchiriccò
Hi Guido, On 24/10/18 20:51, Guido Wimmel wrote: Hi, Am 16.10.18 um 10:54 schrieb Francesco Chicchiriccò: Hi all, I think it's time to discuss about how we want to get prepared for scenarios where the number of identities (mostly users, for the vast majority) to manage is considerably

Re: [DISCUSS] - gitbox migration / take 2

2018-10-26 Thread Francesco Chicchiriccò
Thanks to everyone involved: given the absolutely positive feedback, I went ahead and created https://issues.apache.org/jira/browse/INFRA-17181 Regards. On 25/10/18 13:57, Francesco Chicchiriccò wrote: Hi all, we briefly discussed this item about one year ago [1], when we did not found

[DISCUSS] - gitbox migration / take 2

2018-10-25 Thread Francesco Chicchiriccò
://lists.apache.org/thread.html/d28709231a99719a3bf26d37b857f05709b02ed89c1de9cbeeddd973@%3Cdev.syncope.apache.org%3E [2] https://gitbox.apache.org/repos/asf -- Francesco Chicchiriccò Tirasa - Open Source Excellence http://www.tirasa.net/ Member at The Apache Software Foundation Syncope, Cocoon

[DISCUSS] Manage millions of identities

2018-10-16 Thread Francesco Chicchiriccò
er%20defined%20types#user-defined-types -- Francesco Chicchiriccò Tirasa - Open Source Excellence http://www.tirasa.net/ Member at The Apache Software Foundation Syncope, Cocoon, Olingo, CXF, OpenJPA, PonyMail http://home.apache.org/~ilgrosso/

Re: Edit Membership Schema Values

2018-09-12 Thread Francesco Chicchiriccò
. Regards. P.S. you should better use the u...@syncope.apache.org ML for such communications -- Francesco Chicchiriccò Tirasa - Open Source Excellence http://www.tirasa.net/ Member at The Apache Software Foundation Syncope, Cocoon, Olingo, CXF, OpenJPA, PonyMail http://home.apache.org

Re: Propagate multiple group members

2018-09-11 Thread Francesco Chicchiriccò
guide.html#propagationactions -- Francesco Chicchiriccò Tirasa - Open Source Excellence http://www.tirasa.net/ Member at The Apache Software Foundation Syncope, Cocoon, Olingo, CXF, OpenJPA, PonyMail http://home.apache.org/~ilgrosso/

Re: [DISCUSS] User requests

2018-09-11 Thread Francesco Chicchiriccò
Hi all, no objections, hence I created https://issues.apache.org/jira/browse/SYNCOPE-1369 Regards. On 07/09/2018 14:52, Francesco Chicchiriccò wrote: On 06/09/2018 12:31, Francesco Chicchiriccò wrote: Hi all, I have been lately involved into some considerations around user workflow

Re: [DISCUSS] User requests

2018-09-07 Thread Francesco Chicchiriccò
On 06/09/2018 12:31, Francesco Chicchiriccò wrote: Hi all, I have been lately involved into some considerations around user workflow, approvals and user requests. As stated in [1], "Workflow manages the internal identity lifecycle by defining statuses and transitions that every user,

[DISCUSS] User requests

2018-09-06 Thread Francesco Chicchiriccò
. WDYT? Regards. [1] https://ci.apache.org/projects/syncope/2_1_X/reference-guide.html#workflow [2] https://ci.apache.org/projects/syncope/2_1_X/reference-guide.html#flowable-user-workflow-adapter [3] https://ci.apache.org/projects/syncope/2_1_X/reference-guide.html#approval -- Francesco Chicchiriccò T

[ANN] Apache Syncope 2.1.1

2018-08-20 Thread Francesco Chicchiriccò
The Apache Syncope team is pleased to announce the release of Syncope 2.1.1. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: http://syncope.apache.org/downloads.

