From portal-commits at lists.jboss.org Tue Jan 24 17:41:48 2012 Content-Type: multipart/mixed; boundary="===============7031343608682681462==" MIME-Version: 1.0 From: portal-commits at lists.jboss.org To: portal-commits at lists.jboss.org Subject: [portal-commits] JBoss Portal SVN: r14039 - in docs/enterprise/trunk: PortletBridge/en-US and 5 other directories. Date: Tue, 24 Jan 2012 17:41:46 -0500 Message-ID: <201201242241.q0OMfkeV008197@svn01.web.mwc.hst.phx2.redhat.com> --===============7031343608682681462== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Author: jaredmorgs Date: 2012-01-24 17:41:45 -0500 (Tue, 24 Jan 2012) New Revision: 14039 Modified: docs/enterprise/trunk/Installation_Guide/en-US/Book_Info.xml docs/enterprise/trunk/Installation_Guide/en-US/Revision_History.xml docs/enterprise/trunk/PortletBridge/en-US/Book_Info.xml docs/enterprise/trunk/PortletBridge/en-US/Revision_History.xml docs/enterprise/trunk/Reference_Guide/en-US/Book_Info.xml docs/enterprise/trunk/Reference_Guide/en-US/Revision_History.xml docs/enterprise/trunk/Release_Notes/en-US/Book_Info.xml docs/enterprise/trunk/Release_Notes/en-US/CP07_Release_Notes.xml docs/enterprise/trunk/Release_Notes/en-US/Revision_History.xml docs/enterprise/trunk/Release_Notes/en-US/feature_requests.old docs/enterprise/trunk/Release_Notes/en-US/feature_requests.xml docs/enterprise/trunk/Release_Notes/en-US/known_issues.old docs/enterprise/trunk/Release_Notes/en-US/known_issues.xml docs/enterprise/trunk/Release_Notes/en-US/resolved_issues.old docs/enterprise/trunk/Release_Notes/en-US/resolved_issues.xml docs/enterprise/trunk/Release_Notes_Old/en-US/CP07_Release_Notes.xml docs/enterprise/trunk/Tuning_Guide/en-US/Book_Info.xml docs/enterprise/trunk/Tuning_Guide/en-US/Revision_History.xml docs/enterprise/trunk/User_Guide/en-US/Book_Info.xml docs/enterprise/trunk/User_Guide/en-US/Revision_History.xml Log: Eff it, lets release Modified: docs/enterprise/trunk/Installation_Guide/en-US/Book_Info.xml =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D --- docs/enterprise/trunk/Installation_Guide/en-US/Book_Info.xml 2012-01-24= 21:21:57 UTC (rev 14038) +++ docs/enterprise/trunk/Installation_Guide/en-US/Book_Info.xml 2012-01-24= 22:41:45 UTC (rev 14039) @@ -4,11 +4,11 @@ = Installation Guide - An Installation Guide for &PRODUCT; + For use with &PRODUCT; JBoss Enterprise Portal Platform 4.3 4.3.7 - 1 + 100 = This Installation Guide documents relevant information= regarding the installation of JBoss Enterprise Portal Platform Modified: docs/enterprise/trunk/Installation_Guide/en-US/Revision_History.x= ml =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D --- docs/enterprise/trunk/Installation_Guide/en-US/Revision_History.xml 201= 2-01-24 21:21:57 UTC (rev 14038) +++ docs/enterprise/trunk/Installation_Guide/en-US/Revision_History.xml 201= 2-01-24 22:41:45 UTC (rev 14039) @@ -6,6 +6,20 @@ Revision History + + 4.3.7-100 + Tue Jan 24 2011 + + Jared + Morgan + jmorgan [at] redhat [dot] com + + + + Prepared for JBoss Enterprise Portal Platform 4.= 3.0 CP07 GA. + + + 1-1.4 Fri Jul 15 2011 Modified: docs/enterprise/trunk/PortletBridge/en-US/Book_Info.xml =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D --- docs/enterprise/trunk/PortletBridge/en-US/Book_Info.xml 2012-01-24 21:2= 1:57 UTC (rev 14038) +++ docs/enterprise/trunk/PortletBridge/en-US/Book_Info.xml 2012-01-24 22:4= 1:45 UTC (rev 14039) @@ -7,7 +7,7 @@ JBoss Enterprise Portal Platform 4.3 4.3.7 - 1 + 100 The JBoss Portlet Bridge is an implementation of the JSR-301 s= pecification to support JSF within a portlet and with added enhancements to= support other web frameworks. Currently the bridge supports any combinatio= n of JSF, Seam, and RichFaces to run inside a portlet. Modified: docs/enterprise/trunk/PortletBridge/en-US/Revision_History.xml =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D --- docs/enterprise/trunk/PortletBridge/en-US/Revision_History.xml 2012-01-= 24 21:21:57 UTC (rev 14038) +++ docs/enterprise/trunk/PortletBridge/en-US/Revision_History.xml 2012-01-= 24 22:41:45 UTC (rev 14039) @@ -5,6 +5,20 @@ Revision History + + 4.3.7-100 + Tue Jan 24 2011 + + Jared + Morgan + jmorgan [at] redhat [dot] com + + + + Prepared for JBoss Enterprise Portal Platform 4.= 3.0 CP07 GA. + + + 1-2.1 Fri Jul 15 2011 Modified: docs/enterprise/trunk/Reference_Guide/en-US/Book_Info.xml =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D --- docs/enterprise/trunk/Reference_Guide/en-US/Book_Info.xml 2012-01-24 21= :21:57 UTC (rev 14038) +++ docs/enterprise/trunk/Reference_Guide/en-US/Book_Info.xml 2012-01-24 22= :41:45 UTC (rev 14039) @@ -3,11 +3,11 @@ ]> Reference Guide - A Reference Guide for Enterprise Portal Platform 4.3 + For use with JBoss Enterprise Portal Platform 4.3 JBoss Enterprise Portal Platform 4.3 4.3.7 - 1 + 100 This book is the Enterprise Portal Platform Reference Guide. Modified: docs/enterprise/trunk/Reference_Guide/en-US/Revision_History.xml =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D --- docs/enterprise/trunk/Reference_Guide/en-US/Revision_History.xml 2012-0= 1-24 21:21:57 UTC (rev 14038) +++ docs/enterprise/trunk/Reference_Guide/en-US/Revision_History.xml 2012-0= 1-24 22:41:45 UTC (rev 14039) @@ -6,6 +6,20 @@ Revision History + + 4.3.7-100 + Tue Jan 24 2011 + + Jared + Morgan + jmorgan [at] redhat [dot] com + + + + Prepared for JBoss Enterprise Portal Platform 4.= 3.0 CP07 GA. + + + 1-1.10 Fri Jul 15 2011 Modified: docs/enterprise/trunk/Release_Notes/en-US/Book_Info.xml =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D --- docs/enterprise/trunk/Release_Notes/en-US/Book_Info.xml 2012-01-24 21:2= 1:57 UTC (rev 14038) +++ docs/enterprise/trunk/Release_Notes/en-US/Book_Info.xml 2012-01-24 22:4= 1:45 UTC (rev 14039) @@ -9,7 +9,7 @@ JBoss Enterprise Portal Platform 4.3 4.3.7 - 1 + 50 These release notes contain important information related to JBos= s Enterprise Portal Platform &VZ; that may not be currently available in th= e Product Manuals. You should read these Release Notes in their entirety be= fore installing the product. Modified: docs/enterprise/trunk/Release_Notes/en-US/CP07_Release_Notes.xml =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D --- docs/enterprise/trunk/Release_Notes/en-US/CP07_Release_Notes.xml 2012-0= 1-24 21:21:57 UTC (rev 14038) +++ docs/enterprise/trunk/Release_Notes/en-US/CP07_Release_Notes.xml 2012-0= 1-24 22:41:45 UTC (rev 14039) @@ -1,6 +1,5 @@ - - %BOOK_ENTITIES; ]> @@ -16,17 +15,16 @@ Installation - The JBoss Enterprise Portal Platform Installation Guid= e contains detailed installation instructions as well as enviro= nment requirements. + The JBoss Enterprise Portal Platform &VZ; Installatio= n Guide contains detailed installation instructions as well as = environment requirements. The Installation Guide is available in multiple formats from <= ulink url=3D"http://docs.redhat.com/docs/en-US/JBoss_Enterprise_Portal_Plat= form/index.html" type=3D"http"/>. - Component Versions - Updated table from https://docspace.corp.redhat.com/docs= /DOC-68705 (version 13) + Component versions<remark>Component versions</remark> - Component Versions + Component versions @@ -38,156 +36,36 @@ - EAP - 5.1.1-GA + JBoss Enterprise Application Platform + 4.3.0 CP10 - eXo junit - 1.2.1-GA + Identity Module + 1.1.3 - eXo kernel - 2.3.3-GA + Portlet Module + 2.0.9 - eXo Core - 2.4.3-GA + Web Module + 1.2.4 - eXo WS - 2.2.3-GA + CMS Module + 1.2.9 - eXo JCR - 1.14.3-GA + JBoss Portlet Bridge + 2.0.1.FINAL.EPP43CP07 - - Apache Shindig - 2.0.2-CP01 - - - Simple Captcha - 1.1.1-GA-Patch01 - - - GateIn Parent - 1.1.0-GA - - - GateIn dep - 1.1.0-GA - - - GateIn Common - 2.0.4-GA - - - GateIn WCI - 2.1.0-GA - - - GateIn PC - 2.3.0-GA - - - GateIn WSRP - 2.1.0-EPP520-GA - - - GateIn MOP - 1.1.0-GA - - - GateIn SSO - 1.1.0-GA - - - PicketLink IDM - 1.3.0.GA - - - Chromattic - 1.1.1 - - - Portlet Bridge - 2.2.0.GA.EPP520 - - - Seam - 2.2.4.EAP5 - - - Richfaces - 3.3.1.SP3 - - - Groovy - 1.7.6 - - - Commons DBCP - 1.4 - - - Commons IO - 1.4 - - - Commons Lang - 2.6 - - - HSQLDB - 2.0.0 - - - JBoss Cache - 3.2.7 - - - GateIn Management - 1.0.0-GA -
