[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2023-09-19 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 Tomás Cohen Arazi changed: What|Removed |Added Keywords|additional_work_needed | -- You are receiving

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2023-07-12 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 --- Comment #45 from Matt Blenkinsop --- Nice work everyone! Pushed to oldstable for 22.11.x -- You are receiving this mail because: You are watching all bug changes. ___ Koha-bugs maili

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2023-07-12 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 Matt Blenkinsop changed: What|Removed |Added Version(s)|23.05.00,22.11.07 |23.05.00,22.11.08,22.11.07

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2023-06-16 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 Nick Clemens changed: What|Removed |Added Blocks||34033 Referenced Bugs: htt

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2023-06-16 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 --- Comment #44 from Emmi Takkinen --- Oh and also SET password = $password needs guotation marks around $password :D Ran into this while updating my test database. After fixing them manually update proceeded without problems. -- Y

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2023-06-16 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 --- Comment #43 from Emmi Takkinen --- Also there's no table edi_vendor_accounts. -- You are receiving this mail because: You are watching all bug changes. ___ Koha-bugs mailing list Koha

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2023-06-16 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 Emmi Takkinen changed: What|Removed |Added CC||emmi.takki...@koha-suomi.fi

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2023-06-12 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 jkbijo...@gmail.com changed: What|Removed |Added CC||jkbijo...@gmail.com --

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2023-06-09 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 Tomás Cohen Arazi changed: What|Removed |Added CC||tomasco...@gmail.com --

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2023-06-07 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 --- Comment #40 from Jonathan Druart --- (In reply to David Cook from comment #39) > Would this work without the encryption_key being set though? Might need to > add a catch for that I don't think we should anything more, with bug 3

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2023-06-07 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 --- Comment #39 from David Cook --- Would this work without the encryption_key being set though? Might need to add a catch for that -- You are receiving this mail because: You are watching all bug changes. _

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2023-06-07 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 --- Comment #38 from Martin Renvoize --- I threw that together.. needs testing though. -- You are receiving this mail because: You are watching all bug changes. ___ Koha-bugs mailing list

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2023-06-07 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 Martin Renvoize changed: What|Removed |Added Keywords||additional_work_needed --

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2023-06-07 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 --- Comment #37 from Martin Renvoize --- Created attachment 152097 --> https://bugs.koha-community.org/bugzilla3/attachment.cgi?id=152097&action=edit Bug 30649: (follow-up) Improve database update This patch implements the propose

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2023-06-07 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 Jonathan Druart changed: What|Removed |Added See Also||https://bugs.koha-communit

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2023-06-06 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 --- Comment #36 from David Cook --- (In reply to Jonathan Druart from comment #35) > We could maybe require the module only if there are rows in > vendor_edi_accounts? Sounds reasonable to me -- You are receiving this mail because

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2023-06-05 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 Jonathan Druart changed: What|Removed |Added See Also||https://bugs.koha-communit

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2023-06-02 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 --- Comment #34 from Pedro Amorim --- Nice work everyone! Pushed to 22.11.x for next release -- You are receiving this mail because: You are watching all bug changes. ___ Koha-bugs maili

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2023-06-02 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 Pedro Amorim changed: What|Removed |Added Version(s)|23.05.00|23.05.00,22.11.07 rel

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2023-05-15 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 --- Comment #33 from Tomás Cohen Arazi --- Pushed to master for 23.05. Nice work everyone, thanks! -- You are receiving this mail because: You are watching all bug changes. ___ Koha-bugs

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2023-05-15 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 Tomás Cohen Arazi changed: What|Removed |Added Version(s)||23.05.00 release

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2023-01-19 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 Martin Renvoize changed: What|Removed |Added Severity|enhancement |normal -- You are receiv

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2022-11-29 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 --- Comment #32 from Kyle M Hall --- (In reply to Jonathan Druart from comment #28) > I don't know how this is relevant, but borrowers.secret is MEDIUMTEXT and > you are using VARCHAR(256) here. > > By the way, 256? Typo for 255? I

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2022-11-29 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 --- Comment #31 from Kyle M Hall --- Created attachment 144325 --> https://bugs.koha-community.org/bugzilla3/attachment.cgi?id=144325&action=edit Bug 30649: (QA follow-up) Switch password field to mediumtext -- You are receiving

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2022-11-29 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 Kyle M Hall changed: What|Removed |Added Attachment #144323|0 |1 is obsolete|

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2022-11-29 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 Kyle M Hall changed: What|Removed |Added Attachment #142989|0 |1 is obsolete|

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2022-11-29 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 Jonathan Druart changed: What|Removed |Added CC||jonathan.druart+koha@gmail