[ANN] Apache Syncope 2.0.10

2018-08-20 Thread Francesco Chicchiriccò
The Apache Syncope team is pleased to announce the release of Syncope 2.0.10. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: http://syncope.apache.org/download

[RESULT] [VOTE] Apache Syncope 2.1.1

2018-08-20 Thread Francesco Chicchiriccò
Hi all, after 72 hours, the vote for Syncope 2.1.1 [1] *passes* with 5 PMC + 3 non-PMC votes. +1 (PMC / binding) * Andrea Patricelli * Fabio Martelli * Massimiliano Perrone * Matteo Alessandroni * Francesco Chicchiriccò +1 (non binding) * Dima Ayash * Lorenzo Di Cola * Matteo Di Carlo 0 -1

[RESULT] [VOTE] Apache Syncope 2.0.10

2018-08-20 Thread Francesco Chicchiriccò
Hi all, after 72 hours, the vote for Syncope 2.0.10 [1] *passes* with 5 PMC + 3 non-PMC votes. +1 (PMC / binding) * Andrea Patricelli * Fabio Martelli * Massimiliano Perrone * Matteo Alessandroni * Francesco Chicchiriccò +1 (non binding) * Dima Ayash * Lorenzo Di Cola * Matteo Di Carlo 0

Re: Adding the live Compilation feature in the NetBeans plugin

2018-08-20 Thread Francesco Chicchiriccò
apache.org/jira/projects/SYNCOPE/issues/SYNCOPE-1220?filter=allopenissues [2]: https://github.com/apache/syncope/pull/82 [3] https://paste.apache.org/6Qzi -- Francesco Chicchiriccò Tirasa - Open Source Excellence http://www.tirasa.net/ Member at The Apache Software Foundation Syncope, Cocoon, O

[VOTE] Apache Syncope 2.0.10

2018-08-17 Thread Francesco Chicchiriccò
+1 Regards. -- Francesco Chicchiriccò Tirasa - Open Source Excellence http://www.tirasa.net/ Member at The Apache Software Foundation Syncope, Cocoon, Olingo, CXF, OpenJPA, PonyMail http://home.apache.org/~ilgrosso/

[VOTE] Apache Syncope 2.1.1

2018-08-17 Thread Francesco Chicchiriccò
site: http://syncope.apache.org/2.1.1/index.html PGP release keys (signed using 273DF287): http://www.apache.org/dist/syncope/KEYS Vote will be open for 72 hours. [ ] +1 approve [ ] +0 no opinion [ ] -1 disapprove (and reason why) Here's my +1 Regards. -- Francesco Chicchiriccò Tirasa - O

Re: Time for 2.0.10 / 2.1.11?

2018-08-16 Thread Francesco Chicchiriccò
the student, but he needs some time to apply last code improvements and submit the pull request. I'll advice tomorrow about the status, in the worst case I think that we can move the feature to 2.1.2. Best regards, Andrea Il 16/08/2018 14:23, Francesco Chicchiriccò ha scritto: H

Re: Time for 2.0.10 / 2.1.11?

2018-08-16 Thread Francesco Chicchiriccò
Oops, it's 2.1.1 of course... On 16/08/2018 14:23, Francesco Chicchiriccò wrote: Hi all, 2.0.10 [1] and 2.1.11 [2] are plenty of fixes and some new feature, I think it's time to release. Do you see any stopper? Regards. [1] https://issues.apache.org/jira/issues/?jql=project%20%3D

Time for 2.0.10 / 2.1.11?

2018-08-16 Thread Francesco Chicchiriccò
10 [2] https://issues.apache.org/jira/issues/?jql=project%20%3D%20SYNCOPE%20AND%20status%20in%20(Resolved%2C%20Closed)%20AND%20fixVersion%20%3D%202.1.1 -- Francesco Chicchiriccò Tirasa - Open Source Excellence http://www.tirasa.net/ Member at The Apache Software Foundation Syncope, Cocoon, O

Re: [DISCUSS] Next releases

2018-07-09 Thread Francesco Chicchiriccò
Hi all, update on this topic: all the three items below are now done. I have opened SYNCOPE-1332 to track the work around Java 9/10 on the master branch. IMO, we should focus now in defining what to put in 3.0.0. Regards. On 12/06/2018 16:46, Francesco Chicchiriccò wrote: Hi all, as you

[ANN] Apache Syncope 2.1.0

2018-07-09 Thread Francesco Chicchiriccò
The Apache Syncope team is pleased to announce the release of Syncope 2.1.0. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: http://syncope.apache.org/download

[RESULT] [VOTE] Apache Syncope 2.1.0

2018-07-09 Thread Francesco Chicchiriccò
Hi all, after 72 hours, the vote for Syncope 2.1.0 *passes* with 5PMC + 1 non-PMC votes. +1 (PMC / binding) * Fabio Martelli * Massimiliano Perrone * Matteo Alessandroni * Colm O hEigeartaigh * Francesco Chicchiriccò +1 (non binding) * Lorenzo Di Cola 0 -1 Thanks to everyone