- Upgraded Components - - New Components - The following new components warrant special mention. - - - - Site Migration Utilities - - This new functionality is designed to improve the experien= ce of managing unique sites or groups of pages as they progress from the de= velopment to production life cycle. The Migration utility has multiple admi= nistrative interfaces to support the requirements of different enterprises.= - - - - Site Management Utilities - - The new functionality is provided to assist administrators= in performing routine tasks. This includes the release of IDM cache, gathe= ring of performance metrics and other processes related to managing the por= tal server. - - - - - Updated Components - The following updated components warrant special mention. - - - - Java Content Respostory - - This updated release of the eXo Java Content Repository (J= CR) has been updated to a newer version designed to improve the performance= and scalability of large portal sites. - - - - - For detailed information about component versions included in = this release, refer to = - + New and upgraded components<remark>New and upgraded components<= /remark> + There are no new or upgrade components that require special ment= ion in this release. Refer to for those co= mponents that received an update outside of the primary components specifie= d in Documentation @@ -196,7 +74,7 @@
- Product Support Links + Product support links Product Update and Support Processes @@ -216,16 +94,16 @@ - - New Features + + New features - Known Issues + Known issues - Resolved Issues + Resolved issues The following issues were resolved in this release of JBoss En= terprise Portal Platform. Modified: docs/enterprise/trunk/Release_Notes/en-US/Revision_History.xml =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D --- docs/enterprise/trunk/Release_Notes/en-US/Revision_History.xml 2012-01-= 24 21:21:57 UTC (rev 14038) +++ docs/enterprise/trunk/Release_Notes/en-US/Revision_History.xml 2012-01-= 24 22:41:45 UTC (rev 14039) @@ -4,12 +4,12 @@ %BOOK_ENTITIES; ]> - Revision History + Revision history - 5.2.0-101 - Thu Dec 14 2011 + 4.3.7-100 + Wed Jan 25 2011 Jared Morgan @@ -17,7 +17,7 @@ - Release Notes prepared for JBoss Enterprise Portal Pla= tform 5.2.0 GA. + Release Notes prepared for JBoss Enterprise Portal Pla= tform 4.3.0 CP07 GA. Modified: docs/enterprise/trunk/Release_Notes/en-US/feature_requests.old =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D --- docs/enterprise/trunk/Release_Notes/en-US/feature_requests.old 2012-01-= 24 21:21:57 UTC (rev 14038) +++ docs/enterprise/trunk/Release_Notes/en-US/feature_requests.old 2012-01-= 24 22:41:45 UTC (rev 14039) @@ -1,4 +1,333 @@ + + + + + + JBEPP-736 + + + Assignee is: mposolda + JIRA is Closed + + It is possible to switch portal clusters between UDP and TCP comm= unication modes using a command-line parameter. The -Dgatein.default.jgroup= s.stack=3D[tcp | udp] parameter switches EPP clusters (JCR, IDM, MOPSession= Manager, NavigationService, DescriptionService) between the two protocols. = The functionality is implemented using an adapted, and mutually exclusive i= mplementation of jboss.default.jgroups.stack. = - -There are no Feature Request in this release. - + + This enhancement is based on, but deliberately independent= of, the JBoss Enterprise Application Platform parameter. "jboss.defau= lt.jgroups.stack" which supports more values by default than Enterpris= e Portal Platform currently does. The decision to keep the two parameters s= eparate was for upstream compatibility. + + + + + + + JBEPP-932 + + + Assignee is: theute + JIRA is Closed + + URL handler support is available in this release. The WCM compone= nt uses this feature to support locales as part of the URL. + + + + + + JBEPP-933 + + + Assignee is: theute + JIRA is Closed + + Performance bottlenecks have been removed when a portal runs with= hundreds of navigation nodes. + + + + + + JBEPP-934 + + + Assignee is: theute + JIRA is Closed + + In previous releases, navigation node translations had to be mana= ged in language property files. This release allows Navigation nodes to be = translated directly through the administration interface. + + + + + + JBEPP-937 + + + Assignee is: theute + JIRA is Closed + + It is now possible to define a portlet.xml that describes element= s such as filters that need to be applied to all portlets. The file is loca= ted in jboss-as/server/[configuration]/conf/gatein/portlet.xml + + + + + + JBEPP-938 + + + Assignee is: mwringe + JIRA is Closed + + This release upgrades Shindig to version 2.0.2. Shindig is used t= o embed OpenSocial gadgets. Refer to the Component Versions section for the= definitive version featured in this release. + + + + + + JBEPP-939 + + + Assignee is: hfnukal + JIRA is Closed + + Web service security between WSRP producers and consumers is avai= lable in this release. This enhancement allows for encrypted communication = and access to authenticated user content over WSRP. + + + + + + JBEPP-940 + + + Assignee is: bdaw + JIRA is Closed + + This release makes it possible to configure several LDAP servers = containing different users with GateIn. In a ReadOnly scenario, the user is= searched in all configured sources. In a ReadWrite scenario, the user is c= reated only in the first configured LDAP server, but obtained from all. = + + + + + + JBEPP-1008= + + + Assignee is: hfnukal + JIRA is Closed + + Application registry categories are now cached for better perf= ormance. + + + + + + JBEPP-1015= + + + Assignee is: theute + JIRA is Closed + + Each site can now have a site description, which can be accessed = and used by the management applications. + + + + + + JBEPP-1016= + + + Assignee is: mwringe + JIRA is Closed + + Priority for the loading of skin css files can now be specified i= n gatein-resources.xml using the css-priority xml element. This allows the = css elements to be loaded in a specific order, which can be useful for over= riding existing css elements. + + + + + + JBEPP-1045= + + + Assignee is: claprun + JIRA is Closed + + WSRP was previously unavailable for portal extensions. The new= WSRP component now properly initializes itself even when started from an e= xtension (as opposed to the default portal container). + + + + + + JBEPP-1077= + + + This issue is unassigned! + JIRA is Closed + + The datasource for JCR is now using managed transactions, and re= quired a change in the datasource descriptor. + + + + + + JBEPP-1078= + + + Assignee is: hfnukal + JIRA is Closed + + EPP is now partially available in Czech language. + + + + + + JBEPP-1088= + + + Assignee is: theute + JIRA is Closed + + When adding a page to a site, pages are displayed in a drop-down = list instead of a free form text field. This makes adding pages more intuit= ive. + + + + + + JBEPP-1098= + + + Assignee is: mwringe + JIRA is Closed + + This release of JBoss Enterprise Portal Platform adds a configura= ble setting to control whether the 'info bar' which surrounds new= portlets is displayed by default. + + + + + + JBEPP-1099= + + + Assignee is: mposolda + JIRA is Closed + + In this release, the Single Sign On (SSO) component has been enha= nced to support FORM authentication for instances where the user can not ge= t access to SSO authentication sessions (such as a Kerberos ticket). Users = can now authenticate manually with the portal-specific username and passwor= d as a fall-back. + + + + + + JBEPP-1116= + + + Assignee is: claprun + JIRA is Closed + + Configuring a page is no longer restricted to local portlets. It = is now possible to define remote portlets (WSRP) in page descriptors to pop= ulate the base data for the page. + + + + + + JBEPP-1140= + + + Assignee is: hfnukal + JIRA is Closed + + In previous releases, the portal did not indicate it had started = clearly in the logs. Changes to core portal code now specifies the portal h= as started in the logs, and includes the portal version number for referenc= e. + + + + + + JBEPP-1149= + + + Assignee