Re: A new tool for OFBIZ translation using OpenAI platform

2024-10-31 Thread Jacques Le Roux
Hi Omer No need to be sorry, a reminder is always welcome :) Thanks for your work and sharing. For those interested it's already in wiki: https://lists.apache.org/thread/d7y4bln6yzqk4cgyd18horhcp3c036qj I have just changed https://cwiki.apache.org/confluence/pages/viewpage.action?pageId=1995333

Re: What is the difference between Agreement and Term

2024-10-30 Thread Jacques Le Roux
https://www.google.fr/search?q=What+is+the+difference+between+Agreement+and+Term&ie=UTF-8 Le 27/10/2024 à 12:44, Emad Radwan a écrit : Hello Community, Would you please shed some light on this? Regards, Emad

Re: Convert Quote to Order

2024-10-27 Thread Jacques Le Roux
Create a quote, modify it by accepting it, create an order from there Le 27/10/2024 à 08:57, Emad Radwan a écrit : Thanks Jacques, but the page is empty! Regards, Emad On Sat, Oct 26, 2024 at 5:46 PM Jacques Le Roux < jacques.le.r...@les7arts.com> wrote: https://cwiki.apache.org/conf

Re: Convert Quote to Order

2024-10-26 Thread Jacques Le Roux
https://cwiki.apache.org/confluence/display/OFBIZ/Create+Sales+Order+from+Quote Le 26/10/2024 à 13:09, Emad Radwan a écrit : Hello Community, Do we have this functionality? Regards, Emad

Re: Stocktaking?

2024-10-26 Thread Jacques Le Roux
Hi Klaus, In OFBiz the term used for Stocktaking is  inventory adjustment You may find some information in this page: https://cwiki.apache.org/confluence/display/OFBIZ/Order+Fulfillment+Process+Overview BTW, thanks to Priya for this remarquable effort.

Re: Ofbiz 18 - "no Dispatcher found" issue

2024-10-16 Thread Jacques Le Roux
har a écrit : Hi Jacques, I am unable to login to JIRA with my ID. Could you please provide me with my user-name and a link to reset my password? I am subscribed to the mailing list with this email ID: mayankea...@yahoo.com . Thanks, Mayank On Monday 14 October 2024 at 23:05:12 GMT+5:30, Jacqu

Re: attempting to join mailing lists

2024-10-12 Thread Jacques Le Roux
Hi Nathan, Your message has been moderated, else it would not have reached this Mailing List. Please subscribe to the user ML for such questions and then use your email client. See why here http://ofbiz.apache.org/mailing-lists.html. You will get a better support, people can answer you on the

Re: training

2024-10-04 Thread Jacques Le Roux
Hi Suchet, This could be helpful to start https://cwiki.apache.org/confluence/display/OFBIZ/Framework+Introduction+Videos+and+Diagrams Jacques Le 04/10/2024 à 18:49, suchet jain a écrit : Hi Community, I am looking for functional training of OFBiz modules. Any pointers would be appreciated --

Re: cache.properties

2024-10-03 Thread Jacques Le Roux
Hi Vikas, All the information is inside the file itself. If you need more read https://cwiki.apache.org/confluence/display/OFBIZ/Framework+Configuration+Guide#FrameworkConfigurationGuide-cache.properties https://cwiki.apache.org/confluence/pages/viewpage.action?pageId=7045138#ApacheOFBizTechnic

Re: Manufacturing - Dependent. Production Runs

2024-09-26 Thread Jacques Le Roux
Hi Emad, As a start, have you read https://cwiki.apache.org/confluence/display/OFBIZ/Running+and+Debugging+OFBiz+in+Eclipse or https://cwiki.apache.org/confluence/display/OFBIZ/Running+and+Debugging+OFBiz+in+Intellij+IDEA ? HTH Jacques Le 26/09/2024 à 13:00, Emad Radwan a écrit : Hello Omar,

Re: Proposal: Move towards developer friendly Ofbiz

2024-09-18 Thread Jacques Le Roux
Hi Groza, Inline... Le 18/09/2024 à 15:55, Groza Danut a écrit : Hi all, My proposal comes from my personal observations so far. I believe currently the 'customer' of the Ofbiz Project should be the developer, not the end user. I say this because of the following reasons: This is what someho

Re: GeoAssoc id and idTo

2024-09-10 Thread Jacques Le Roux
Hi Groza, Good quesiton, it's rather GeoAssoc definitions that are reversed. This was done 13 years ago by https://svn.apache.org/viewvc?view=revision&revision=1162940 (text changed

Re: 回复:Re: 回复:Re: 回复:Re: ofibz causes system extremely slow after one night

2024-09-08 Thread Jacques Le Roux
Protocols add domain framework/security/config/security.properties host-headers-allowed add domain framework/base/config/cache.properties rm as the comment is 1 core 2 GB memeroy os sufficient? I rarely operate the website and just let it stay there... Regards, Yang 原始邮件 发件人:"Jacqu

Re: 回复:Re: ofibz causes system extremely slow after one night

2024-09-04 Thread Jacques Le Roux
an proceed like this? Regards, Yang 原始邮件 发件人:"Jacques Le Roux"< jacques.le.r...@les7arts.com >; 发件时间:2024/9/4 14:36 收件人:"dev"< d...@ofbiz.apache.org >; 主题:Re: ofibz causes system extre

Re: What is the status of the BIRT plugin?

