[jira] [Created] (OFBIZ-11586) Few tests don't pass when using CsrfDefenseStrategy

2020-04-05 Thread Jacques Le Roux (Jira)
Jacques Le Roux created OFBIZ-11586: --- Summary: Few tests don't pass when using CsrfDefenseStrategy Key: OFBIZ-11586 URL: https://issues.apache.org/jira/browse/OFBIZ-11586 Project: OFBiz Iss

[jira] [Closed] (OFBIZ-11475) AjaxAutocompleteOptions should be able to decode return values

2020-04-05 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11475?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jacques Le Roux closed OFBIZ-11475. --- Fix Version/s: 17.12.02 18.12.01 Resolution: Implemented > AjaxAut

[jira] [Commented] (OFBIZ-11475) AjaxAutocompleteOptions should be able to decode return values

2020-04-05 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11475?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17075809#comment-17075809 ] ASF subversion and git services commented on OFBIZ-11475: - Commi

[jira] [Commented] (OFBIZ-11475) AjaxAutocompleteOptions should be able to decode return values

2020-04-05 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11475?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17075808#comment-17075808 ] ASF subversion and git services commented on OFBIZ-11475: - Commi

[jira] [Created] (OFBIZ-11585) Update security.adoc with few words about our CSRF defense strategy

2020-04-05 Thread Jacques Le Roux (Jira)
Jacques Le Roux created OFBIZ-11585: --- Summary: Update security.adoc with few words about our CSRF defense strategy Key: OFBIZ-11585 URL: https://issues.apache.org/jira/browse/OFBIZ-11585 Project: OF

[jira] [Closed] (OFBIZ-11317) Add 'controlPath' attribute to 'ofbizUrl' freemarker macro

2020-04-05 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11317?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jacques Le Roux closed OFBIZ-11317. --- Resolution: Implemented Since OFBIZ-11306 will not be backported no real need to backport he

[jira] [Closed] (OFBIZ-11306) POC for CSRF Token (CVE-2019-12425)

2020-04-05 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jacques Le Roux closed OFBIZ-11306. --- Resolution: Implemented Thanks James! > POC for CSRF Token (CVE-2019-12425) > -

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token (CVE-2019-12425)

2020-04-05 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17075765#comment-17075765 ] ASF subversion and git services commented on OFBIZ-11306: - Commi

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token (CVE-2019-12425)

2020-04-05 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17075769#comment-17075769 ] ASF subversion and git services commented on OFBIZ-11306: - Commi

[jira] [Closed] (OFBIZ-11583) Prevent Host Header Injection (CVE-2019-12425)

2020-04-05 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11583?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jacques Le Roux closed OFBIZ-11583. --- Fix Version/s: 17.12.02 18.12.01 Resolution: Fixed > Prevent Host

[jira] [Commented] (OFBIZ-11583) Prevent Host Header Injection (CVE-2019-12425)

2020-04-05 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11583?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17075767#comment-17075767 ] ASF subversion and git services commented on OFBIZ-11583: - Commi

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token (CVE-2019-12425)

2020-04-05 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17075768#comment-17075768 ] ASF subversion and git services commented on OFBIZ-11306: - Commi

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token (CVE-2019-12425)

2020-04-05 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17075766#comment-17075766 ] ASF subversion and git services commented on OFBIZ-11306: - Commi

[jira] [Commented] (OFBIZ-11583) Prevent Host Header Injection (CVE-2019-12425)

2020-04-05 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11583?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17075770#comment-17075770 ] ASF subversion and git services commented on OFBIZ-11583: - Commi

[jira] [Commented] (OFBIZ-11583) Prevent Host Header Injection (CVE-2019-12425)

2020-04-05 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11583?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17075762#comment-17075762 ] ASF subversion and git services commented on OFBIZ-11583: - Commi

[jira] [Commented] (OFBIZ-11306) POC for CSRF Token (CVE-2019-12425)

2020-04-05 Thread ASF subversion and git services (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17075763#comment-17075763 ] ASF subversion and git services commented on OFBIZ-11306: - Commi

[jira] [Closed] (OFBIZ-11425) Test "POC for CSRF Token" (CVE-2019-12425)

2020-04-05 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11425?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jacques Le Roux closed OFBIZ-11425. --- Resolution: Fixed > Test "POC for CSRF Token" (CVE-2019-12425) > ---

[jira] [Closed] (OFBIZ-11195) XML Entity Injection in webtools/control/entityImport

2020-04-05 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11195?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jacques Le Roux closed OFBIZ-11195. --- Fix Version/s: 17.12.02 18.12.01 Assignee: Jacques Le Roux

[jira] [Updated] (OFBIZ-11306) POC for CSRF Token (CVE-2019-12425)

2020-04-05 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11306?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jacques Le Roux updated OFBIZ-11306: Summary: POC for CSRF Token (CVE-2019-12425) (was: POC for CSRF Token) > POC for CSRF Tok

[jira] [Updated] (OFBIZ-10427) Add a mean to handle CSRF (CVE-2019-12425)

2020-04-05 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-10427?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jacques Le Roux updated OFBIZ-10427: Summary: Add a mean to handle CSRF (CVE-2019-12425) (was: Add a mean to handle CSRF) > A

[jira] [Updated] (OFBIZ-11425) Test "POC for CSRF Token" (CVE-2019-12425)

2020-04-05 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11425?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jacques Le Roux updated OFBIZ-11425: Summary: Test "POC for CSRF Token" (CVE-2019-12425) (was: Test "POC for CSRF Token") > T

[GitHub] [ofbiz-framework] sonarcloud[bot] commented on issue #64: Improved: descriptions of temporal expression records (OFBIZ-11584)

2020-04-05 Thread GitBox
sonarcloud[bot] commented on issue #64: Improved: descriptions of temporal expression records (OFBIZ-11584) URL: https://github.com/apache/ofbiz-framework/pull/64#issuecomment-609384660 Kudos, SonarCloud Quality Gate passed! [](https://sonarcloud.io/project/issues?id=apache_ofbiz-fra

[jira] [Closed] (OFBIZ-11197) Arbitrary Code Execution

2020-04-05 Thread Jacques Le Roux (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11197?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Jacques Le Roux closed OFBIZ-11197. --- Fix Version/s: 17.12.02 18.12.01 Assignee: Jacques Le Roux

[GitHub] [ofbiz-framework] PierreSmits opened a new pull request #64: Improved: descriptions of temporal expression records (OFBIZ-11584)

2020-04-05 Thread GitBox
PierreSmits opened a new pull request #64: Improved: descriptions of temporal expression records (OFBIZ-11584) URL: https://github.com/apache/ofbiz-framework/pull/64 (OFBIZ-11584) This is an automated message from the Apache

[jira] [Updated] (OFBIZ-11584) Improving description of temporal expression

2020-04-05 Thread Pierre Smits (Jira)
[ https://issues.apache.org/jira/browse/OFBIZ-11584?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Pierre Smits updated OFBIZ-11584: - Component/s: framework/service > Improving description of temporal expression >

[jira] [Created] (OFBIZ-11584) Improving description of temporal expression

2020-04-05 Thread Pierre Smits (Jira)
Pierre Smits created OFBIZ-11584: Summary: Improving description of temporal expression Key: OFBIZ-11584 URL: https://issues.apache.org/jira/browse/OFBIZ-11584 Project: OFBiz Issue Type: Impr