is: theute + JIRA is Closed + + This release contains enhancements to Gadgets, which, like portle= ts, can now be integrated on a page definition through XML descriptors. + + + + + + JBEPP-1158= + + + Assignee is: theute + JIRA is Closed + + The HTML Document Object Module (DOM) has been optimized to achie= ve better performance when transmitting markup, and has been simplified for= faster rendering on recent web browsers. Older browsers such as Internet E= xplorer will still work, however performance will be degraded. + + + + + + JBEPP-1169= + + + Assignee is: theute + JIRA is Closed + + The Apache Shindig configuration file has been made more accessib= le to be modified more easily. It is now part of eXoGadgetServer.war/contai= ners/default/container.js + + + + + + JBEPP-1197= + + + Assignee is: hfnukal + JIRA is Closed + + An enhancement to the UserDashboardImpl object now allows dashboa= rd instances to be reused. Dashboards now require less resources to operate= correctly. + + + + + + JBEPP-1210= + + + Assignee is: mposolda + JIRA is Closed + + Cluster data transportation has been optimized to reduce the numb= er of network connections and threads. + + + + + + JBEPP-1250= + + + Assignee is: theute + JIRA is Closed + + When defining navigation in an XML descriptor, it is now possible= to define the strategy to apply during startup. It is possible to "co= nserve", "insert", "merge" or "rewrite" = the content previously imported. + + + + + + JBEPP-1332= + + + Assignee is: theute + JIRA is Closed + + In this release the default JCR workspace name and system JCR wor= kspace name can now be configured in the configuration.properties file. + + + + + + JBEPP-1349= + + + Assignee is: hfnukal + JIRA is Closed + + There was no way to determine the Enterprise Portal Platform vers= ion, based on what was displayed when starting the portal. An enhancement t= o UIFooterPortlet.gtmpl has been implemented, which allows the user to see = what portal version is used by mouse-hovering in the site footer. + + + + Modified: docs/enterprise/trunk/Release_Notes/en-US/feature_requests.xml =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D --- docs/enterprise/trunk/Release_Notes/en-US/feature_requests.xml 2012-01-= 24 21:21:57 UTC (rev 14038) +++ docs/enterprise/trunk/Release_Notes/en-US/feature_requests.xml 2012-01-= 24 22:41:45 UTC (rev 14039) @@ -1,333 +1,44 @@ - + + + - - - JBEPP-736 - - - Assignee is: mposolda - JIRA is Closed - - It is possible to switch portal clusters between UDP and TCP comm= unication modes using a command-line parameter. The -Dgatein.default.jgroup= s.stack=3D[tcp | udp] parameter switches EPP clusters (JCR, IDM, MOPSession= Manager, NavigationService, DescriptionService) between the two protocols. = The functionality is implemented using an adapted, and mutually exclusive i= mplementation of jboss.default.jgroups.stack. + = + + + JBEPP= -920 + + = + Assignee is: theute + = + = + JIRA is Closed + = + = + + JackRabbit has been upgraded to version 1.6.4 in this release. + + = + + = - - This enhancement is based on, but deliberately independent= of, the JBoss Enterprise Application Platform parameter. "jboss.defau= lt.jgroups.stack" which supports more values by default than Enterpris= e Portal Platform currently does. The decision to keep the two parameters s= eparate was for upstream compatibility. - + + + JBEP= P-1457 + + = + Assignee is: theute + = + = + JIRA is Closed + = + = + + The Enterprise Application Platform base component has been upgra= ded to version 4.3.0 CP10 in this release. - - - - - JBEPP-932 - - - Assignee is: theute - JIRA is Closed - - URL handler support is available in this release. The WCM compone= nt uses this feature to support locales as part of the URL. - - - - - - JBEPP-933 - - - Assignee is: theute - JIRA is Closed - - Performance bottlenecks have been removed when a portal runs with= hundreds of navigation nodes. - - - - - - JBEPP-934 - - - Assignee is: theute - JIRA is Closed - - In previous releases, navigation node translations had to be mana= ged in language property files. This release allows Navigation nodes to be = translated directly through the administration interface. - - - - - - JBEPP-937 - - - Assignee is: theute - JIRA is Closed - - It is now possible to define a portlet.xml that describes element= s such as filters that need to be applied to all portlets. The file is loca= ted in jboss-as/server/[configuration]/conf/gatein/portlet.xml - - - - - - JBEPP-938 - - - Assignee is: mwringe - JIRA is Closed - - This release upgrades Shindig to version 2.0.2. Shindig is used t= o embed OpenSocial gadgets. Refer to the Component Versions section for the= definitive version featured in this release. - - - - - - JBEPP-939 - - - Assignee is: hfnukal - JIRA is Closed - - Web service security between WSRP producers and consumers is avai= lable in this release. This enhancement allows for encrypted communication = and access to authenticated user content over WSRP. - - - - - - JBEPP-940 - - - Assignee is: bdaw - JIRA is Closed - - This release makes it possible to configure several LDAP servers = containing different users with GateIn. In a ReadOnly scenario, the user is= searched in all configured sources. In a ReadWrite scenario, the user is c= reated only in the first configured LDAP server, but obtained from all. = - - - - - - JBEPP-1008= - - - Assignee is: hfnukal - JIRA is Closed - - Application registry categories are now cached for better perf= ormance. - - - - - - JBEPP-1015= - - - Assignee is: theute - JIRA is Closed - - Each site can now have a site description, which can be accessed = and used by the management applications. - - - - - - JBEPP-1016= - - - Assignee is: mwringe - JIRA is Closed - - Priority for the loading of skin css files can now be specified i= n gatein-resources.xml using the css-priority xml element. This allows the = css elements to be loaded in a specific order, which can be useful for over= riding existing css elements. - - - - - - JBEPP-1045= - - - Assignee is: claprun - JIRA is Closed - - WSRP was previously unavailable for portal extensions. The new= WSRP component now properly initializes itself even when started from an e= xtension (as opposed to the default portal container). - - - - - - JBEPP-1077= - - - This issue is unassigned! - JIRA is Closed - - The datasource for JCR is now using managed transactions, and re= quired a change in the datasource descriptor. - - - - - - JBEPP-1078= - - - Assignee is: hfnukal - JIRA is Closed - - EPP is now partially available in Czech language. - - - - - - JBEPP-1088= - - - Assignee is: theute - JIRA is Closed - - When adding a page to a site, pages are displayed in a drop-down = list instead of a free form text field. This makes adding pages more intuit= ive. - - - - - - JBEPP-1098= - - - Assignee is: mwringe - JIRA is Closed - - This release of JBoss Enterprise Portal Platform adds a configura= ble setting to control whether the 'info bar' which surrounds new= portlets is displayed by default. - - - - - - JBEPP-1099= - - - Assignee is: mposolda - JIRA is Closed - - In this release, the Single Sign On (SSO) component has been enha= nced to support FORM authentication for instances where the user can not ge= t access to SSO authentication sessions (such as a Kerberos ticket). Users = can now authenticate manually with the portal-specific username and passwor= d as a fall-back. - - - - - - JBEPP-1116= - - - Assignee is: claprun - JIRA is Closed - - Configuring a page is no longer restricted to local portlets. It = is now possible to define remote portlets (WSRP) in page descriptors to pop= ulate the base data for the page. - - - - - - JBEPP-1140= - - - Assignee is: hfnukal - JIRA is Closed - - In previous releases, the portal did not indicate it had started = clearly in the logs. Changes to core portal code now specifies the portal h= as started in the logs, and includes the portal version number for referenc= e. - - - - - - JBEPP-1149= - - - Assignee is: theute - JIRA is Closed - - This release