*** goschtl has joined #zope | 00:05 | |
*** daMaestro has joined #zope | 00:09 | |
*** J1m_ has joined #zope | 00:13 | |
*** goschtl has quit IRC | 00:16 | |
*** daMaestro has quit IRC | 00:30 | |
*** goschtl has joined #zope | 00:38 | |
*** zenwryly has joined #zope | 00:39 | |
*** J1m_ has quit IRC | 00:40 | |
*** daMaestro has joined #zope | 00:43 | |
*** goschtl has quit IRC | 00:47 | |
*** ccomb has quit IRC | 01:09 | |
*** mr_jolly has quit IRC | 01:09 | |
*** mr_jolly has joined #zope | 01:16 | |
*** lcpfnyvc has quit IRC | 02:07 | |
*** lcpfnyvc has joined #zope | 02:08 | |
*** Arfrever has quit IRC | 02:20 | |
*** MrTango has quit IRC | 02:36 | |
*** d2m has quit IRC | 02:47 | |
*** J1m_ has joined #zope | 02:57 | |
*** mr_jolly has quit IRC | 03:01 | |
*** gwik has quit IRC | 04:22 | |
*** daMaestro has quit IRC | 04:22 | |
*** chaoflow_ is now known as chaoflow | 04:55 | |
*** purserj has joined #zope | 05:17 | |
*** davisagli has quit IRC | 07:10 | |
*** davisagli has joined #zope | 07:11 | |
*** sm has quit IRC | 07:31 | |
*** dayne has quit IRC | 08:06 | |
*** hever has quit IRC | 08:59 | |
*** digitalmortician has quit IRC | 09:14 | |
*** tiwula has quit IRC | 09:26 | |
*** d2m has joined #zope | 09:37 | |
*** goschtl has joined #zope | 09:52 | |
*** goschtl has quit IRC | 10:07 | |
*** mcdonc has quit IRC | 10:19 | |
*** zagy has joined #zope | 10:26 | |
*** planetzopebot has quit IRC | 10:33 | |
*** planetzopebot has joined #zope | 10:34 | |
*** d2m has quit IRC | 11:00 | |
*** d2m has joined #zope | 11:14 | |
*** ccomb has joined #zope | 11:19 | |
*** d2m has quit IRC | 11:30 | |
*** cpf_ has joined #zope | 11:32 | |
CIA-85 | zagy * r120456 /Acquisition/branches/zagy-unicode-should-be-called: remove completed bug fix branch (released in 2.13.6) | 11:37 |
---|---|---|
*** nebo has joined #zope | 12:00 | |
*** nebo has quit IRC | 12:17 | |
*** digitalmortician has joined #zope | 12:27 | |
*** nebo has joined #zope | 12:33 | |
*** nebo has quit IRC | 12:48 | |
CIA-85 | hannosch 2.12 * r120457 Zope/include: Update AQ external | 12:49 |
*** Ariel_Calzada has joined #zope | 13:07 | |
*** mr_jolly has joined #zope | 13:14 | |
*** TomBlockley has joined #zope | 13:43 | |
*** MrTango has joined #zope | 13:50 | |
CIA-85 | mj * r120458 zope.password/ (5 files in 2 dirs): | 13:51 |
CIA-85 | Add a 'match' method to the IPasswordManager interface, which returns True if a given password hash was encdoded with the scheme implemented by the specific manager. | 13:51 |
CIA-85 | Note that the plain-text manager always returns False for this method, as the alternative is to always return True and thus also validate hashed password against their literal values, a security risk. | 13:51 |
*** nitrogenycs has joined #zope | 13:54 | |
*** m8 has joined #zope | 13:54 | |
*** TomBlockley has quit IRC | 13:57 | |
CIA-85 | mj * r120459 zope.password/ (src/zope/password/password.py CHANGES.txt): | 14:46 |
CIA-85 | Use {SHA} instead of {SHA1} to be compatible with LDAP (RFC 2307). | 14:46 |
CIA-85 | We still support checking against password hashes prefixed with {SHA1}. | 14:46 |
*** zagy has quit IRC | 14:57 | |
*** d2m has joined #zope | 15:06 | |
*** d2m has quit IRC | 15:17 | |
*** digitalmortician has quit IRC | 15:23 | |
*** digitalmortician has joined #zope | 15:35 | |
*** J1m_ has joined #zope | 15:37 | |
CIA-85 | mj * r120460 zope.password/src/zope/password/password.py: Clean up SSHA test, turning a redundant test into something that actually covers the issue at hand. | 15:53 |