2024-09-03 Thread Jacques Le Roux
Hi Groza, I suggest to have a look at: https://lists.apache.org/list?user@ofbiz.apache.org:gte=1d:birt%20plugin https://lists.apache.org/list?user@ofbiz.apache.org:gte=1d:birt%20security Summary: as long as you don't create reports yourself there is no problems with Birt in OFBiz as it's OOTB s

CVE-2024-45507: Apache OFBiz: Prevent use of URLs in files when loading them from Java or Groovy, leading to a RCE

2024-09-03 Thread Jacques Le Roux
Severity: important Affected versions: - Apache OFBiz before 18.12.16 Description: Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade t

CVE-2024-45195: Apache OFBiz: Confused controller-view authorization logic (forced browsing)

2024-09-03 Thread Jacques Le Roux
Severity: important Affected versions: - Apache OFBiz before 18.12.16 Description: Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue. Credit: shin24

Re: 回复:unauthorized SSRF and RCE vulnerability for Apache OFBiz under 18.12.16

2024-09-02 Thread Jacques Le Roux
Sure thing, thanks for the feedback Le 02/09/2024 à 09:17, sunxiang0...@163.com a écrit : it's ok,credit just 孙相(Sun Xiang) 发自我的手机 原始邮件 发件人: Jacques Le Roux 日期: 2024年9月2日周一 下午2:51 收件人: secur...@ofbiz.apache.org, 孙相,0386 主 题: Re: unauthorized SSRF an

Re: 回复: 回复:Re: want to be apache contributor

2024-09-01 Thread Jacques Le Roux
ement committee privately atpriv...@ofbiz.apache.org. If the project is still unable to respond, you can then escalate the matter to the ASF Infrastructure team atus...@infra.apache.org > > > > > Regards, > Yang > > > > > > >     > 原始

Re: Attribute 'auth' is not allowed to appear in element 'view-map' for ecommerce plugin

2024-09-01 Thread Jacques Le Roux
Hi Yang, I'm not quite sure why you get that. It's not a big deal, has no other effects than this information in log. It's due to inconsistency with your code and http://ofbiz.apache.org/dtds/site-conf.xsd As you can see, it has been changed last week: https://github.com/apache/ofbiz-site/bl

Re: 回复:Re: want to be apache contributor

2024-09-01 Thread Jacques Le Roux
the project is still unable to respond, you can then escalate the matter to the ASF Infrastructure team atus...@infra.apache.org Regards, Yang 原始邮件 发件人:"Jacques Le Roux"https://issues.apache.org/jira/brows

Re: want to be apache contributor

2024-08-31 Thread Jacques Le Roux
Here is the solution: https://issues.apache.org/jira/browse/INFRA-26082 Le 31/08/2024 à 16:09, Jacques Le Roux a écrit : Wait Yang, All documentation is useful ;) The problem is to maintained it... Le 31/08/2024 à 16:01, 雷咩咩 a écrit : hi Jacques, I had created account in atlassian and can

Re: 回复:URL Issue

2024-08-31 Thread Jacques Le Roux
1:42 +0300] "GET /rainbowstone/RAINBOWSTONE_SAPHIR.less HTTP/2.0" 200 1560 " https://localhost:8443/facility/control/FindFacility"; "Mozilla/5.0 (X11; Linux x86_64; rv:129.0) Gecko/20100101 Firefox/129.0" 127.0.0.1 - - [26/Aug/2024:20:51:42 +0300] "GET /facility/contr

Re: want to be apache contributor

2024-08-31 Thread Jacques Le Roux
ards, Yang Original Email From:"Jacques Le Roux"< jacques.le.r...@les7arts.com >; Sent Time:2024/8/31 21:35 To:"雷咩咩"< 675686...@qq.com >;"user@ofbiz.apache.org"< user@ofbiz.ap

Re: want to be apache contributor

2024-08-31 Thread Jacques Le Roux
h Infra (things change quickly) Jacques Le 31/08/2024 à 10:13, Jacques Le Roux a écrit : Hi Yang, You need to create a Confluence account (Jira ans Confluence are separated) with one email that works there (maybe .invalid will not) and tell us the Confluence Id you choose (the email is easier