contains enhancements to Gadgets, which, like portle= ts, can now be integrated on a page definition through XML descriptors. - - - - - - JBEPP-1158= - - - Assignee is: theute - JIRA is Closed - - The HTML Document Object Module (DOM) has been optimized to achie= ve better performance when transmitting markup, and has been simplified for= faster rendering on recent web browsers. Older browsers such as Internet E= xplorer will still work, however performance will be degraded. - - - - - - JBEPP-1169= - - - Assignee is: theute - JIRA is Closed - - The Apache Shindig configuration file has been made more accessib= le to be modified more easily. It is now part of eXoGadgetServer.war/contai= ners/default/container.js - - - - - - JBEPP-1197= - - - Assignee is: hfnukal - JIRA is Closed - - An enhancement to the UserDashboardImpl object now allows dashboa= rd instances to be reused. Dashboards now require less resources to operate= correctly. - - - - - - JBEPP-1210= - - - Assignee is: mposolda - JIRA is Closed - - Cluster data transportation has been optimized to reduce the numb= er of network connections and threads. - - - - - - JBEPP-1250= - - - Assignee is: theute - JIRA is Closed - - When defining navigation in an XML descriptor, it is now possible= to define the strategy to apply during startup. It is possible to "co= nserve", "insert", "merge" or "rewrite" = the content previously imported. - - - - - - JBEPP-1332= - - - Assignee is: theute - JIRA is Closed - - In this release the default JCR workspace name and system JCR wor= kspace name can now be configured in the configuration.properties file. - - - - - - JBEPP-1349= - - - Assignee is: hfnukal - JIRA is Closed - - There was no way to determine the Enterprise Portal Platform vers= ion, based on what was displayed when starting the portal. An enhancement t= o UIFooterPortlet.gtmpl has been implemented, which allows the user to see = what portal version is used by mouse-hovering in the site footer. - - - + = + + + Modified: docs/enterprise/trunk/Release_Notes/en-US/known_issues.old =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D --- docs/enterprise/trunk/Release_Notes/en-US/known_issues.old 2012-01-24 2= 1:21:57 UTC (rev 14038) +++ docs/enterprise/trunk/Release_Notes/en-US/known_issues.old 2012-01-24 2= 2:41:45 UTC (rev 14039) @@ -1,4 +1,116 @@ + + = - -There are no known issues in this release. - + + + = + + + JBEP= P-1376 + + = + Assignee is: theute + = + = + JIRA is OPEN + = + = + + When serving content from a portlet, resource encoding is being r= ewritten with the default encoding of the running JVM. To work around the i= ssue, server the resource as a binary, or set the default system encoding t= o ISO-8859-1. + + = + + + + + + JBEP= P-1396 + + = + This issue is unassigned! + = + = + JIRA is OPEN + = + = + + When a dashboard page is created and its title translated in vari= ous languages, switching languages will not update the dashboard page name = on the user interface immediately. To work around the issue, log out and lo= g back in to show the correct translation for the page name. + + = + + + + + + JBEP= P-1399 + + = + This issue is unassigned! + = + = + JIRA is OPEN + = + = + + If you create a system subnode under a node in the Navigation Man= agement, you are allowed the delete the parent node without the "Cannot del= ete a system node" message being shown. When trying to save the result, a m= essage "Unknown error" is shown and the following NPE is thrown. A fix is b= eing investigated for a future release. + + = + + + + + + JBEP= P-1401 + + = + Assignee is: theute + = + = + JIRA is OPEN + = + = + + An issue with the No Result Found pop-up causes it to display aft= er first searching for a non-existent user string, then searching for a str= ing that is known to exist. There is no work around for this issue. + + = + + + + + + JBEP= P-1402 + + = + Assignee is: theute + = + = + JIRA is OPEN + = + = + + An issue with node copy or clone behavior allows users to copy or= clone a system node but not delete the node. This is caused by the node al= ready being a system node, and therefore it can not be deleted based on it'= s context. There is no work around for this issue. + + = + + + + + + JBEP= P-1411 + + = + This issue is unassigned! + = + = + JIRA is OPEN + = + = + + System child nodes can be deleted if the parent node is deleted. = A system node should not be able to de be deleted, regardless of its positi= on in a navigation tree. This behavior will be fixed in a future release. + + = + + + + Modified: docs/enterprise/trunk/Release_Notes/en-US/known_issues.xml =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D --- docs/enterprise/trunk/Release_Notes/en-US/known_issues.xml 2012-01-24 2= 1:21:57 UTC (rev 14038) +++ docs/enterprise/trunk/Release_Notes/en-US/known_issues.xml 2012-01-24 2= 2:41:45 UTC (rev 14039) @@ -1,116 +1,4 @@ - - = - - - = - - - JBEP= P-1376 - - = - Assignee is: theute - = - = - JIRA is OPEN - = - = - - When serving content from a portlet, resource encoding is being r= ewritten with the default encoding of the running JVM. To work around the i= ssue, server the resource as a binary, or set the default system encoding t= o ISO-8859-1. - - = - - - - - - JBEP= P-1396 - - = - This issue is unassigned! - = - = - JIRA is OPEN - = - = - - When a dashboard page is created and its title translated in vari= ous languages, switching languages will not update the dashboard page name = on the user interface immediately. To work around the issue, log out and lo= g back in to show the correct translation for the page name. - - = - - - - - - JBEP= P-1399 - - = - This issue is unassigned! - = - = - JIRA is OPEN - = - = - - If you create a system subnode under a node in the Navigation Man= agement, you are allowed the delete the parent node without the "Cannot del= ete a system node" message being shown. When trying to save the result, a m= essage "Unknown error" is shown and the following NPE is thrown. A fix is b= eing investigated for a future release. - - = - - - - - - JBEP= P-1401 - - = - Assignee is: theute - = - = - JIRA is OPEN - = - = - - An issue with the No Result Found pop-up causes it to display aft= er first searching for a non-existent user string, then searching for a str= ing that is known to exist. There is no work around for this issue. - - = - - - - - - JBEP= P-1402 - - = - Assignee is: theute - = - = - JIRA is OPEN - = - = - - An issue with node copy or clone behavior allows users to copy or= clone a system node but not delete the node. This is caused by the node al= ready being a system node, and therefore it can not be deleted based on it'= s context. There is no work around for this issue. - - = - - - - - - JBEP= P-1411 - - = - This issue is unassigned! - = - = - JIRA is OPEN - = - = - - System child nodes can be deleted if the parent node is deleted. = A system node should not be able to de be deleted, regardless of its positi= on in a navigation tree. This behavior will be fixed in a future release. - - = - - - - + +There are no known issues in this release. + Modified: docs/enterprise/trunk/Release_Notes/en-US/resolved_issues.old =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D --- docs/enterprise/trunk/Release_Notes/en-US/resolved_issues.old 2012-01-2= 4 21:21:57 UTC (rev 14038) +++ docs/enterprise/trunk/Release_Notes/en-US/resolved_issues.old 2012-01-2= 4 22:41:45 UTC (rev 14039) @@ -1,4 +1,457 @@ - - -There are no resolved issues in this release. - + + + + + + JBEPP-348 + + + Assignee is: hfnukal + JIRA is Closed + + A Cross-site Scripting (XSS) vulnerability was discovered in t= he portlet description, which allowed Javascript to be specified in the por= tlet description through the application registry. The vulnerability has be= en fixed in this release. (CVE-2011-4580) + + + + + + JBEPP-353 + + + Assignee is: hfnukal + JIRA is Closed + + A Cross-site Scripting (XSS) vulnerability was discovered when= adding a portlet to a category. The vulnerability has been fixed in this r= elease. (CVE-2011-4580) + + + + + + JBEPP-631 + + + Assignee is: hfnukal + JIRA is Closed + + Remote Gadgets were not persisting data in category gadgets with = more than five categories when the user switched between pages. User data e= ntered in one screen was being lost when the user switched between pages. T= he fix implements changes to UIForm.js and UIFormCheckBoxInput.java which h= andles selected values reliably when the user switches between screens. + + + + + + JBEPP-699 + + + This issue is unassigned! + JIRA is Closed + + A bug in UIUserLanguageSelector caused a problem with dynamically= updating the locale when a user selected a different language. The languag= e state had to be saved using the Apply button. The fix introduces changes = to locale handling in the affected module which fixes the issue. + + + + + + JBEPP-715 + + + This issue is unassigned! + JIRA is Closed + + The page URL conventions in previous versions of JBoss Enterprise= Portal Platform did not allow for Portal pages to have the same name. In t= hese instances, pages with identical names were allocated the same URL, wit= h only one page available through it. A change to the way JBoss Enterprise = Portal Platform constructs page URLs resolves this issue. + + + + + + JBEPP-763 + + + Assignee is: hfnukal + JIRA is Closed + + The platform ships with a resource compressor (CSS and Javascript= ). Some javascript files were incorrectly compressed and would break unless= the developer mode was enabled. Enabling the developer mode introduced pe= rformance side-effects. The Javascript compression engine has been replaced= , and can be turned off if required, which fixes the issue. + + + + + + JBEPP-900 + + + Assignee is: hfnukal + JIRA is Closed + + A bug in the Logo Portlet caused the processAction methods to be = called once when the first, valid, processAction method was called to submi= t the value, and again when the page was rendered. This caused null values = to be passed on the second submit. A fix to UILogoPortlet.gtmpl removes the= second processAction call issue, which fixes the issue. + + + + + + JBEPP-901 + + + Assignee is: bdaw + JIRA is Closed + + When a "root" user (advanced administrative rights) = logs onto the portal, part of the logon process calls a query that fetches = all the groups from the database. This query was not optimized to handle da= tabases containing very large numbers of groups. When testing with a large = group database, the login process took an unacceptable amount of time. The = fix implements performance improvements to the query, and provides enhanced= caching for large group records. + + + + + + JBEPP-903 + + + Assignee is: bdaw + JIRA is Closed + + An issue was identified when the OrganizationManagementPortlet= displayed many users from the IDM DB. This caused performance issues, spec= ifically impacting load times for the portlet. The fix implements performan= ce optimizations for specific database queries related to the process. Load= time performance is improved for the portlet. + + + + + + JBEPP-908 + + + Assignee is: bdaw + JIRA is Closed + + A performance issue in a database query that checked for dupli= cate emails at user registration caused unacceptable wait times. The larger= the user count was in the database, the more pronounced the issue. The fix= implements performance optimization in the database query. User registrati= on wait time is improved for portal instances with very large user database= s. + + + + + + JBEPP-927 + + + Assignee is: theute + JIRA is Closed + + It is not possible to save notes in the TODO gadget when the gadg= et is placed anywhere except a dashboard. This behavior is expected. A work= around to this issue has been implemented in this version, which allows not= es to be entered into this gadget only. Other gadgets still have this issue. + + + + + + JBEPP-950 + + + Assignee is: mposolda + JIRA is Closed + + An inefficiency in MOPSessionManager cache was causing unaccep= table wait times when an user accessed the portal for the first time, when = the portal was idle for an extended period, or when accessing pages that ha= d not been previously cached. The fix implements performance improvements f= or cases where a portal instance has many pages and navigation nodes, impro= ving overall response time. + + + + + + JBEPP-951 + + + Assignee is: mposolda + JIRA is Closed + + Performance issues were discovered in the portal when editing = a navigation, or portal page that contained many sub-pages. In some cases, = the save action was taking longer than one minute to complete. The fix impl= ements changes to the queries used to retrieve navigation, or portal pages = after saving, which improves load times significantly. = + + + + + + JBEPP-983 + + + Assignee is: claprun + JIRA is Closed + + An inconsistency in how portlets are handled across different par= t of the administration interface resulted in an error when remote portlets= were added to a category from the "Portlet" tab of the Applicati= on Registry. The inconsistency has now be resolved and it should be now pos= sible to properly display remote portlets regardless of how they were added= to categories. + + + + + + JBEPP-985 + + + Assignee is: hfnukal + JIRA is Closed + + DateTimeValidator.java had an unnecessary check where the date in= put value needed to match the (not localized) DATETIME_REGEX. This superflu= ous requirement caused localized date input to fail. The fix removes the DA= TETIME_REGEX, which fixes the issue. + + + + + + JBEPP-1032= + + + Assignee is: bdaw + JIRA is Closed + + A bug was discovered where a transaction commit related to IDM da= tabase operations was not placed within a final() block. Any misconfigurati= on, or operation failure, could cause the database connection to remain ope= n. The fix ensures the transaction commit related to IDM database operation= s is placed within a final() block, which fixes the issue. + + + + + + JBEPP-1048= + + + Assignee is: hfnukal + JIRA is Closed + + A Cross-Site Scripting (XSS) vulnerability was discovered in t= he Edit Page > Container Title field. The vulnerability is fixed in this= release. (CVE-2011-4580) + + + + + + JBEPP-1049= + + + Assignee is: theute + JIRA is Closed + + A Cross-site Scripting (XSS) vulnerability was discovered in t= he New Node label. The vulnerability has been removed in this release. (CVE= -2011-4580) + + + + + + JBEPP-1050= + + + Assignee is: theute + JIRA is Closed + + A Cross-site Scripting (XSS) vulnerability was discovered in t= he RSS reader gadget. The vulnerability has been fixed in this release. (CV= E-2011-4580) + + + + + + JBEPP-1067= + + + Assignee is: bdaw + JIRA is Closed + + Only users from the LDAP database were shown in organization m= anagement if LDAP did not support sorting. The fix changes the logging leve= l to INFO in PicketLink IDM. + + + + + + JBEPP-1082= + + + Assignee is: hfnukal + JIRA is Closed + + If gadget restrict access to specific group, it was accessible= for not members in Dashboard and page editing. +Now users cannot add restricted gadget. + + + + + + JBEPP-1148= + + + Assignee is: theute + JIRA is Closed + + Activating JRMP configuration in JBoss EPP 5.1.x (or EPP based pr= oducts) produced a large quantity of JMX/RMI logs in stdout/stderr. The JRM= P agent had logging set to FINE, which resulted in verbose log information.