Re: [VOTE] Apache Syncope 2.1.0

2018-07-08 Thread Francesco Chicchiriccò
uence/display/SYNCOPE/Fusion Regards. On 06/07/2018 08:12, Francesco Chicchiriccò wrote: On 05/07/2018 18:02, Francesco Chicchiriccò wrote: I've created a 2.1.0 release, with the following artifacts up for a vote: GIT source tag (1c898982ab328617cae8dc1259e89045bf73fbb3): https://git-wip-us.

Re: [VOTE] Apache Syncope 2.1.0

2018-07-05 Thread Francesco Chicchiriccò
On 05/07/2018 18:02, Francesco Chicchiriccò wrote: I've created a 2.1.0 release, with the following artifacts up for a vote: GIT source tag (1c898982ab328617cae8dc1259e89045bf73fbb3): https://git-wip-us.apache.org/repos/asf?p=syncope.git;a=tag;h=1c898982ab328617cae8dc1259e89045bf73fbb3

[VOTE] Apache Syncope 2.1.0

2018-07-05 Thread Francesco Chicchiriccò
site: http://syncope.apache.org/2.0.9/index.html PGP release keys (signed using 273DF287): http://www.apache.org/dist/syncope/KEYS Vote will be open for 72 hours. [ ] +1 approve [ ] +0 no opinion [ ] -1 disapprove (and reason why) Here's my +1 Regards. -- Francesco Chicchiriccò Tirasa - O

[ANN] Apache Syncope 2.0.9

2018-07-02 Thread Francesco Chicchiriccò
The Apache Syncope team is pleased to announce the release of Syncope 2.0.9. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: http://syncope.apache.org/download

[RESULT] [VOTE] Apache Syncope 2.0.9 - take 2

2018-07-02 Thread Francesco Chicchiriccò
Hi all, after 72 hours, the vote for Syncope 2.0.9 *passes* with 8 PMC + 2 non-PMC votes. +1 (PMC / binding) * Fabio Martelli * Matteo Alessandroni * Andrea Patricelli * Jean-Baptiste Onofré * Marco Di Sabatino * Colm O hEigeartaigh * Massimiliano Perrone * Francesco Chicchiriccò +1 (non

[VOTE] Apache Syncope 2.0.9 - take 2

2018-06-28 Thread Francesco Chicchiriccò
aging site: http://syncope.apache.org/2.0.9/index.html PGP release keys (signed using 273DF287): http://www.apache.org/dist/syncope/KEYS Vote will be open for 72 hours. [ ] +1 approve [ ] +0 no opinion [ ] -1 disapprove (and reason why) Here's my +1 Regards. -- Francesco Chicchiriccò Tir

[CANCEL] [VOTE] Apache Syncope 2.0.9

2018-06-27 Thread Francesco Chicchiriccò
-launch the vote for 2.0.9 shortly. Regards. On 27/06/2018 16:29, Francesco Chicchiriccò wrote: I've created a 2.0.9 release, with the following artifacts up for a vote: GIT source tag (43d8df8707048a17675efd98c91a06644f479d42): https://git-wip-us.apache.org/repos/asf?p=syncope.git;a=com

[VOTE] Apache Syncope 2.0.9

2018-06-27 Thread Francesco Chicchiriccò
aging site: http://syncope.apache.org/2.0.9/index.html PGP release keys (signed using 273DF287): http://www.apache.org/dist/syncope/KEYS Vote will be open for 72 hours. [ ] +1 approve [ ] +0 no opinion [ ] -1 disapprove (and reason why) Here's my +1 Regards. -- Francesco Chicchiriccò Tir

Re: [DISCUSS] Publish Docker images to DockerHub

2018-06-25 Thread Francesco Chicchiriccò
inspect the future content at https://ci.apache.org/projects/syncope/2_0_X/getting-started.html#docker Regards. On 14/06/2018 08:44, Francesco Chicchiriccò wrote: Hi, it seems that pushing to ASF's DockerHub might work differently than expected: anyway, I have opened https://issues.apach