Re: 回复:URL Issue

2024-08-31 Thread Jacques Le Roux
27.0.0.1 - - [26/Aug/2024:20:51:42 +0300] "GET /facility/control/FindFacility HTTP/2.0" 200 4274 " https://localhost:8443/facility/control/main?externalLoginKey=ELf5b96d38-f415-4bdf-94d4-7666a2445a03"; "Mozilla/5.0 (X11; Linux x86_64; rv:129.0) Gecko/20100101 Firefox/129.0&

Re: 回复:URL Issue

2024-08-31 Thread Jacques Le Roux
rol/WebAppServletContextListener.java#L41>) It seems to be that this listener is never registered , so that it has no effect. Note that its annotated with @WebListener So confirm that I am correct, or wrong. Regards On Fri, Aug 30, 2024 at 6:30 PM Jacques Le Roux < jacques.le.r...@les7arts.com> wrote: H

Re: want to be apache contributor

2024-08-31 Thread Jacques Le Roux
Hi Yang, You need to create a Confluence account (Jira ans Confluence are separated) with one email that works there (maybe .invalid will not) and tell us the Confluence Id you choose (the email is easier I guess, but that's up to you) Something has changed (temporarily I hope) in Confluence,

Re: 回复:URL Issue

2024-08-30 Thread Jacques Le Roux
e reason yet. If you could confirm that it's not reproductible but in demo server that would help to restrain the possibilities TIA Jacques Le 29/08/2024 à 10:17, Jacques Le Roux a écrit : Hi, Finally it's not that clear. As can be found in trunk demo access_logs, such URLs exist at least

Re: 回复:Re: 回复: configured jks certificate but browser said insecure

2024-08-29 Thread Jacques Le Roux
ang 原始邮件 发件人:"Jacques Le Roux"< jacques.le.r...@les7arts.com >; 发件时间:2024/8/29 22:24 收件人:"user"< user@ofbiz.apache.org >; 主题:Re: 回复: configured jks certificate but browser said insecure

Re: Product configuration

2024-08-29 Thread Jacques Le Roux
e don't have product information(how many sqm per box there are for this model) so I cannot directly convert between sqm to box using just the conversion factor. Groza Danut On Wed, Aug 28, 2024 at 4:59 PM Jacques Le Roux < jacques.le.r...@les7arts.com> wrote: Hi Groza, Have you been ab

Re: 回复: configured jks certificate but browser said insecure

2024-08-29 Thread Jacques Le Roux
Original Email From:"Jacques Le Roux"https://cwiki.apache.org/confluence/display/OFBIZ/Apache+OFBiz+Contributors Jacques Le 29/08/2024 à 03:22, 雷咩咩 a écrit : > I think I can add my steps to set it up in the confluence wiki, if you'd > like Apache

Re: 回复:URL Issue

2024-08-29 Thread Jacques Le Roux
"Prevent special encoded characters sequences in URLs" So we need to clearly define steps to manually generate these URLs. Then, if it's OK, we could allow URLs containing ";jsessionid=" to bypass the security filter. I copy this email to the dev ML because of its impo

Re: 回复: configured jks certificate but browser said insecure

2024-08-28 Thread Jacques Le Roux
Hi Yang, Yes please, are you already a Confluence contributor? https://cwiki.apache.org/confluence/display/OFBIZ/Apache+OFBiz+Contributors Jacques Le 29/08/2024 à 03:22, 雷咩咩 a écrit : I think I can add my steps to set it up in the confluence wiki, if you'd like Apache OFBiz Technical Produc

Re: configured jks certificate but browser said insecure

2024-08-28 Thread Jacques Le Roux
Hi Yang, You should have a look at https://letsencrypt.org/zh-cn/ HTH Jacques Le 28/08/2024 à 17:30, 雷咩咩 a écrit : hi ofbiz users, I've successfully started ofbiz and reverse proxied by nginx, can visit by https://leiyang.icu/accounting/control/login. However, as I also have other websi

Re: First pull request

2024-08-28 Thread Jacques Le Roux
Hi, You should be able to get to this link without any specific privileges. Jacques Le 26/08/2024 à 16:26, 雷咩咩 a écrit : Hi I'm new user too but seems you missed the link?  https://github.com/apache/ofbiz-plugins/pull/127/commits/9186a4527300cbc8bd4e6b76325925e0b52b62b8 and maybe need add d

Re: Contribution to ecommerce labels

2024-08-28 Thread Jacques Le Roux
Hi Tomislav, I have added a note about your tool in https://cwiki.apache.org/confluence/display/OFBIZ/Text+Translation https://cwiki.apache.org/confluence/pages/viewpage.action?pageId=199533364 Thanks ! Jacques Le 22/08/2024 à 08:46, Jacques Le Roux a écrit : Hi Tomislav, Thanks so much, I