= The fix removes the embedded logger configuration, which results in the JB= oss Enterprise Application Platform server log configuration being used for= logging. + + + + + + JBEPP-1150= + + + Assignee is: mputz + JIRA is Closed + + An invisible navigation node was displayed in the Sitemap portlet= when the parent node was expanded (not with Expand All button). The workar= ound described in the linked JIRA has been implemented in this release, whi= ch corrects the originally reported issue. + + + + + + JBEPP-1167= + + + Assignee is: theute + JIRA is Closed + + A problem with regard to the location of token keys prevented Gad= gets from working in load-balanced clustered portal environments. Token key= s have been moved to a location accessible by all load-balanced clustered p= ortal instances. Gadgets can now be used as intended. + + + + + + JBEPP-1196= + + + Assignee is: hfnukal + JIRA is Closed + + A problem with UploadService was causing the MIME type of .rtf fi= les extracted from DiskFileItem in Apache as "text/rtf". The valu= e should have been extracted as "application/rtf", which caused p= roblems for applications dependent on correct MIME type information. The fi= x corrects the MIME type encoding, and ensures .rtf files are set with the = MIME type "application/rtf". + = + + + + + + JBEPP-1221= + + + Assignee is: mwringe + JIRA is Closed + + A problem with the GroupManagement.java isAdministrator method ca= used a NullPointerException when the Organization Portlet is placed on a pa= ge and an anonymous user tries to access it. The fix changes the behavior o= f isAdministrator for anonymous users, which fixes the issue. + + + + + + JBEPP-1241= + + + Assignee is: theute + JIRA is Closed + + A Cross-site Scripting (XSS) vulnerability was discovered in t= he UIFormDateTimeInput component. The vulnerability has been fixed in this = release. (CVE-2011-4580) + + + + + + JBEPP-1243= + + + Assignee is: theute + JIRA is Closed + + Group descriptions text entered by users was not properly prot= ected from XSS attacks. It was possible to execute arbitrary Javascript if = a user had permissions to enter a group description. The group description = field has been protected to not execute any Javascript, which resolves the = issue. (CVE-2011-4580) + + + + + + JBEPP-1293= + + + Assignee is: kenfinni + JIRA is Closed + + org.jboss.portletbridge.seam.SeamPhaseListenerWrapper.afterPhase(= ) did not correctly handle exceptions. Exceptions that typically occurred d= uring during afterPhase() were truncated (for example StaleObjectStateExcep= tion in Hibernate commit). The Seam exception handler was not notified of t= he truncated exceptions therefore the application moves to a next page inst= ead of an error page. The fix ensures org.jboss.portletbridge.seam.SeamPhas= eListenerWrapper.afterPhase() catches exceptions and passes them to Seam ex= ception handler (for example, org.jboss.seam.jsf.SeamPhaseListener). Becaus= e exceptions are handled correctly, the Seam exception handler displays and= error page given the appropriate conditions. + + + + + + JBEPP-1310= + + + Assignee is: hfnukal + JIRA is Closed + + If the Opera browser is used to access the portal home page, a Ja= vascript Uncaught exception is raised: "TypeError: 'Browser.setOp= acity' is not a function". The fix incorporates a verified custo= mer-submitted patch to Browser.js, which allows Opera browsers to access th= e portal home page. = + + + + + + JBEPP-1319= + + + Assignee is: claprun + JIRA is Closed + + If the WSRP consumer was refreshed and activated, WSRP selfv2 pre= vented the server from starting when it was rebooted. The only way to work = around this issue was to perform a force quit. The fix adds a &lt;value= -param&gt; configuration option to the main WSRP configuration. consume= rsInitDelay provides a way to specify a delayed start (configurable, in sec= onds) of the ConsumerRegistry, which prevents a deadlock situation while th= e self consumers wait for the producer WSDL to be published. + + + + + + JBEPP-1324= + + + Assignee is: hfnukal + JIRA is Closed + + It was found that the invoker servlets, deployed by default via +httpha-invoker, only performed access control on the HTTP GET and POST +methods, allowing remote attackers to make unauthenticated requests by +using different HTTP methods. Due to the second layer of authentication +provided by a security interceptor, this issue is not exploitable on +default installations unless an administrator has misconfigured the +security interceptor or disabled it. (CVE-2011-4085) + + + + + + JBEPP-1331= + + + Assignee is: theute + JIRA is Closed + + When a portal host name contained the word "portal" in = the name, gadgets were not displayed and a TemplateRuntimeException would o= ccur. The fix adds functionality to several portal components which allows = for the word "portal" in the host name. + + + + + + JBEPP-1336= + + + Assignee is: theute + JIRA is Closed + + It was found that the GateIn Portal contained verb-specific se= curity constraints. As a result, authentication and authorization were only= correctly applied to requests made using the GET and POST HTTP verbs. The = GateIn Portal application does not allow a user to trigger any action using= HTTP verbs other than POST and GET, so this issue did not expose an exploi= table security flaw. As a defence-in-depth measure, the verb-specific secur= ity constraints have been removed. Authentication and authorization now cor= rectly apply to requests made using all HTTP verbs. + + + + + + JBEPP-1351= + + + Assignee is: hfnukal + JIRA is Closed + + The org.gatein.sso.agent.login.SSOLoginModule contains the common= options "portal" and "realmName" as offered in other L= oginModule classes. In the packaged gatein-jboss-beans.xml, this login modu= le did not have these options. This caused problems when a customer wanted = to implement SSO on a different portal container (for example in ecmdemo). = The fix includes these common options in gatein-jboss-beans.xml, which reso= lves the issue. + + + + + + JBEPP-1357= + + + Assignee is: claprun + JIRA is Closed + + The Web Services for Remote Portlet (WSRP) configuration files fo= r consumers and producer were previously only looked for in the WSRP extens= ion archive. This resulted in extra configuration complexity for customers = who wanted to edit the configuration directives for WSRP consumers and prod= ucer. The fix implements changes to the WSRP integration point that will no= w also look for WSRP configuration files in the conf/gatein directory of th= e active JBoss AS profile. + + + + + + JBEPP-1361= + + + Assignee is: mposolda + JIRA is Closed + + The JBoss Clustered Single Sign On (SSO) Valve must authenticate = on all clustered nodes using the same password. The login process in Enterp= rise Portal Platform differed from normal authentication methods, and custo= mers had to bypass standard authentication by enabling BASIC authentication= , or patch login.jsp as described in the Reference Guide. The fix introduce= s PortalClusteredSSOSupportValve, which removes the patching and workaround= s customers had to implement in earlier versions of the product, and increa= ses overall platform security. + + + + Modified: docs/enterprise/trunk/Release_Notes/en-US/resolved_issues.xml =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D --- docs/enterprise/trunk/Release_Notes/en-US/resolved_issues.xml 2012-01-2= 4 21:21:57 UTC (rev 14038) +++ docs/enterprise/trunk/Release_Notes/en-US/resolved_issues.xml 2012-01-2= 4 22:41:45 UTC (rev 14039) @@ -2,456 +2,64 @@ - + - JBEPP-348 + JBEPP-918 - Assignee is: hfnukal - JIRA is Closed - - A Cross-site Scripting (XSS) vulnerability was discovered in t= he portlet description, which allowed Javascript to be specified in the por= tlet description through the application registry. The vulnerability has be= en fixed in this release. (CVE-2011-4580) - - - - - - JBEPP-353 - - - Assignee is: hfnukal - JIRA is Closed - - A Cross-site Scripting (XSS) vulnerability was discovered when= adding a portlet to a category. The vulnerability has been fixed in this r= elease. (CVE-2011-4580) - - - - - - JBEPP-631 - - - Assignee is: hfnukal - JIRA is Closed - - Remote Gadgets were not persisting data in category gadgets with = more than five categories when the user switched between pages. User data e= ntered in one screen was being lost when the user switched between pages. T= he fix implements changes to UIForm.js and UIFormCheckBoxInput.java which h= andles selected values reliably when the user switches between screens. - - - - - - JBEPP-699 - - - This issue is unassigned! - JIRA is Closed - - A bug in UIUserLanguageSelector caused a problem with dynamically= updating the locale when a user selected a different