Re: [DISCUSS] Publish Docker images to DockerHub

2018-06-13 Thread Francesco Chicchiriccò
Hi, it seems that pushing to ASF's DockerHub might work differently than expected: anyway, I have opened https://issues.apache.org/jira/browse/INFRA-16647 to ask support to Infra about this. Regards. On 12/06/2018 16:34, Andrea Patricelli wrote: Hi all, Il 12/06/2018 16:30, Fran

[DISCUSS] Next releases

2018-06-12 Thread Francesco Chicchiriccò
? Regards. [1] https://issues.apache.org/jira/projects/SYNCOPE/versions/12342943 [2] https://issues.apache.org/jira/projects/SYNCOPE/versions/12334366 -- Francesco Chicchiriccò Tirasa - Open Source Excellence http://www.tirasa.net/ Member at The Apache Software Foundation Syncope, Cocoon, Olingo, CXF

[DISCUSS] Publish Docker images to DockerHub

2018-06-12 Thread Francesco Chicchiriccò
cker.com/r/apache/ [8] https://issues.apache.org/jira/browse/INFRA-16220 -- Francesco Chicchiriccò Tirasa - Open Source Excellence http://www.tirasa.net/ Member at The Apache Software Foundation Syncope, Cocoon, Olingo, CXF, OpenJPA, PonyMail http://home.apache.org/~ilgrosso/

Re: JavaEE connection pool removeAbandoned setting

2018-06-03 Thread Francesco Chicchiriccò
On 01/06/2018 08:35, Francesco Chicchiriccò wrote: On 31/05/2018 19:30, Guido Wimmel wrote: Hi Francesco, Am 30.05.2018 um 11:11 schrieb Francesco Chicchiriccò: On 29/05/2018 20:36, Guido Wimmel wrote: Hi, the recommended JavaEE configuration example on http://syncope.apache.org/docs

Re: JavaEE connection pool removeAbandoned setting

2018-05-31 Thread Francesco Chicchiriccò
On 31/05/2018 19:30, Guido Wimmel wrote: Hi Francesco, Am 30.05.2018 um 11:11 schrieb Francesco Chicchiriccò: On 29/05/2018 20:36, Guido Wimmel wrote: Hi, the recommended JavaEE configuration example on http://syncope.apache.org/docs/reference-guide.html#javaee-container contains Is

Re: JavaEE connection pool removeAbandoned setting

2018-05-30 Thread Francesco Chicchiriccò
ments#RunSyncopeinrealenvironments-context.xml and https://github.com/apache/syncope/blob/2_0_X/src/main/asciidoc/reference-guide/workingwithapachesyncope/systemadministration/javaeecontainer.adoc ? Regards. -- Francesco Chicchiriccò Tirasa - Open Source Excellence http://www.tirasa.net/ Member at The Apache Sof

Re: Questions about testing

2018-05-24 Thread Francesco Chicchiriccò
master/fit/enduser-reference [7] https://github.com/apache/syncope/blob/master/pom.xml#L1913-L1921 -- Francesco Chicchiriccò Tirasa - Open Source Excellence http://www.tirasa.net/ Member at The Apache Software Foundation Syncope, Cocoon, Olingo, CXF, OpenJPA, PonyMail http://home.apache.org/~ilgrosso/

Re: OpenID Connect for Apache Syncope

2018-05-11 Thread Francesco Chicchiriccò
8 at 8:25 AM, Dima Ayash wrote: Hi all, Thank you for your nice words. I already opened an issue for this work  on [1]. [1] https://issues.apache.org/jira/browse/SYNCOPE-1270 Best regards, Dima Ayash. On 02/07/2018 11:26 AM, Francesco Chicchiriccò wrote: Hi Dima, welcome to the Apache Syn

Re: ApacheCon current-event banner

2018-04-18 Thread Francesco Chicchiriccò
ets/d/101O3EVBYv_QhHW74bFLoO89ydaXoUJW4AC97YhnR530/edit#gid=0 -- Francesco Chicchiriccò Tirasa - Open Source Excellence http://www.tirasa.net/ Member at The Apache Software Foundation Syncope, Cocoon, Olingo, CXF, OpenJPA, PonyMail http://home.apache.org/~ilgrosso/

Re: Dashboard exception - approvals

2018-04-18 Thread Francesco Chicchiriccò
enapi.json resource, and is set by CXF in https://github.com/apache/cxf/blob/3.1.x-fixes/rt/rs/description-swagger/src/main/java/org/apache/cxf/jaxrs/swagger/openapi/SwaggerToOpenApiConversionUtils.java#L418-L446 Possibly, the method use to reconstruct the request URL does not work properl