Re: Product configuration

2024-08-28 Thread Jacques Le Roux
Hi Groza, Have you been able to find the solution by your one? There is some related discussions in user ML. Jacques Le 11/08/2024 à 09:29, Groza Danut a écrit : Hello all, Sorry if this is a too basic question, but I have a product configuration I don't know how to model in Ofbiz. I have a

Re: 回复:URL Issue

2024-08-28 Thread Jacques Le Roux
Thanks Guys, I could not reproduce yet, but I think we have already enough clues to fix that. Also I can find a lot of in trunk demo log. That will be helpful too. Jacques Le 27/08/2024 à 16:20, 雷咩咩 a écrit : i can reproduce by login with admin, randomly click severl places, then when click l

Re: Want to register as Contributor

2024-08-27 Thread Jacques Le Roux
Hi Srinivas, Your message has been moderated, else it would not have reached this Mailing List. Please subscribe to the user ML and then use your email client. See why here http://ofbiz.apache.org/mailing-lists.html. You will get a better support, people can answer you on the ML. The wider the

Re: First pull request

2024-08-27 Thread Jacques Le Roux
Hi Groza, Thanks for your contribution. I just pushed it after checking that the form what OK (I can't really verify Romanian but translated 2 or 3 long sentences ;) We did not receive confirmation for documentation contribution from Tomislav but as it does not need an ICLA I'll put itin documen

Re: how to enable login account

2024-08-25 Thread Jacques Le Roux
nk? Original Email From:"Jacques Le Roux"< jacques.le.r...@les7arts.com >; Sent Time:2024/8/25 18:09 To:"675686066"< 675686...@qq.com >; Subject:Re: how to enable login account Hi 雷咩咩, You must have made a wrong association between demoCustomer and his securi

Re: how to enable login account

2024-08-25 Thread Jacques Le Roux
Hi 雷咩咩, You must have made a wrong association between demoCustomer and his security group Jacques Le 25/08/2024 à 03:05, 雷咩咩 a écrit : but then by the democustomer account i can modify the login password of admin. how can that be? anyone can explain? currently the democustomer password is 'p

Re: Contribution to ecommerce labels

2024-08-21 Thread Jacques Le Roux
Hi Tomislav, Thanks so much, I was not aware of this tools. Would you mind putting this information in OFBiz documentation? TIA Jacques Le 21/08/2024 à 17:58, Tomislav Preksavec a écrit : Hi Groza, actually I made a tool for OfBiz labels translation a few years ago. It's a python3 script, i

Re: 回复: gradle build fail due to npm timeout

2024-08-13 Thread Jacques Le Roux
Thanks too, Indeed, I'll add this information Le 13/08/2024 à 13:14, 雷咩咩 a écrit : thanks for reply. i'm using truck version. And I think regarding how to build truck version, the tutorial you provided doesn't have significant difference from that I mentioned(https://ofbiz.apache.org/develope

Re: gradle build fail due to npm timeout

2024-08-13 Thread Jacques Le Roux
Hi, Not sure it's of much help, but it may also depends on the OFBiz version your are using trunk : follow https://nightlies.apache.org/ofbiz/trunk/readme/html5/README.html (Gradle 7.6) 18.12.15: follow https://nightlies.apache.org/ofbiz/stable/readme/html5/README.html (Gradle gradle-5.0-rc-5

Re: apache-ofbiz-18.12.14 with PostgreSQL db .

2024-08-05 Thread Jacques Le Roux
Was related to Docker, answered by Daniel at https://issues.apache.org/jira/browse/OFBIZ-13129 Jacques Le 01/08/2024 à 16:12, Sameer Alwosaby a écrit : The issues start in SecurityPermissionSeedData.xml file , we try many time to solve 2024-08-01 17:00:49,311 |main |E

CVE-2024-38856: Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code

2024-08-04 Thread Jacques Le Roux
Severity: important Affected versions: - Apache OFBiz through 18.12.14 Description: Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the issue. Unauthenticated endpoints

Re: Problem installing/enabling birt plugin

2024-07-25 Thread Jacques Le Roux
I did as you suggested and loaded the demo data. I no longer get the error message and the BIRT option is in the main menu. I will continue to explore this as I am really trying to move towards a real production build with no demo data. Thanks for your reply. -Original Message

Re: Job Run Scheduling

2024-07-23 Thread Jacques Le Roux
Hi Emad, What is the new status after pushing the "Schedule" button, none? Jacques Le 06/07/2024 à 18:03, Emad Radwan a écrit : Hello Community, After creating a production run a button with 'Schedule' is available. I have noticed that it only stamps the relevant records in WorkEffort entity

Re: Problem installing/enabling birt plugin

2024-07-19 Thread Jacques Le Roux
Hi Jeff, I'll not ask if you use the last 18.12 release (18.12.14) or the trunk (22.01 is unofficially //abandoned). They are very similar (almost same). I just did a fast try with the trunk version that I have available under framework both from their respective repos. Just after making the