CIA-85 | mj * r120461 zope.password/ (5 files in 3 dirs): Add a crypt password manager. | 15:53 |
*** nebo has joined #zope | 15:54 | |
*** hever has joined #zope | 15:58 | |
*** hever has quit IRC | 16:01 | |
*** hever has joined #zope | 16:02 | |
*** bigkevmcd has quit IRC | 16:04 | |
*** TheJester has quit IRC | 16:16 | |
*** TheJester has joined #zope | 16:16 | |
*** hever has quit IRC | 16:22 | |
*** hever has joined #zope | 16:28 | |
*** hever has quit IRC | 16:30 | |
*** sm has joined #zope | 16:42 | |
CIA-85 | mj * r120462 zope.password/ (4 files in 2 dirs): | 16:49 |
CIA-85 | Port AccessControl.AuthEncoding.MySQLDigestScheme to zope.password. | 16:49 |
CIA-85 | This is very much a legacy scheme, encoding to a very weak 16 bit hash with no salt support. | 16:49 |
CIA-85 | mj * r120463 zope.password/ (8 files in 2 dirs): | 16:49 |
CIA-85 | Keep things backwards compatible by creating an extended interface. | 16:49 |
CIA-85 | By moving the match method to a IMatchingPasswordManager, we keep the original interface unchanged and thus backwards compatible. Users of zope.password that require the new functionality can test for the new interface. | 16:49 |
CIA-85 | mj * r120464 zope.password/README.txt: Correct spelling. | 16:49 |
CIA-85 | mj * r120465 zope.password/README.txt: Add the 2 new legacy managers to the readme. | 16:49 |
*** zenwryly has quit IRC | 16:49 | |
*** Arfrever has joined #zope | 16:59 | |
*** Ariel_Calzada has quit IRC | 17:08 | |
*** seppo14 has joined #zope | 17:09 | |
*** supton has joined #zope | 17:10 | |
*** Ariel_Calzada has joined #zope | 17:13 | |
*** River_Rat has joined #zope | 17:16 | |
*** River-Rat has quit IRC | 17:18 | |
*** seppo14 has left #zope | 17:25 | |
*** mlechner has joined #zope | 17:25 | |
*** alexmorega has joined #zope | 17:45 | |
*** supton has quit IRC | 17:53 | |
*** agroszer has joined #zope | 18:07 | |
*** agroszer has quit IRC | 18:08 | |
*** mlechner has quit IRC | 18:13 | |
*** supton has joined #zope | 18:26 | |
*** sm_ has joined #zope | 18:34 | |
*** sm has quit IRC | 18:38 | |
*** sm_ is now known as sm | 18:38 | |
CIA-85 | mj * r120466 zope.password/ (src/zope/password/password.py CHANGES.txt README.txt): | 18:57 |
CIA-85 | Remove the completely useless 'cosmetic' salt from the MD5 manager. | 18:57 |
CIA-85 | The generated salt was not being used to generate the actual hash and had no | 18:57 |
CIA-85 | cryptographic meaning. It only served to make the output incompatible with | 18:57 |
CIA-85 | RFC 2307 MD5 implementations. Any encoded input with the salt still in place are still supported for password checks. | 18:57 |
CIA-85 | mj * r120467 zope.password/src/zope/password/password.py: Remove now redundant test. | 18:57 |
CIA-85 | mj * r120468 zope.password/ (src/zope/password/password.py CHANGES.txt README.txt): Remove the 'cosmetic' salt from the SHA1 implementation as well, update docs. | 18:57 |
CIA-85 | mj * r120469 zope.password/src/zope/password/password.py: | 18:57 |
CIA-85 | LDAP does not use the URL-safe base64 encoding! See http://www.openldap.org/faq/data/cache/347.html. | 18:57 |
CIA-85 | Correct to use the standard encoding instead. | 18:57 |
CIA-85 | mj * r120470 zope.password/ (src/zope/password/password.py CHANGES.txt): | 18:57 |
CIA-85 | Maintain backwards compatibility to older hashes encoded with urlsafe. | 18:57 |
CIA-85 | Update documentation as well. | 18:57 |
CIA-85 | mj * r120471 zope.password/src/zope/password/password.py: | 18:57 |