Re: Misleading policy documentation (minor)

2018-04-17 Thread Francesco Chicchiriccò
t an issue for me anymore. Grazie, as always, for your attention, tremendous effort, and awesome product. It's our pleasure :-) Regards. On Tue, Apr 17, 2018 at 11:30 AM, Francesco Chicchiriccò < ilgro...@apache.org> wrote: On 17/04/2018 17:25, varontron wrote: Hi, In configuring

Re: Dashboard exception - approvals

2018-04-17 Thread Francesco Chicchiriccò
se the user ML for such e-mails: please use that for the future, thanks. -- Francesco Chicchiriccò Tirasa - Open Source Excellence http://www.tirasa.net/ Member at The Apache Software Foundation Syncope, Cocoon, Olingo, CXF, OpenJPA, PonyMail http://home.apache.org/~ilgrosso/

Re: Misleading policy documentation (minor)

2018-04-17 Thread Francesco Chicchiriccò
Perhaps the docs could clarify this? Hi, I don't think so: it's [\\w@\\-\\.]+ when you use it inside a string literal in Java, but the actual regex is always [\w@\-\.]+ Regards. -- Francesco Chicchiriccò Tirasa - Open Source Excellence http://www.tirasa.net/ Member at The Ap

Re: Dashboard exception - approvals

2018-04-17 Thread Francesco Chicchiriccò
Dave - http://analgesicsolutions.com https://github.com/Novartis/YADA -- Sent from: http://syncope-dev.1063484.n5.nabble.com/ -- Francesco Chicchiriccò Tirasa - Open Source Excellence http://www.tirasa.net/ Member at The Apache Software Foundation Syncope, Cocoon, Olingo, CXF, OpenJPA, PonyMail http://home.apache.org/~ilgrosso/

Re: Token creation is not thread safe

2018-04-13 Thread Francesco Chicchiriccò
On 13/04/2018 09:48, Isuranga Perera wrote: Hi Francesco, Yes, that will fix the problem. Glad we agree :-) I'll set SYNCOPE-1301; please close the PR #70. Regards. On Fri, Apr 13, 2018 at 1:00 PM, Francesco Chicchiriccò Hi, after our discussion on PR #70 [1] yesterday, I took the c

Re: Token creation is not thread safe

2018-04-13 Thread Francesco Chicchiriccò
on of this one. Best Regards Isuranga Perera On Mon, Apr 9, 2018 at 4:27 PM, Francesco Chicchiriccò wrote: On 09/04/2018 11:24, Isuranga Perera wrote: Sure will work on that. Shall I create a JIRA? Yes, please. Do set both 2.0.9 and 2.1.0 as fix-for-versions since I will apply your PR bo

Re: Default 'User Workflow' issue

2018-04-12 Thread Francesco Chicchiriccò
rWorkflow.bpmn20.xml [5] https://github.com/apache/syncope/blob/2_0_X/core/workflow-flowable/src/main/resources/userWorkflow.bpmn20.xml -- Francesco Chicchiriccò Tirasa - Open Source Excellence http://www.tirasa.net/ Member at The Apache Software Foundation Syncope, Cocoon, Olingo, CXF, OpenJPA, PonyMail http://home.apache.org/~ilgrosso/

Re: Token creation is not thread safe

2018-04-09 Thread Francesco Chicchiriccò
Mon, Apr 9, 2018 at 2:45 PM, Francesco Chicchiriccò wrote: On 09/04/2018 11:10, Isuranga Perera wrote: Since such condition can happen only if the same user tries to login from 2 mediums at the same, this is rarely happen. However that slight chance may prevent that particular user from login to

Re: Token creation is not thread safe

2018-04-09 Thread Francesco Chicchiriccò
p with a proposal which works with all the supported DBMSes, then please go on. As already asked as comment in your recent PR: did you submit an ICLA for your contributions? Thanks. Regards. On Mon, Apr 9, 2018 at 2:06 PM, Francesco Chicchiriccò wrote: On 09/04/2018 10:14, Isuranga Pere