Re: Error with executeMRP service

2024-07-03 Thread Jacques Le Roux
According to Infra, it turned out that your Jira username is emad1967 not eradwan1967, try again... Le 03/07/2024 à 15:38, Emad Radwan a écrit : Hi. The provided password didn't work and I notified the gentleman from jira. On Wed, 3 Jul 2024, 3:32 pm Jacques Le Roux, wrote: Hi Emad,

Re: Error with executeMRP service

2024-07-03 Thread Jacques Le Roux
Hi Emad, Still there? TIA Jacques Le 02/07/2024 à 18:48, Jacques Le Roux a écrit : You should have received a new password. Let me know if all is now OK with you. TIA Le 02/07/2024 à 13:44, Jacques Le Roux a écrit : I'll ask Infra team about that... Le 02/07/2024 à 12:34, Emad Rad

Re: Error with executeMRP service

2024-07-02 Thread Jacques Le Roux
You should have received a new password. Let me know if all is now OK with you. TIA Le 02/07/2024 à 13:44, Jacques Le Roux a écrit : I'll ask Infra team about that... Le 02/07/2024 à 12:34, Emad Radwan a écrit : This is what i'm saying, the site responds if you request username b

Re: Error with executeMRP service

2024-07-02 Thread Jacques Le Roux
I'll ask Infra team about that... Le 02/07/2024 à 12:34, Emad Radwan a écrit : This is what i'm saying, the site responds if you request username but not for password!! Sorry, for my ignorance but I don't have a Jira administrator!! On Tue, Jul 2, 2024 at 1:29 PM Jacques

Re: ReST support

2024-07-02 Thread Jacques Le Roux
Hi San, The 22.01 version has been unofficially abandoned because we want to create a new 24.xx branch with some work to be completed, for now: https://cwiki.apache.org/confluence/display/OFBIZ/Release+24.xx+Roadmap If you really need REST, I'd rather use the trunk and when possible "update" (t

Re: Error with executeMRP service

2024-07-02 Thread Jacques Le Roux
/07/2024 à 12:24, Jacques Le Roux a écrit : Hi Emad, I just tried for you and got this answer:    Your username has been sent to you via email.    You can then request a new password with that usernamehere <https://issues.apache.org/jira/secure/ForgotLoginDetails.jspa>.    If the emai

Re: Error with executeMRP service

2024-07-02 Thread Jacques Le Roux
forget username they reply but for password I didn't get it although having tried many times. Can you help with this, please? https://issues.apache.org/jira/secure/ForgotLoginDetails.jspa Username: eradwan1967 Regards, Emad On Mon, May 27, 2024 at 1:07 PM Jacques Le Roux < jacques.le.r

Re: Inquiry Regarding UI Changes for [ofbiz-framework + ofbiz-plugins]

2024-06-28 Thread Jacques Le Roux
écrit : Hello Mr. Jacques Le Roux, My name is Steve Mamendja, and I am a fifth-year software engineering student. As part of my final year project, I have chosen the Apache OFBiz project. After several attempts, I have tried to modify the user interface of the 'party' module, but unfor

Re: The number of threads used to run services in async mode

2024-06-25 Thread Jacques Le Roux
Hi Tomek, If you did not already, I'd look at: https://cwiki.apache.org/confluence/display/OFBIZ/Service+Engine+Guide https://cwiki.apache.org/confluence/display/OFBIZ/Service+Engine+Configuration+Guide https://github.com/apache/ofbiz-framework/blob/trunk/framework/service/dtd/service-config.xs

Re: Owasp dependencycheck task is not getting build successfully

2024-06-17 Thread Jacques Le Roux
Hi Sumesh, We have abandoned this feature for years as it was no longer usable (too much false positive in large numbers). https://cwiki.apache.org/confluence/display/OFBIZ/About+OWASP+Dependency+Check The last time I tried to use it was after the last commit for https://issues.apache.org/jira/

Re: New User with a Jira Question

2024-06-11 Thread Jacques Le Roux
Hi Bill, Thanks for your report, it has been implement with https://issues.apache.org/jira/browse/OFBIZ-13116 Jacques Le 07/06/2024 à 17:09, Bill Harder a écrit : https://issues.apache.org/jira/browse/OFBIZ-11725 I am new to this, but have been tracking the jira mail list for close to 6+ mon

Re: AW: Ofbiz starting slow

2024-06-04 Thread Jacques Le Roux
Forgot to tell about image.server.path in catalog.properties. I guess you are already setting it? Le 05/06/2024 à 07:58, Jacques Le Roux a écrit : Hi Ingo, After reading https://lists.apache.org/thread/ymbjbf4r6tlcj5r8grh9dsrdhnfkj2tp Are you putting your images on a dedicated server as

