Friday, 2009-11-06

../irclogs/#mantishelp.2009-11-06.log
--- scribe started ---00:00
dhx_mvb123: we do have quite a lot of faulty plugins on MantisForge... some with glaring security (XSS) vulnerabilities, etc01:02
vb123dhx_m: we should make sure to report any security issues to the authors.02:34
vb123we should also think about certain plugins for which we refer to explicitly and hence providing some level of confidence.02:34
vb123The core plugins is a subset of that.02:35
kirillkavb123: lo04:15
kirillkawhat about faq?04:15
kirillkavb123: contact with me kirillkr on googlemail04:33
vb123kirillka: ?08:45
kirillkavb123: hi08:46
vb123my user name on mantisforge is vboctor08:46
kirillkaone sec08:46
kirillkavb123: ok08:48
kirillkanow you have access to 3 plugins08:49
vb123which ones?08:49
kirillkawith owner krasnovforum08:49
kirillkawhere owner cas I don't know pass08:50
kirillkafaq, bbcode, highlightcode08:50
kirillkadhx_m: hi, you here?08:50
dhx_mkirillka: yep, hi :)08:51
vb123I checked in some FAQ fixes: http://git.mantisforge.org/w/faq.git?a=commitdiff;h=d602552badcdf282eac57b17f09d459c954145f308:51
kirillkawhat you accaunt on git?08:51
dhx_mdhx on mantisforge I believe08:51
dhx_mI'll confirm08:51
kirillkaok08:51
vb123kirillka: can you check why these errors were not showing in your environment?08:52
kirillkaadd08:52
dhx_mhmmm there are usernames on mantisforge?08:52
dhx_moh yeah there is08:52
dhx_mI see it now08:52
dhx_mdhx it is08:52
kirillkaI add you too08:53
kirillkavb123: one sec08:53
vb123ok08:54
dhx_mthanks08:54
kirillkavb123: you right. on test - machine not work.08:58
vb123you mean the FAQ before my checkin?08:59
kirillkaÎÕÙ08:59
kirillkayes08:59
vb123so you changed your error reporting settings?09:01
kirillkayes.09:01
vb123ok, no you can check all the plugins you have access to.09:02
vb123I just noticed something with the bbcode plugin.09:02
vb123once it is installed, the following happens:09:02
vb123Before: NoteA09:02
kirillkain highlight more notice from dhx_m09:02
vb123After: <p>NoteA</p>09:02
vb123sorry, I meant the highlight not the bbcode.09:02
vb123bbcode was installed as well.09:03
kirillkathis plugins must rewriten with bbcode - bar09:04
vb123what do you mean?09:04
kirillkain textarea add bar with button09:04
dhx_mbbcode is prone to xss attacks09:05
dhx_mand fixing it doesn't seem easy09:05
kirillkadhx_m: highlightcode - too09:05
dhx_myep09:07
kirillkavb123: on test site last version of faq09:10
kirillkaall work09:10
vb123yep, I did some testing here.09:13
vb123after my fixes.09:13
kirillkavbBig thanks09:19
kirillkavb123:  Big thanks09:19
vb123no problem.09:19
kirillkadhx_m: If you help fix xss from plugins - big thanks too ;)09:22
dhx_mif I get time, sure :)09:40
dhx_mis there some sort of "bbcode standard"?09:41
ln-once a bug report has been entered to project X, can it be modified to belong to project Y?12:43
dhx_myes12:45
dhx_mjust move it ;)12:45
dhx_myou will then need to manually update the category once it is in project Y12:45
ln-oh, there's the Move button indeed12:46
ln-thanks12:46
dhx_m:)12:48
CIA-22Mantisbt: jreese * r82a3b9ced185 /core/ (5 files in 2 dirs): Implement optional sorting for custom columns16:16
CIA-22Mantisbt: jreese master-1.2.x * re99d93b12a8d /core/ (5 files in 2 dirs): Implement optional sorting for custom columns16:16
darynnuclear_eclipse - that seems like a new feature to me. Why did you merge it to 1.2.x?17:22
nuclear_eclipsebecause it "fixes" incompleteness that I had started adding to 1.2 from before we had an RC17:25
darynoh, ok.17:25
nuclear_eclipseeg, I'm finally finishing what I had started weeks ago :P17:25
darynjust wondering17:25
nuclear_eclipseyeah, there are definitely a lot of things that went into the RC's lately that have been altogether new features or changes, and I don't like to do things like that, but the custom filter/column features were incomplete without the stuff I added yesterday/today17:26
nuclear_eclipseat this point though, I think I'm ready to drop an RC3 with all the SOAP fixes, or even just push a final release17:27
darynwould be nice to get to final for sure17:27
nuclear_eclipserombert's fixes for SOAP have really been what I was hoping to get before a final release all along...17:28
daryni've seen some complaints about new features on here but seems like nobody actually asks about it so I thought I'd ask17:28
darynnew features in an RC that is17:28
nuclear_eclipsepaul just makes snarky comments :P17:28
darynyeah i don't really like passive agressive...just tell me you disagree and we'll deal with it17:29
darynso...your explanation works for me. looks like a good feature.17:29
nuclear_eclipsethanks :)17:30
nuclear_eclipseIt will allow things like `filter on issues with changesets attached`, or `show me how many changesets are attached to each issue in this list`17:30
daryni like the direction you took with the filters. i was looking in a similar direction but hadn't had time to work on it17:32
darynshould make things easier, better for future17:32
nuclear_eclipseyeah17:32
nuclear_eclipseanywho, lunchtime here17:32
nuclear_eclipsecheers17:32
daryncheers17:33
WatergadGood evening. Sometime being actively used Mantis ends an event with a blank page (bug_update.php, bugnote add etc.). Could anyone give a clue?18:02