Re: Token creation is not thread safe

2018-04-09 Thread Francesco Chicchiriccò
onstraint. Regards. On Mon, Apr 9, 2018 at 1:12 PM, Francesco Chicchiriccò wrote: On 09/04/2018 09:30, Isuranga Perera wrote: Hi Francesco, Yes there is @Transactional annotation. But it haven't set the isolation property as well as the propagation property. Based on the default va

Re: Token creation is not thread safe

2018-04-09 Thread Francesco Chicchiriccò
ong. The transaction isolation level is set in https://github.com/apache/syncope/blob/master/core/persistence-jpa/src/main/resources/domains/MasterDomain.xml#L57-L59 Regards. On Mon, Apr 9, 2018 at 12:20 PM, Francesco Chicchiriccò wrote: On 09/04/2018 08:46, Isuranga Perera wrote: Hi Francesc

Re: Token creation is not thread safe

2018-04-08 Thread Francesco Chicchiriccò
java/data/AccessTokenDataBinderImpl.java#L119 Best Regards Isuranga Perera On Mon, Apr 9, 2018 at 11:42 AM, Francesco Chicchiriccò mailto:ilgro...@apache.org>> wrote: On 09/04/2018 07:07, Isuranga Perera wrote: Hi All, Token create method in AccessTokenDataBinderImpl

Re: Token creation is not thread safe

2018-04-08 Thread Francesco Chicchiriccò
#L104 [2] https://github.com/apache/syncope/blob/master/core/provisioning-java/src/main/java/org/apache/syncope/core/provisioning/java/data/AccessTokenDataBinderImpl.java#L113 Best Regards Isuranga Perera -- Francesco Chicchiriccò Tirasa - Open Source Excellence http://www.tirasa.net/ Member a

Re: Support Groovy implementations in the Eclipse IDE plugin

2018-04-06 Thread Francesco Chicchiriccò
from current master branch) is still *very* important. Regards. On Fri, Apr 6, 2018 at 4:36 PM, Francesco Chicchiriccò mailto:ilgro...@apache.org>> wrote: On 06/04/2018 08:41, Isuranga Perera wrote: Hi Francesco, I was able to build the source (master branch)

Re: Support Groovy implementations in the Eclipse IDE plugin

2018-04-06 Thread Francesco Chicchiriccò
terpart) to get more insight about the features to add. Regards. -- Francesco Chicchiriccò Tirasa - Open Source Excellence http://www.tirasa.net/ Member at The Apache Software Foundation Syncope, Cocoon, Olingo, CXF, OpenJPA, PonyMail http://home.apache.org/~ilgrosso/

Re: SYNCOPE-1270 : OpenID Connect client feature

2018-04-04 Thread Francesco Chicchiriccò
that Groovy implementations are only available in the master branch, so you should work there. Regards. On Wed, Apr 4, 2018 at 4:47 PM, Francesco Chicchiriccò mailto:ilgro...@apache.org>> wrote: Hi, I can see a couple of issues in JIRA waiting for someone to pick up:

Re: SYNCOPE-1270 : OpenID Connect client feature

2018-04-04 Thread Francesco Chicchiriccò
o his account in "Google" and by having a user in Apache Syncope. I would really appreciate questions for more details and also more suggestions to enhance this work. Thank you in advance and best regards, Dima Ayash. - Original Message - From: &qu

Re: quartz tables not installing

2018-04-03 Thread Francesco Chicchiriccò
oning.java.cache.MemoryVirAttrCache quartz.jobstore=org.quartz.impl.jdbcjobstore.PostgreSQLDelegate quartz.sql=tables_postgres.sql quartz.disableInstance=false Thanks! Dave On Mon, Apr 2, 2018 at 12:38 PM, Francesco Chicchiriccò wrote: Hi Dave, please see my replies embedded below. On 02/04

Re: SYNCOPE-1270 : OpenID Connect client feature

2018-04-02 Thread Francesco Chicchiriccò
requests from JIRA, or propose a new one. @Dima: could it be possible to provide a status update about your work there? Regards. -- Francesco Chicchiriccò Tirasa - Open Source Excellence http://www.tirasa.net/ Member at The Apache Software Foundation Syncope, Cocoon, Olingo, CXF, OpenJPA, PonyMail

Re: quartz tables not installing

2018-04-02 Thread Francesco Chicchiriccò
nt of core/src/main/resources/provisioning.properties ? -- Francesco Chicchiriccò Tirasa - Open Source Excellence http://www.tirasa.net/ Member at The Apache Software Foundation Syncope, Cocoon, Olingo, CXF, OpenJPA, PonyMail http://home.apache.org/~ilgrosso/