Re: AW: Ofbiz starting slow

2024-06-04 Thread Jacques Le Roux
Hi Ingo, After reading https://lists.apache.org/thread/ymbjbf4r6tlcj5r8grh9dsrdhnfkj2tp Are you putting your images on a dedicated server as suggested here https://lists.apache.org/thread/k2zj0hkf4sr2rdb90s6s8x2jfzb256lb ? HTH Jacques Le 04/06/2024 à 16:22, Ingo Wolfmayr a écrit : Hi Johan,

Re: Configure SSL-only connection to postgres database in ofbiz

2024-06-04 Thread Jacques Le Roux
Hi Sumesh, Your message has been moderated, else it would not have reached this Mailing List. Please subscribe to the user ML for such questions and then use your email client. See why here http://ofbiz.apache.org/mailing-lists.html. You will get a better support, people can answer you on the

CVE-2024-36104: Apache OFBiz: Path traversal leading to a RCE

2024-06-02 Thread Jacques Le Roux
Severity: important Affected versions: - Apache OFBiz before 18.12.14 Description: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.14. Users are recommended to upgrade to version 18.12.

Re: Error with executeMRP service

2024-05-27 Thread Jacques Le Roux
Ah forgot, you may use your message (or adapt it) below as the description... TIA Le 27/05/2024 à 12:02, Jacques Le Roux a écrit : Hi Emad, As I suggested to Yannong, please create a Jira issue. This may help if you never did: https://cwiki.apache.org/confluence/display/OFBIZ/OFBiz

Re: Error with executeMRP service

2024-05-27 Thread Jacques Le Roux
Hi Emad, As I suggested to Yannong, please create a Jira issue. This may help if you never did: https://cwiki.apache.org/confluence/display/OFBIZ/OFBiz+Contributors+Best+Practices#OFBizContributorsBestPractices-HowtocreateaJiraissue Jacques Le 27/05/2024 à 10:14, Emad Radwan a écrit : Hello C

Re: An odd behavior in Payments

2024-05-08 Thread Jacques Le Roux
Hi Emad, Please open a Jira issue https://cwiki.apache.org/confluence/display/OFBIZ/OFBiz+Contributors+Best+Practices TIA Jacques Le 27/04/2024 à 13:28, Emad Radwan a écrit : Hello Community, While creating a new incoming payment if the 'Payment Method Id' dropdown I select one that is linke

Re: Performance scale up Thread

2024-05-08 Thread Jacques Le Roux
I suggest you use YourKit Java Profiler BTW, it's free for Apache committers https://svn.apache.org/repos/private/committers/donated-licenses/yourkit-java-profiler.txt HTH Jacques Le 08/05/2024 à 20:30, Mandar K a écrit : Dear All, related to performance scale up thread wanted to share one ob

CVE-2024-32113: Apache OFBiz: Path traversal leading to RCE

2024-05-08 Thread Jacques Le Roux
Severity: important Affected versions: - Apache OFBiz before 18.12.13 Description: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13. Users are recommended to upgrade to version 18.12.1

Re: Creating a new tenant errors for version 22.01

2024-04-30 Thread Jacques Le Roux
Hi Ivan, Your message has been moderated, else it would not have reached this Mailing List. Please subscribe to the user ML for such questions and then use your email client. See why here http://ofbiz.apache.org/mailing-lists.html. You will get a better support, people can answer you on the M

Re: Crash when logging is set to Verbose

2024-03-26 Thread Jacques Le Roux
Emad, Please create a Jira issue for that. Here is how: https://cwiki.apache.org/confluence/display/OFBIZ/OFBiz+Contributors+Best+Practices Jacques Le 25/03/2024 à 22:38, Emad Radwan a écrit : Hello Community, I noticed that - even in the online demo - that if logging is set to verbose and wh

Re: Online Demo UI Language

2024-03-26 Thread Jacques Le Roux
Hi Emad, On demo if you see another language than yours (or English if there is no translation for your language) then someone else changed for his/her own language. So yes it's annoying but you can change back to another language and it will be stored in the user you use preferences (only as lo

Re: what is expected date for apache ofbiz 24.0.0

2024-03-22 Thread Jacques Le Roux
Le 22/03/2024 à 17:24, Sameer Alwosaby a écrit : what is expected date for apache ofbiz 24.0.0? Hi Sameer, We are not sure yet, we are currently discussing about that. Note that we don't use semantic versioning. We use one similar to Ubuntu's (year/month) where we add the release number after

Re: Data Migration

2024-03-12 Thread Jacques Le Roux
It's the privilege of mature projects, less updates ;) Le 12/03/2024 à 09:51, Ravee Bandaru a écrit : Hello Jac. Thanks so much for the valuable information !! So, We will continue to use both the Releases - 18 and 22. Cheers, Ravee On Mon, 11 Mar 2024 at 22:26, Jacques Le Roux