Watergadabout 50-70 users, <100 projects, <500 issues18:04
Watergads/Good evening/Good day or even morning for you, I suppose (:18:05
darynWatergad that is usually some sort of php error. have you checked the web server logs?18:11
Watergadoops... I didn't18:12
Watergadsorry, had to do it first18:12
darynno problem18:12
lwfhi! is it possible to allow signups without checking the email address?19:30
lwfor if i put it like this, can mantis 1.1.8 be used without a mail server?19:38
nuclear_eclipselwf: if you run Mantis on unix/linux, yes19:39
lwfnuclear_eclipse: unfortunately not, it's running on windows19:40
nuclear_eclipsehmm, it "can" run without email, but bug trackers tend to not be as useful without email and notifications...19:43
lwfi suppose that's true19:46
lwfcan you recommend any simple mail server for that purpose that is easy to setup on windows?19:47
lwfoh, and it won't have any domain name19:47
lwfif that makes any difference19:47
nuclear_eclipsethat's fine, it just needs to be a relay19:48
nuclear_eclipseand no, I don't know any off-hand, but http://en.wikipedia.org/wiki/Comparison_of_mail_servers might help19:48
lwfi'll give that a try, thanks19:49
lwfdoesn't a relay need a smtp server to forward the mails to?20:01
Watergadwhat for if you even wanted to run w/out mailserver, just use standalone email server. No, it's optional - to forward email further20:02
lwfwould this do? http://emailrelay.sourceforge.net/20:03
WatergadSeems that it's not exactly what you want20:05
WatergadBut I can be wrong, I'm not familiar with email servers enough20:05
lwfi want mantis to be able to send mails from a windows machine, that's all :)20:06
lwfother than that i don't know much about email either20:06
WatergadThere are many small easy win mailservers20:07
WatergadI don't remember exactly names, I just opened google and found the smallest (:20:07
Watergadit was about 4 years ago but I don't think anything changed20:08
lwfshoot20:08
Watergadjust check out URL nuclear_eclipse has given20:09
Watergad*give20:09
lwfoh20:09
lwfso i want SMTP then and that's all?20:10
Watergadafaik yes20:10
Watergadhttp://www.google.com/search?hl=en&source=hp&q=mail+server+windows smth like that20:13
lwfi'l looking at hMailServer atm20:13
Watergadyes, it looks enough for your needs20:13
Watergadand quite simple to not to think a lot about it20:14
lwfit doesn't look a so bad20:14
WatergadI suppose my last phrase was not composed properly, nevermind20:19
Watergadlack of english practice, sorry...20:20
lwfno problem, your english is fine20:21
paulr_.20:27
paulr_7:44 < nuclear_eclipse> paul just makes snarky comments :P20:29
paulr_nuclear_eclipse: out of interest20:29
paulr_did you look at ldap patch?20:29
nuclear_eclipseyou mean the patch to lang_api?20:30
paulr_nod20:31
paulr_it should be a no-op20:31
nuclear_eclipseI saw it and wasn't really sure what the change was for20:32
paulr_changing lang files to array20:33
paulr_it should be a non-change backwards compatible20:33
paulr_until we change lang files20:33
paulr_which is something siebrand/myself have been discussing logistics of20:33
nuclear_eclipseok20:33
paulr_iirc, we discussed in here 2-3 months ago20:33
paulr_but basically20:33
paulr_$s_foo = 'bar', $s_moo = 'moo'20:33
paulr_becomes20:33
paulr_$g_lang['foo'=bar, $g_lang['moo']=moo20:34
nuclear_eclipsewould be nice to be able to keep multiple langs in memory at once for places like email generation where X people getting notified use diff langs each20:37
paulr_I dont change/limit that through right?20:37
nuclear_eclipseI dunno20:37
paulr_this if anything should be a no-change-performance fix20:37
nuclear_eclipseI'm just saying it'd be nice to not have to re-read the lang files every time20:37
paulr_(i.e. we dont do preg_replace or whatever on 500 strings)20:38
paulr_i'm thinking of long term20:38
paulr_once we have an array20:38
paulr_we can serialise array and cache if somewhere20:38
paulr_(file/memcache maybe?)20:38
nuclear_eclipseyeah20:41
paulr_if we can confirm the lang api change is a no-change20:41
paulr_we can commit20:41
paulr_and then siebrand/myself can work out logistics of getting translate wiki sort20:42
paulr_+ed20:42
lwfit's alive! i just got my first email server working... on windows 200020:50
lwfi feel a little dirty but it's ok20:51
lwfthanks guys!20:51
Watergadcongratulations20:51
nuclear_eclipselwf: just make sure it can't be accessed outside your network, don't want to be acting as a spam relay20:52
lwfit's already protected by a firewall but i suppose configuring the server not to accept any connections from other hosts couldn't hurt, thanks20:53
paulr_nuclear_eclipse: so anything wrong/invalid with patch? :P21:08
paulr_lwf: windows 2000???21:08
lwfpaulr_: windows 2000 professional, actually21:10
lwfthat mean it's good21:10
nuclear_eclipsepaulr_: not that I could tell really21:13
paulr_so its fine I guess?21:17
nuclear_eclipseif it breaks 1.3 for a while, I'm not going to be heartbroken ;)21:18
paulr_ok21:20
paulr_:)21:20
paulr_worksforme21:20
* nuclear_eclipse assumes you won't be committing that patch to 1.221:21
paulr_trunk21:21
paulr_I only commit to trunk /21:21
* paulr_ pokes siebrand 21:21

Generated by irclog2html.py