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2022-11-26 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 --- Comment #27 from Victor Grousset/tuxayo --- (In reply to Kyle M Hall from comment #22) > (In reply to Victor Grousset/tuxayo from comment #21) > > That's why I wondered if there was any gain compared to just storing the > > passw

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2022-11-13 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 Katrin Fischer changed: What|Removed |Added Version|21.05 |master -- You are receivi

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2022-11-09 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 --- Comment #26 from David Cook --- (In reply to Katrin Fischer from comment #25) > (In reply to David Cook from comment #24) > > (In reply to Katrin Fischer from comment #23) > > > It might also hinder a a quick desaster recovery to

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2022-11-09 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 --- Comment #25 from Katrin Fischer --- (In reply to David Cook from comment #24) > (In reply to Katrin Fischer from comment #23) > > It might also hinder a a quick desaster recovery to a different server? At > > least something more

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2022-11-09 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 --- Comment #24 from David Cook --- (In reply to Katrin Fischer from comment #23) > It might also hinder a a quick desaster recovery to a different server? At > least something more to think about for backups etc. With the encryptio

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2022-11-09 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 --- Comment #23 from Katrin Fischer --- It might also hinder a a quick desaster recovery to a different server? At least something more to think about for backups etc. -- You are receiving this mail because: You are watching all bu

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2022-11-07 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 --- Comment #22 from Kyle M Hall --- (In reply to Victor Grousset/tuxayo from comment #21) > That's why I wondered if there was any gain compared to just storing the > passwords into koha-conf.xml directly? (or another file) Simply

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2022-11-06 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 --- Comment #21 from Victor Grousset/tuxayo --- (In reply to Martin Renvoize from comment #16) > The value does come from the encryption. If the database is somehow > compromised (for example, someone accidentally shares a backup..

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2022-11-02 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 --- Comment #20 from David Cook --- (In reply to Martin Renvoize from comment #18) > OK.. I decided to open another bug for my thoughts on key change.. > > I'll pass this one but highlight to the RM that we may need to rethink the >

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2022-11-02 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 --- Comment #19 from David Cook --- (In reply to Martin Renvoize from comment #17) > When we upgraded > from SHA to BCrypt for user account hashing we added a layer inside the > codebase to upgrade the hash on first access I seem to

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2022-11-02 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 Martin Renvoize changed: What|Removed |Added Status|Signed Off |Passed QA -- You are rec

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2022-11-02 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 --- Comment #18 from Martin Renvoize --- OK.. I decided to open another bug for my thoughts on key change.. I'll pass this one but highlight to the RM that we may need to rethink the DB update. -- You are receiving this mail becau

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2022-11-02 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 Martin Renvoize changed: What|Removed |Added See Also||https://bugs.koha-communit

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2022-11-02 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 --- Comment #17 from Martin Renvoize --- Still contemplating QA here.. the code works as expected and I'm happy with the implementation as a whole. However.. I'm not so sure about the in place database upgrade... we tend to try and

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2022-11-02 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 --- Comment #16 from Martin Renvoize --- (In reply to Victor Grousset/tuxayo from comment #14) > (In reply to Kyle M Hall from comment #9) > > (In reply to Victor Grousset/tuxayo from comment #8) > > > I don't get how to encrypt a pa

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2022-11-02 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 Martin Renvoize changed: What|Removed |Added QA Contact|testo...@bugs.koha-communit |martin.renvoize@ptfs-europ

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2022-11-02 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 Martin Renvoize changed: What|Removed |Added Attachment #142820|0 |1 is obsolete|

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2022-10-31 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 --- Comment #14 from Victor Grousset/tuxayo --- (In reply to Kyle M Hall from comment #9) > (In reply to Victor Grousset/tuxayo from comment #8) > > I don't get how to encrypt a password to an external service and still be > > able t

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2022-10-30 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 David Nind changed: What|Removed |Added CC||da...@davidnind.com --- Commen

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2022-10-30 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 David Nind changed: What|Removed |Added Attachment #142057|0 |1 is obsolete|

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2022-10-30 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 David Nind changed: What|Removed |Added Status|Needs Signoff |Signed Off -- You are receivi

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2022-10-18 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 Kyle M Hall changed: What|Removed |Added CC||martin.renvoize@ptfs-europe

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2022-10-18 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 Kyle M Hall changed: What|Removed |Added Attachment #142056|0 |1 is obsolete|

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2022-10-18 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 Kyle M Hall changed: What|Removed |Added Attachment #134302|0 |1 is obsolete|

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2022-10-18 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 Kyle M Hall changed: What|Removed |Added Status|BLOCKED |Needs Signoff -- You are rec

[Koha-bugs] [Bug 30649] Vendor EDI account passwords should be encrypted in the database

2022-10-18 Thread bugzilla-daemon
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=30649 Kyle M Hall changed: What|Removed |Added Summary|Vendor EDI account |Vendor EDI account