Re: Data Migration

2024-03-11 Thread Jacques Le Roux
Vivek, We are not quite ready yet for 24.xx. There should be no problem migrating from/to any of 18/22/24. Only the code changed not the data. HTH Jacques Le 11/03/2024 à 13:03, Vivek Kumar Prasad a écrit : Thanks, Jac for your response and such valuable information. We have been using ver

Re: Data Migration

2024-03-11 Thread Jacques Le Roux
Hi Vivek, FYI: the 22.01 is not officially deprecated but at 90% it will be abandoned and replaced by a new 24.xx version yet to come. For instance we are mostly no longer backporting bug to 22.01, notably security ones. Jacques Le 11/03/2024 à 11:34, Vivek Kumar Prasad a écrit : Hello Commu

CVE-2024-25065: Apache OFBiz: Path traversal allowing authentication bypass.

2024-02-28 Thread Jacques Le Roux
Severity: critical Affected versions: - Apache OFBiz before 18.12.12 Description: Possible path traversal in Apache OFBiz allowing authentication bypass. Users are recommended to upgrade to version 18.12.12, that fixes the issue. Credit: YunPeng - 郭 运鹏 (finder) References: https://ofbiz.ap

https://ofbiz.apache.org/security.html: CVE-2024-23946: Apache OFBiz: Path traversal or file inclusion

2024-02-28 Thread Jacques Le Roux
Severity: critical Affected versions: - Apache OFBiz before 18.12.12 Description: Possible path traversal in Apache OFBiz allowing file inclusion. Users are recommended to upgrade to version 18.12.12, that fixes the issue. Credit: Arun Shaji from trendmicro.com (finder) References: https://

Re: Anyone familiar with CalcTax errors?

2024-02-21 Thread Jacques Le Roux
It was that, the patch is at https://github.com/apache/ofbiz-framework/commit/2bb296de52.patch HTH Jacques Le 21/02/2024 à 09:31, Jacques Le Roux a écrit : Hi Steve, I believe it's related to https://issues.apache.org/jira/browse/OFBIZ-12686 I then did not backport to 118.12. I'll

Re: Anyone familiar with CalcTax errors?

2024-02-21 Thread Jacques Le Roux
Hi Steve, I believe it's related to https://issues.apache.org/jira/browse/OFBIZ-12686 I then did not backport to 118.12. I'll check the reason, maybe a simple oversight So You don't need to create a Jira for now. Jacques Le 21/02/2024 à 07:16, Jacques Le Roux a écrit : Hi S

Re: Anyone familiar with CalcTax errors?

2024-02-20 Thread Jacques Le Roux
21 AM, Jacques Le Roux wrote: Hi Steven, I can't reproduce in trunk. I'm able to create the purchase order. What version did you use? You need to give us more information. The best way to do that is to create a Jira issue, just follow https://cwiki.apache.org/confluence/disp

Re: Anyone familiar with CalcTax errors?

2024-02-20 Thread Jacques Le Roux
Hi Steven, I can't reproduce in trunk. I'm able to create the purchase order. What version did you use? You need to give us more information. The best way to do that is to create a Jira issue, just follow https://cwiki.apache.org/confluence/display/OFBIZ/OFBiz+Contributors+Best+Practices You

Re: A question about issues encountered on Ofbiz trunk

2024-02-20 Thread Jacques Le Roux
Hi Ernest, The best way is to follow https://cwiki.apache.org/confluence/display/OFBIZ/OFBiz+Contributors+Best+Practices When it's a bug we fix the trunk and backport in release branches HTH Jacques Le 20/02/2024 à 05:33, Ernest Hocking a écrit : Good morning Can I seek some clarification a

Re: css in form fields

2024-02-18 Thread Jacques Le Roux
Hi Ernest, In 2010, while working on a custom project with David E. Jones and Andrew Zeneski (the OFBiz founders), I learnt a lot in a short time. With their inspiration I got the idea. Then the team improved it multiple times. At this same moment, I also put in the currently still misnamed "M

Re: ./gradlew pullAllPluginsSource FAILURE: Build failed with an exception.

2024-02-06 Thread Jacques Le Roux
xecution.java:122) at org.gradle.launcher.daemon.server.exec.LogAndCheckHealth.execute(LogAndCheckHealth.java:55) at org.gradle.launcher.daemon.server.api.DaemonCommandExecution.proceed(DaemonCommandExecution.java:122) at org.gradle.launcher.daemon.server.exec.LogToClient.doBuild(LogToClient.java:62) a

Re: ./gradlew pullAllPluginsSource FAILURE: Build failed with an exception.

2024-02-06 Thread Jacques Le Roux
Nevermind, as long as it works, all is OK ;) Le 06/02/2024 à 15:30, BK a écrit : Looks like I fixed the java, still working through some other things though. My apologies on this... I never quite learned how to set these environments up properly and it's a wrestling match every time.