CIA-85 | Newly generated slappasswd example with / and + to test base64 assertions. | 18:57 |
CIA-85 | Note that with a different salt there are / and + characters in the slappasswd output showing that the urlsafe_base64 assumption from before is incorrect. | 18:57 |
CIA-85 | mj * r120472 zope.password/src/zope/password/password.py: | 18:57 |
CIA-85 | Correct slappasswd test to actually use the new salt, and fix urlsafe case. | 18:57 |
CIA-85 | The urlsafe backwards compatible mode is now covered with a test and actually works. | 18:57 |
*** nijan has joined #zope | 19:06 | |
nijan | Hello, I have googled for "Zope2 or Zope3", but even the wiki in zope.org contains recommandations from 2007. It says site builders who want to get sites up and running quickly, with a lot of ready-made add-ons to choose from, should choose Zope 2, but keep an eye on Zope 3 and try to use its practices where possible. | 19:09 |
nijan | Is this advice still valuable or after 4 years I should go for Zope3? Basically, I need plone and add-ons, but I see that plone now supports zope3. | 19:10 |
*** menesis has joined #zope | 19:16 | |
*** nijan has quit IRC | 19:21 | |
*** mcdonc has joined #zope | 19:30 | |
*** tiwula has joined #zope | 19:44 | |
*** supton has quit IRC | 19:44 | |
*** davisagli has quit IRC | 19:45 | |
*** davisagli has joined #zope | 19:46 | |
*** d2m has joined #zope | 19:56 | |
*** alexmorega has quit IRC | 20:02 | |
*** mustard has joined #zope | 20:52 | |
*** Theuni1 has quit IRC | 20:55 | |
*** J1m_ has quit IRC | 21:03 | |
*** mustard has quit IRC | 21:16 | |
*** hever has joined #zope | 21:38 | |
*** tiwula has quit IRC | 21:51 | |
CIA-85 | mj * r120473 zope.password/ (src/zope/password/password.py CHANGES.txt): | 21:51 |
CIA-85 | Make SHA and MD5 output compatible with LDAP schemes. | 21:51 |
CIA-85 | This means using base64 output instead of hexdigests. We still support checking passwords against the old format. | 21:51 |
CIA-85 | mj * r120474 zope.password/CHANGES.txt: typo. | 21:51 |
*** RaceCondition has joined #zope | 22:14 | |
*** menesis has quit IRC | 22:14 | |
RaceCondition | I couldn't find any information on how to use zope.tal in a non-zope app | 22:15 |
*** menesis has joined #zope | 22:16 | |
*** Theuni1 has joined #zope | 22:19 | |
*** menesis has quit IRC | 22:19 | |
*** menesis has joined #zope | 22:19 | |
*** mustard has joined #zope | 22:25 | |
*** hever has quit IRC | 22:28 | |
*** hever has joined #zope | 22:31 | |
*** menesis has quit IRC | 22:45 | |
*** menesis1 has joined #zope | 22:46 | |
*** menesis1 is now known as menesis | 22:46 | |
*** goschtl has joined #zope | 22:46 | |
*** menesis has quit IRC | 22:47 | |
*** menesis has joined #zope | 22:48 | |
*** Theuni1 has quit IRC | 22:49 | |
*** nitrogenycs has quit IRC | 23:04 | |
*** nitrogenycs has joined #zope | 23:05 | |
*** d2m has quit IRC | 23:17 | |
*** goschtl has quit IRC | 23:20 | |
*** J1m_ has joined #zope | 23:30 | |
*** ccomb has quit IRC | 23:33 | |
CIA-85 | thefunny42 * r120475 /grokcore.view/branches/sylvain-template-warning-improvements: Branch to improve the number of unassociated template warning | 23:34 |
CIA-85 | thefunny42 sylvain-template-warning-improvements * r120476 grokcore.view/ (6 files in 2 dirs): Add an ignoreTemplate ZCML directive. | 23:34 |
*** davisagli has quit IRC | 23:44 | |
*** davisagli has joined #zope | 23:45 | |
*** J1m_ has quit IRC | 23:48 | |
*** J1m_ has joined #zope | 23:53 |
Generated by irclog2html.py 2.15.1 by Marius Gedminas - find it at mg.pov.lt!