Re: 2.0.8 (stable) YAMLFactory not found et al

2018-03-30 Thread Francesco Chicchiriccò
topping tomcat...;eval "$TC_CMD stop" rm $LOGDIR/* rm -rf $DEPLOYDIR/syncope* find . -name "*.war" -exec cp {} $DEPLOYDIR \; -print echo Starting tomcat...;eval "$TC_CMD start" --- HTH, Dave Varon Creator of YADA <https://github.com/Novartis/YADA> https

[SECURITY] CVE-2018-1322: Information disclosure via FIQL and ORDER BY sorting

2018-03-19 Thread Francesco Chicchiriccò
Che-Chun Kuo. References: [1] http://syncope.apache.org/security.html -- Francesco Chicchiriccò Tirasa - Open Source Excellence http://www.tirasa.net/ Member at The Apache Software Foundation Syncope, Cocoon, Olingo, CXF, OpenJPA, PonyMail http://home.apache.org/~ilgrosso/

[SECURITY] CVE-2018-1321: Remote code execution by administrators with report and template entitlements

2018-03-19 Thread Francesco Chicchiriccò
: Do not assign report and template entitlements to any administrator. Credit: This issue was discovered by Che-Chun Kuo. References: [1] http://syncope.apache.org/security.html -- Francesco Chicchiriccò Tirasa - Open Source Excellence http://www.tirasa.net/ Member at The Apache Software

[ANN] Apache Syncope 1.2.11

2018-03-19 Thread Francesco Chicchiriccò
The Apache Syncope team is pleased to announce the release of Syncope 1.2.11. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: http://syncope.apache.org/downlo

[ANN] Apache Syncope 2.0.8

2018-03-19 Thread Francesco Chicchiriccò
The Apache Syncope team is pleased to announce the release of Syncope 2.0.8. Apache Syncope is an Open Source system for managing digital identities in enterprise environments, implemented in Java EE technology . The release will be available within 24h from: http://syncope.apache.org/download

[RESULT] [VOTE] Apache Syncope 2.0.8

2018-03-19 Thread Francesco Chicchiriccò
Hi all, after 72 hours, the vote for Syncope 2.0.8 [1] *passes* with 8 PMC + 2 non-PMC votes. +1 (PMC / binding) * Francesco Chicchiriccò * Matteo Alessandroni * Jean-Baptiste Onofré * Fabio Martelli * Massimiliano Perrone * Andrea Patricelli * Marco Di Sabatino * Colm O hEigeartaigh +1 (non

[RESULT] [VOTE] Apache Syncope 1.2.11

2018-03-19 Thread Francesco Chicchiriccò
Hi all, after 72 hours, the vote for Syncope 1.2.11 [1] *passes* with 8 PMC + 2 non-PMC votes. +1 (PMC / binding) * Francesco Chicchiriccò * Matteo Alessandroni * Jean-Baptiste Onofré * Fabio Martelli * Massimiliano Perrone * Andrea Patricelli * Marco Di Sabatino * Colm O hEigeartaigh +1 (non

[VOTE] Apache Syncope 2.0.8

2018-03-13 Thread Francesco Chicchiriccò
aging site: http://syncope.apache.org/2.0.8/index.html PGP release keys (signed using 273DF287): http://www.apache.org/dist/syncope/KEYS Vote will be open for 72 hours. [ ] +1 approve [ ] +0 no opinion [ ] -1 disapprove (and reason why) Here's my +1 Regards. -- Francesco Chicchiriccò Tir

[VOTE] Apache Syncope 1.2.11

2018-03-13 Thread Francesco Chicchiriccò
aging site: http://syncope.apache.org/2.0.8/index.html PGP release keys (signed using 273DF287): http://www.apache.org/dist/syncope/KEYS Vote will be open for 72 hours. [ ] +1 approve [ ] +0 no opinion [ ] -1 disapprove (and reason why) Here's my +1 Regards. -- Francesco Chicchiriccò Tir

Re: [DISCUSS] - Privileges in Syncope 2.1.0

2018-03-12 Thread Francesco Chicchiriccò
Hi, I went ahead and created https://issues.apache.org/jira/browse/SYNCOPE-1281 and https://cwiki.apache.org/confluence/display/SYNCOPE/%5BDISCUSS%5D+Privilege+management for discussion. Regards. On 15/09/2017 08:49, Francesco Chicchiriccò wrote: On 14/09/2017 18:36, Colm O hEigeartaigh