Re: ./gradlew pullAllPluginsSource FAILURE: Build failed with an exception.

2024-02-06 Thread Jacques Le Roux
Hi Ryan, First which OFBiz version are you using? R18 needs JDK 8. Later (trunk or R22) uses JDK 17, IIRW JDK 11 works also. What is the failure you cross? Please past the console log (text). Also before try a "update-alternatives --list java" in case... You should not have any problem with y

Re: Use of the grid widget

2024-02-05 Thread Jacques Le Roux
Hi Ernest, Most of the time there are no differences between grids and forms. It seems you crossed one. Please create a Jira with the information below and we will try to understand and maybe fix it. The best would be to upload the complete work you did for us to test in trunk. BTW, which OFBi

Re: Error in calling SOAPServices

2024-02-05 Thread Jacques Le Roux
Hi Ansari, Unfortunately images are not accepted by this ML. You may create a related Jira and put images there for people to see them. Jacques Le 02/02/2024 à 10:15, ansariBE a écrit : Dear Experts, With any version of ofbiz tried with 17 and 18.12.05, whenever invoking SOAPService getting

Re: Ofbiz for use a core System for indigenous States

2024-02-02 Thread Jacques Le Roux
Hi Andreas, Apart if you are interested in history, the German Empire is maybe a large versatile example for management of indigenous states and federations :). Anyway, I'd say that, as OFBiz especially depends on its DB, it also depends of the material you put in it. So that should be possible

Re: Error in Ofbiz login

2024-02-02 Thread Jacques Le Roux
Hi Ansari, Unfortunately images are not accepted by this ML. You may refer to the related Jira for people to see these images. By putting them there if they are not already. Jacques Le 02/02/2024 à 10:09, ansariBE a écrit : Dear experts, I tried to setup ofbiz 18.12.11 in my laptop and I ha

Re: CVE-2023-51467-release18.12.11

2024-01-25 Thread Jacques Le Roux
It's not ready yet. We had to restart the vote. It should be available in a week or 2 Jacques Le 25/01/2024 à 16:02, Sameer Alwosaby a écrit : Where we can find 18.12.12 version please? On Thu, 18 Jan 2024, 13:42 Jacques Le Roux, wrote: Hi Vikas, There is currently a vote fo

Re: CVE-2023-51467-release18.12.11

2024-01-18 Thread Jacques Le Roux
Hi Vikas, There is currently a vote for the 18.12.12 version. Better wait for this new version HTH Jacques Le 12/01/2024 à 08:21, Vikas Jaiswal a écrit : Hello, I don’t see the tag for release18.12.11 where the vulnerability Active Exploitation of Apache OFBiz Zero-day Vulner

Re: upgrade ofbiz version

2023-12-26 Thread Jacques Le Roux
Hi Vikas, Mostly https://cwiki.apache.org/confluence/display/OFBIZ/Revisions+Requiring+Data+Migration+-+upgrade+ofbiz for data changes The rest depends on how you have handled your own changes in OFBiz OOTB (Out Of The Box) code. As you may know plugins are the recommended way. If you made ch

Re: Looking for expertise in OFBIZ 18.2 and FrontEnd JQuery based + SOAP

2023-12-24 Thread Jacques Le Roux
Hi Mohammed, Your message has been moderated, else it would not have reached this Mailing List. Please subscribe to the user ML for questions and then use your email client. See why here http://ofbiz.apache.org/mailing-lists.html. You will get a better support, people can answer you on the ML.

CVE-2023-49070: Pre-auth RCE in Apache Ofbiz 18.12.09 due to XML-RPC still present

2023-12-04 Thread Jacques Le Roux
Severity: moderate Affected versions: - Apache OFBiz before 18.12.10 Description: Pre-auth RCE in Apache Ofbiz 18.12.09. It's due to XML-RPC no longer maintained still present. This issue affects Apache OFBiz: before 18.12.10.  Users are recommended to upgrade to version 18.12.10 This issue i

Re: Order manager PDF not working

2023-11-20 Thread Jacques Le Roux
Fixed with https://issues.apache.org/jira/browse/OFBIZ-12867 Le 20/11/2023 à 11:48, Ernest Hocking a écrit : Thanks Jacques Kind regards Ernest On Mon, 20 Nov 2023, 17:09 Jacques Le Roux, wrote: Hi Ernest, It works in next, so I guess in stable too. So must be a change since. I'll h

Re: Order manager PDF not working

2023-11-20 Thread Jacques Le Roux
Hi Ernest, It works in next, so I guess in stable too. So must be a change since. I'll have a look... Jacques Le 20/11/2023 à 05:08, Ernest Hocking a écrit : Good morning everyone, I've noticed that the print PDF link in orderview is not working and fails with the message. Error "Error: fai

  1   2   3   4   5   6   7   8   9   10   >