Saturday, 2012-06-09

*** Joins: kirillka (~Miranda@195.242.142.17)01:28
GitHub185[mantisbt] vboctor pushed 1 new commit to master-1.2.x: http://git.io/IOJXnw01:32
GitHub185[mantisbt/master-1.2.x] Remove 'ERROR_DUPLICATE_FILE' entry from Croatian language which was causing a warning.  Found by test-langsas part of release process for 1.2.11. - Victor Boctor01:32
GitHub28[mantisbt] vboctor pushed 1 new commit to master-1.2.x: http://git.io/1_qfmw01:41
GitHub28[mantisbt/master-1.2.x] Updated doc/RELEASE for 1.2.11. - Victor Boctor01:41
*** Joins: vb123 (~vb123@50.46.101.89)03:10
vb123dhx1, are you there?03:10
vb123MantisBT v1.2.11 released.03:11
vb123also updated the official bug tracker and demo instances.03:11
vb123I wasn't able to build docbook stuff, so used the ones from the nightly build.03:12
vb123good night.03:15
*** Quits: vb123 (~vb123@50.46.101.89) (Ping timeout: 245 seconds)03:25
dhx1:)03:43
*** Joins: giallu (~giallu@fedora/giallu)03:55
kirillkadhx1: hi04:14
dhx1kirillka: hi04:19
kirillkadhx1: I wrote with John. I have trouble04:21
kirillkafor plugins api04:21
kirillkaI have 2 events04:21
kirillkaEVENT_UPDATE_BUG04:22
kirillkaand EVENT_BUG_ACTION04:22
kirillkaI want see what happened with bug04:22
kirillkaI try use ACTION, but I don't see all of events.04:23
kirillkaEVENT_UPDATE_BUG all events, but I don't see kind of events04:23
kirillkadhx1: any ideas?04:38
dhx1kirillka: I don't quite understand?05:18
dhx1group action updates, SOAP API, bug_attach.php, etc... probably don't fire those events05:19
*** Joins: paulr (~IceChat09@cpc1-enfi15-2-0-cust580.hari.cable.virginmedia.com)05:36
kirillkadhx1: all events, such attach file. this action not execute action event05:58
dhx1it's quite likely that the events won't fire on every instance of a bug being updated06:01
dhx1because there are multiple methods used and places where bug updates occur06:01
dhx1this isn't desired behaviour either06:02
paulrhey dhx06:14
paulrdid you see john's blog?06:14
dhx1paulr: yes06:18
dhx1paulr: as stated, it isn't much of a surprise06:19
dhx1I share the same concerns about PHP06:19
dhx1worst language ever!06:19
dhx1oh well06:19
*** Quits: kirillka (~Miranda@195.242.142.17) (Quit: kirillka)06:23
paulrdhx1: maybe I should start asking you to do CVE requests for flaws :P07:47
dhx1:)07:47
dhx1haha07:47
paulrsay 1 a day until end of month?07:47
dhx1lol, for MantisBT?07:49
paulr:)07:49
paulrwe could start with a minor information disclosure07:50
dhx1not noteworthy, sorry :)07:50
paulrmantisbt allows users to specify a level at which MANTIS_VERSION is displayed, however soap api shows this value to all soap users07:50
dhx1ugh... I want to get rid of that07:51
paulrsome companies would probably request a CVE for that ;p07:51
dhx1there is no point hiding the version information07:51
dhx1lol07:51
dhx1it would not surprise me07:51
dhx1it is easy enough to look at XHTML changes between releases to see what the version is07:51
paulrbut basically07:51
paulrsecurity research = fine07:52
paulrif people find and publish real issues07:52
dhx1automated vulnerability fuzzer results = useless!07:52
paulrat the same time, every time one does a bug fix, do we really need to go "shall we evalute if this could be considered a security issue in any case"07:52
paulrtake kirill's thing earlier07:53
paulrthat's a security issue :)07:53
dhx1lol07:53
dhx1it could be07:53
paulryou can add a plugin that logs when a user attaches a file07:53
paulrthere's a code path where the plugin hook does't fire07:53
paulrtherefore audit plugin does not log file attached07:53
paulrtherefore security issue07:53
dhx1paulr: perhaps we should start a "Common XHTML Non-Conformance Issue Database" where we track XHTML non-conformances in software? :P07:55
paulrheh08:33
*** Quits: giallu (~giallu@fedora/giallu) (Ping timeout: 260 seconds)09:14
*** Quits: dhx1 (~anonymous@60-242-247-232.static.tpgi.com.au) (Quit: Leaving)10:46
*** Joins: vb123 (~vb123@50.46.101.89)18:06
*** Quits: vb123 (~vb123@50.46.101.89) (Ping timeout: 244 seconds)18:13
*** Joins: vBm (~vBm@unaffiliated/vbm)18:47
*** Parts: vBm (~vBm@unaffiliated/vbm) ()18:47
*** Quits: sdfjkljkdfsljkl (~sdfjkljkd@static.96.23.63.178.clients.your-server.de) (Remote host closed the connection)20:00
*** Joins: sdfjkljkdfsljkl (~sdfjkljkd@static.96.23.63.178.clients.your-server.de)20:00
*** Quits: paulr (~IceChat09@cpc1-enfi15-2-0-cust580.hari.cable.virginmedia.com) (Quit: I used to think I was indecisive, but now I'm not too sure.)20:51
*** Joins: vb123 (~vb123@50.46.101.89)22:28
GitHub95[mantisbt] vboctor pushed 1 new commit to master-1.2.x: http://git.io/6NRW3w22:34
GitHub95[mantisbt/master-1.2.x] Changed version to 1.2.12-dev - Victor Boctor22:34
*** Quits: vb123 (~vb123@50.46.101.89) (Ping timeout: 245 seconds)22:50
*** Joins: vb123 (~vb123@50.46.101.89)22:53
GitHub166[mantisbt] vboctor pushed 1 new commit to master-1.2.x: http://git.io/qc1I1w23:08
GitHub166[mantisbt/master-1.2.x] Fixes #13445: Add mc_login() for login and to return user data. - Victor Boctor23:08
*** Quits: vb123 (~vb123@50.46.101.89) (Ping timeout: 252 seconds)23:25

Generated by irclog2html.py 2.10.0 by Marius Gedminas - find it at mg.pov.lt!