language. The languag= e state had to be saved using the Apply button. The fix introduces changes = to locale handling in the affected module which fixes the issue. - - - - - - JBEPP-715 - - - This issue is unassigned! - JIRA is Closed - - The page URL conventions in previous versions of JBoss Enterprise= Portal Platform did not allow for Portal pages to have the same name. In t= hese instances, pages with identical names were allocated the same URL, wit= h only one page available through it. A change to the way JBoss Enterprise = Portal Platform constructs page URLs resolves this issue. - - - - - - JBEPP-763 - - - Assignee is: hfnukal - JIRA is Closed - - The platform ships with a resource compressor (CSS and Javascript= ). Some javascript files were incorrectly compressed and would break unless= the developer mode was enabled. Enabling the developer mode introduced pe= rformance side-effects. The Javascript compression engine has been replaced= , and can be turned off if required, which fixes the issue. - - - - - - JBEPP-900 - - - Assignee is: hfnukal - JIRA is Closed - - A bug in the Logo Portlet caused the processAction methods to be = called once when the first, valid, processAction method was called to submi= t the value, and again when the page was rendered. This caused null values = to be passed on the second submit. A fix to UILogoPortlet.gtmpl removes the= second processAction call issue, which fixes the issue. - - - - - - JBEPP-901 - - - Assignee is: bdaw - JIRA is Closed - - When a "root" user (advanced administrative rights) = logs onto the portal, part of the logon process calls a query that fetches = all the groups from the database. This query was not optimized to handle da= tabases containing very large numbers of groups. When testing with a large = group database, the login process took an unacceptable amount of time. The = fix implements performance improvements to the query, and provides enhanced= caching for large group records. - - - - - - JBEPP-903 - - - Assignee is: bdaw - JIRA is Closed - - An issue was identified when the OrganizationManagementPortlet= displayed many users from the IDM DB. This caused performance issues, spec= ifically impacting load times for the portlet. The fix implements performan= ce optimizations for specific database queries related to the process. Load= time performance is improved for the portlet. - - - - - - JBEPP-908 - - - Assignee is: bdaw - JIRA is Closed - - A performance issue in a database query that checked for dupli= cate emails at user registration caused unacceptable wait times. The larger= the user count was in the database, the more pronounced the issue. The fix= implements performance optimization in the database query. User registrati= on wait time is improved for portal instances with very large user database= s. - - - - - - JBEPP-927 - - Assignee is: theute JIRA is Closed - It is not possible to save notes in the TODO gadget when the gadg= et is placed anywhere except a dashboard. This behavior is expected. A work= around to this issue has been implemented in this version, which allows not= es to be entered into this gadget only. Other gadgets still have this issue. + A bug in the org.jboss.portal.cms.security.AuthorizationProviderI= mpl#getCurrentRoles() call was incorrectly returning null. Users authentica= ted using LDAP were not seeing content that should have been available to t= hem through the CMSPreviewServlet. The fix implements a fallback mechanism = that uses the membershipModule to correctly authenticate users. - + - JBEPP-950 + JBEPP-928 - Assignee is: mposolda - JIRA is Closed - - An inefficiency in MOPSessionManager cache was causing unaccep= table wait times when an user accessed the portal for the first time, when = the portal was idle for an extended period, or when accessing pages that ha= d not been previously cached. The fix implements performance improvements f= or cases where a portal instance has many pages and navigation nodes, impro= ving overall response time. - - - - - - JBEPP-951 - - - Assignee is: mposolda - JIRA is Closed - - Performance issues were discovered in the portal when editing = a navigation, or portal page that contained many sub-pages. In some cases, = the save action was taking longer than one minute to complete. The fix impl= ements changes to the queries used to retrieve navigation, or portal pages = after saving, which improves load times significantly. = - - - - - - JBEPP-983 - - - Assignee is: claprun - JIRA is Closed - - An inconsistency in how portlets are handled across different par= t of the administration interface resulted in an error when remote portlets= were added to a category from the "Portlet" tab of the Applicati= on Registry. The inconsistency has now be resolved and it should be now pos= sible to properly display remote portlets regardless of how they were added= to categories. - - - - - - JBEPP-985 - - - Assignee is: hfnukal - JIRA is Closed - - DateTimeValidator.java had an unnecessary check where the date in= put value needed to match the (not localized) DATETIME_REGEX. This superflu= ous requirement caused localized date input to fail. The fix removes the DA= TETIME_REGEX, which fixes the issue. - - - - - - JBEPP-1032= - - - Assignee is: bdaw - JIRA is Closed - - A bug was discovered where a transaction commit related to IDM da= tabase operations was not placed within a final() block. Any misconfigurati= on, or operation failure, could cause the database connection to remain ope= n. The fix ensures the transaction commit related to IDM database operation= s is placed within a final() block, which fixes the issue. - - - - - - JBEPP-1048= - - - Assignee is: hfnukal - JIRA is Closed - - A Cross-Site Scripting (XSS) vulnerability was discovered in t= he Edit Page > Container Title field. The vulnerability is fixed in this= release. (CVE-2011-4580) - - - - - - JBEPP-1049= - - Assignee is: theute JIRA is Closed - A Cross-site Scripting (XSS) vulnerability was discovered in t= he New Node label. The vulnerability has been removed in this release. (CVE= -2011-4580) - - - - - - JBEPP-1050= - - - Assignee is: theute - JIRA is Closed - - A Cross-site Scripting (XSS) vulnerability was discovered in t= he RSS reader gadget. The vulnerability has been fixed in this release. (CV= E-2011-4580) - - - - - - JBEPP-1067= - - - Assignee is: bdaw - JIRA is Closed - - Only users from the LDAP database were shown in organization m= anagement if LDAP did not support sorting. The fix changes the logging leve= l to INFO in PicketLink IDM. - - - - - - JBEPP-1082= - - - Assignee is: hfnukal - JIRA is Closed - - If gadget restrict access to specific group, it was accessible= for not members in Dashboard and page editing. -Now users cannot add restricted gadget. - - - - - - JBEPP-1148= - - - Assignee is: theute - JIRA is Closed - - Activating JRMP configuration in JBoss EPP 5.1.x (or EPP based pr= oducts) produced a large quantity of JMX/RMI logs in stdout/stderr. The JRM= P agent had logging set to FINE, which resulted in verbose log information.