Re: [QGIS-Developer] Image in a Attribute table.

2020-02-02 Thread Denis Rouzaud
Hi Kyle, The best place to post this is on the issue tracker where you'll be able to paste both the code snippet and the project data. That keeps everything in a single place and avoid the need for devs to redo the project. https://github.com/qgis/QGIS/issues Many thanks for the report, Kind rega

[QGIS-Developer] Image in a Attribute table.

2020-02-02 Thread Kyle Felipe Vieira Roberto
Hi guys! I want to show a image in a custom form, the image is inside a BLOB field. I wrote a python function to do that, but when i open the attribute table, qgis issues a message (inconplete) [image: image.png] So, i made this gitlab snippet with a project and the python code. https://gitlab.c

Re: [QGIS-Developer] Potential vulnerabilities

2020-02-02 Thread nadiaspit
Hi Jonathan, this is a good idea and also a good proposal for the students of next edition of Master in Cybersecurity. I will tell to my professor. Thank you Nadia -- Sent from: http://osgeo-org.1560.x6.nabble.com/QGIS-Developer-f4099106.html ___ QG

Re: [QGIS-Developer] Please help with the changelog for 3.12

2020-02-02 Thread Nyall Dawson
On Sun, 2 Feb 2020 at 08:10, Tim Sutton wrote: > > Hi All > > QGIS 3.12 will be released in 19 days and our changelog needs a lot of love > before that. If you are able to, please spend some time documenting new > features and key improvements in the changelog. > > https://changelog.qgis.org/en/

Re: [QGIS-Developer] Potential vulnerabilities

2020-02-02 Thread Jonathan Moules
Hi Nadia, Just a random thought here, but I wonder if doing this exercise against QGIS Desktop would be more worthwhile from a security perspective? There are very few deployments of QGIS-Server but many many deployments of Desktop. For example, is it possible to compromise QGIS Desktop via a

Re: [QGIS-Developer] Good news: next Ubuntu version shipping with gdal3/proj6

2020-02-02 Thread Tim Sutton
Hi Ah cool - thanks for the heads up! Regards Tim > On 2 Feb 2020, at 08:52, Mathieu Pellerin wrote: > > Here's a nice Sunday news: Ubuntu 20.04 (ETA end of April) will ship with > gdal 3 (at the moment 3.0.3, hopefully will be 3.0.4 by release day to fix a > nasty bug) and proj 6.3. > > T

Re: [QGIS-Developer] Potential vulnerabilities

2020-02-02 Thread nadiaspit
Hi Even, thank you so much for answering my questions. Of course my assessment is far beyond automating scanning for vulnerability. I just wrote about 1 potential issue. As I said at the beginning, this is about my Project Work as student of Master of Cybersecurity in Pisa, Italy. I really apprec

Re: [QGIS-Developer] Potential vulnerabilities

2020-02-02 Thread Paolo Cavallini
Hi Evevn, thanks for the review. To be fair, original report from Nadia was indeed against Lizmap. Cheers. Il 02/02/20 18:12, Even Rouault ha scritto: > Nadia, > > Thanks for investigating QGIS server security. However, I would expect a > vulnerability report to go a bit beyond than just using a

Re: [QGIS-Developer] Potential vulnerabilities

2020-02-02 Thread Even Rouault
Nadia, Thanks for investigating QGIS server security. However, I would expect a vulnerability report to go a bit beyond than just using a generic security scanner that can have false positives, especially here as all components involved are open source so it is possible to look at the code, instru

Re: [QGIS-Developer] Potential vulnerabilities

2020-02-02 Thread Jonathan Moules
Hi Jorge, I don't run QGIS server, I was basing that on the original report by Nadia to the list which shows a 500 response for that request to their box. But yes, testing that URL against some (ostensibly) QGIS servers I can find online, it does seem to work as expected. Not sure why Nadia got

[QGIS-Developer] Good news: next Ubuntu version shipping with gdal3/proj6

2020-02-02 Thread Mathieu Pellerin
Here's a nice Sunday news: Ubuntu 20.04 (ETA end of April) will ship with gdal 3 (at the moment 3.0.3, hopefully will be 3.0.4 by release day to fix a nasty bug) and proj 6.3. This can likely increase the number of QGIS core devs using this next gen pair of libraries, which would undeniably help t