Re: Null Pointer Exception on opening apache syncope window in netbeans

2018-03-12 Thread Francesco Chicchiriccò
http://syncope.apache.org/contributing.html#How_do_I_become_a_contributor_or_a_committer -- Francesco Chicchiriccò Tirasa - Open Source Excellence http://www.tirasa.net/ Member at The Apache Software Foundation Syncope, Cocoon, Olingo, CXF, OpenJPA, PonyMail http://home.apache.org/~ilgrosso/

Re: Regarding syncope-standalone 2.1.0 -SNAPSHOT

2018-02-20 Thread Francesco Chicchiriccò
w the Java process to bind to the port 9080: after saying yes, I could finally access http://localhost:9080/syncope-console HTH Regards. [1] https://javatutorial.net/set-java-home-windows-10 -- Francesco Chicchiriccò Tirasa - Open Source Excellence http://www.tirasa.net/ Member at The Apach

Re: [PROPOSAL] Replace SecureRandom with ThreadLocalRandom

2018-02-08 Thread Francesco Chicchiriccò
On 08/02/2018 11:38, Francesco Chicchiriccò wrote: On 08/02/2018 11:37, Colm O hEigeartaigh wrote: On Thu, Feb 8, 2018 at 10:29 AM, Francesco Chicchiriccò wrote: "Instances of |java.util.Random| are threadsafe. However, the concurrent use of the same |java.util.Random| instance across th

Re: [PROPOSAL] Replace SecureRandom with ThreadLocalRandom

2018-02-08 Thread Francesco Chicchiriccò
On 08/02/2018 11:37, Colm O hEigeartaigh wrote: On Thu, Feb 8, 2018 at 10:29 AM, Francesco Chicchiriccò wrote: "Instances of |java.util.Random| are threadsafe. However, the concurrent use of the same |java.util.Random| instance across threads may encounter contention and consequent

Re: [PROPOSAL] Replace SecureRandom with ThreadLocalRandom

2018-02-08 Thread Francesco Chicchiriccò
On 08/02/2018 11:17, Colm O hEigeartaigh wrote: Hi Francesco, On Wed, Feb 7, 2018 at 12:12 PM, Francesco Chicchiriccò wrote: I see... what about wrapping SecureRandom in ThreadLocal instead, e.g. replacing What does wrapping SecureRandom in ThreadLocal buy us from a performance POV? As

Re: [PROPOSAL] Replace SecureRandom with ThreadLocalRandom

2018-02-07 Thread Francesco Chicchiriccò
and other Java EE containers on Linux WDYT? On Mon, Feb 5, 2018 at 12:25 PM, Colm O hEigeartaigh wrote: No, my query got passed on to someone else, still waiting to hear back Colm. On Mon, Feb 5, 2018 at 7:44 AM, Francesco Chicchiriccò < ilgro...@apache.org> wrote: Hi, thanks

Re: OpenID Connect for Apache Syncope

2018-02-07 Thread Francesco Chicchiriccò
of L'Aquila, Italy. And now I am a trainee in Tirasa Company. I am interested to work in "OpenID Connect for Apache Syncope" which will be the subject of my thesis too. I also submitted the Individual Contributor License Agreement (ICLA). Thank you in advance and best regards, Di

Re: [PROPOSAL] Replace SecureRandom with ThreadLocalRandom

2018-02-04 Thread Francesco Chicchiriccò
Hi, thanks for the feedback go to so far. I know from IRC that Colm has been exploring the security feasibility with some of his contacts:  any results so far? Regards. On 30/01/2018 08:24, Francesco Chicchiriccò wrote: Hi there, any feedback on this? If no one sees issues with that I&#x

Re: [PROPOSAL] Replace SecureRandom with ThreadLocalRandom

2018-01-29 Thread Francesco Chicchiriccò
Hi there, any feedback on this? If no one sees issues with that I'll proceed as indicated. Regards. On 24/01/2018 17:54, Francesco Chicchiriccò wrote: Hi all (and Colm in particular, as this should be in your chords), we are currently basing all operations requiring random generation (m

<    1   2   3   4   5   6   7   8   9   10   >