= The fix removes the embedded logger configuration, which results in the JB= oss Enterprise Application Platform server log configuration being used for= logging. + Removing the dashboard context from default-object.xml resulted i= n a Null Pointer Exception (NPE) when a user authenticated. The fix ensures= that a proper null check is performed at the dashboardContext =3D portalOb= jectContainer.getContext(dashboardContextId) call, which fixes the issue. - + - JBEPP-1150= + JBEPP-995 - Assignee is: mputz - JIRA is Closed - - An invisible navigation node was displayed in the Sitemap portlet= when the parent node was expanded (not with Expand All button). The workar= ound described in the linked JIRA has been implemented in this release, whi= ch corrects the originally reported issue. - - - - - - JBEPP-1167= - - Assignee is: theute JIRA is Closed - A problem with regard to the location of token keys prevented Gad= gets from working in load-balanced clustered portal environments. Token key= s have been moved to a location accessible by all load-balanced clustered p= ortal instances. Gadgets can now be used as intended. + IE 6 displayed "This page contains both secure and nonsecure= items" on every page when users were authenticated using SSL. While I= E6 was honoring the information it received in the header.jsp, this caused = unnecessary modal dialog boxes to display every time a page with mixed cont= ent was opened. The fix implements changes to the header.jsp to correctly d= etect when a user is authenticated, and prevents the dialog boxes from open= ing. - + - JBEPP-1196= + JBEPP-1118= - Assignee is: hfnukal - JIRA is Closed - - A problem with UploadService was causing the MIME type of .rtf fi= les extracted from DiskFileItem in Apache as "text/rtf". The valu= e should have been extracted as "application/rtf", which caused p= roblems for applications dependent on correct MIME type information. The fi= x corrects the MIME type encoding, and ensures .rtf files are set with the = MIME type "application/rtf". - = - - - - - - JBEPP-1221= - - - Assignee is: mwringe - JIRA is Closed - - A problem with the GroupManagement.java isAdministrator method ca= used a NullPointerException when the Organization Portlet is placed on a pa= ge and an anonymous user tries to access it. The fix changes the behavior o= f isAdministrator for anonymous users, which fixes the issue. - - - - - - JBEPP-1241= - - Assignee is: theute JIRA is Closed - A Cross-site Scripting (XSS) vulnerability was discovered in t= he UIFormDateTimeInput component. The vulnerability has been fixed in this = release. (CVE-2011-4580) - - - - - - JBEPP-1243= - - - Assignee is: theute - JIRA is Closed - - Group descriptions text entered by users was not properly prot= ected from XSS attacks. It was possible to execute arbitrary Javascript if = a user had permissions to enter a group description. The group description = field has been protected to not execute any Javascript, which resolves the = issue. (CVE-2011-4580) - - - - - - JBEPP-1293= - - - Assignee is: kenfinni - JIRA is Closed - - org.jboss.portletbridge.seam.SeamPhaseListenerWrapper.afterPhase(= ) did not correctly handle exceptions. Exceptions that typically occurred d= uring during afterPhase() were truncated (for example StaleObjectStateExcep= tion in Hibernate commit). The Seam exception handler was not notified of t= he truncated exceptions therefore the application moves to a next page inst= ead of an error page. The fix ensures org.jboss.portletbridge.seam.SeamPhas= eListenerWrapper.afterPhase() catches exceptions and passes them to Seam ex= ception handler (for example, org.jboss.seam.jsf.SeamPhaseListener). Becaus= e exceptions are handled correctly, the Seam exception handler displays and= error page given the appropriate conditions. + A bug in the HttpSession listener caused the ClusteredSession.inv= alidated() method to be called one during session validation, and again dur= ing the sessionDestroyed() call. Because the session was already invalidat= ed, an exception is raised at the second invalidation attempt. The fix to H= ttpSession removes the unnecessary second call, which fixes the issue. - + - JBEPP-1310= + JBEPP-1323= - Assignee is: hfnukal - JIRA is Closed - - If the Opera browser is used to access the portal home page, a Ja= vascript Uncaught exception is raised: "TypeError: 'Browser.setOp= acity' is not a function". The fix incorporates a verified custo= mer-submitted patch to Browser.js, which allows Opera browsers to access th= e portal home page. = - - - - - - JBEPP-1319= - - - Assignee is: claprun - JIRA is Closed - - If the WSRP consumer was refreshed and activated, WSRP selfv2 pre= vented the server from starting when it was rebooted. The only way to work = around this issue was to perform a force quit. The fix adds a &lt;value= -param&gt; configuration option to the main WSRP configuration. consume= rsInitDelay provides a way to specify a delayed start (configurable, in sec= onds) of the ConsumerRegistry, which prevents a deadlock situation while th= e self consumers wait for the producer WSDL to be published. - - - - - - JBEPP-1324= - - - Assignee is: hfnukal - JIRA is Closed - - It was found that the invoker servlets, deployed by default via -httpha-invoker, only performed access control on the HTTP GET and POST -methods, allowing remote attackers to make unauthenticated requests by -using different HTTP methods. Due to the second layer of authentication -provided by a security interceptor, this issue is not exploitable on -default installations unless an administrator has misconfigured the -security interceptor or disabled it. (CVE-2011-4085) - - - - - - JBEPP-1331= - - Assignee is: theute JIRA is Closed - When a portal host name contained the word "portal" in = the name, gadgets were not displayed and a TemplateRuntimeException would o= ccur. The fix adds functionality to several portal components which allows = for the word "portal" in the host name. - - - - - - JBEPP-1336= - - - Assignee is: theute - JIRA is Closed - - It was found that the GateIn Portal contained verb-specific se= curity constraints. As a result, authentication and authorization were only= correctly applied to requests made using the GET and POST HTTP verbs. The = GateIn Portal application does not allow a user to trigger any action using= HTTP verbs other than POST and GET, so this issue did not expose an exploi= table security flaw. As a defence-in-depth measure, the verb-specific secur= ity constraints have been removed. Authentication and authorization now cor= rectly apply to requests made using all HTTP verbs. + It was found that the invoker servlets, deployed by default vi= a httpha-invoker, only performed access control on the HTTP GET and POST me= thods, allowing remote attackers to make unauthenticated requests by using = different HTTP methods. Due to the second layer of authentication provided = by a security interceptor, this issue is not exploitable on default install= ations unless an administrator has misconfigured the security interceptor o= r disabled it. (CVE-2011-4085) - - - JBEPP-1351= - - - Assignee is: hfnukal - JIRA is Closed - - The org.gatein.sso.agent.login.SSOLoginModule contains the common= options "portal" and "realmName" as offered in other L= oginModule classes. In the packaged gatein-jboss-beans.xml, this login modu= le did not have these options. This caused problems when a customer wanted = to implement SSO on a different portal container (for example in ecmdemo). = The fix includes these common options in gatein-jboss-beans.xml, which reso= lves the issue. - - - - - - JBEPP-1357= - - - Assignee is: claprun - JIRA is Closed - - The Web Services for Remote Portlet (WSRP) configuration files fo= r consumers and producer were previously only looked for in the WSRP extens= ion archive. This resulted in extra configuration complexity for customers = who wanted to edit the configuration directives for WSRP consumers and prod= ucer. The fix implements changes to the WSRP integration point that will no= w also look for WSRP configuration files in the conf/gatein directory of th= e active JBoss AS profile. - - - - - - JBEPP-1361= - - - Assignee is: mposolda - JIRA is Closed - - The JBoss Clustered Single Sign On (SSO) Valve must authenticate = on all clustered nodes using the same password. The login process in Enterp= rise Portal Platform differed from normal authentication methods, and custo= mers had to bypass standard authentication by enabling BASIC authentication= , or patch login.jsp as described in the Reference Guide. The fix introduce= s PortalClusteredSSOSupportValve, which removes the patching and workaround= s customers had to implement in earlier versions of the product, and increa= ses overall platform security. - - - Modified: docs/enterprise/trunk/Release_Notes_Old/en-US/CP07_Release_Notes.= xml =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D --- docs/enterprise/trunk/Release_Notes_Old/en-US/CP07_Release_Notes.xml 20= 12-01-24 21:21:57 UTC (rev 14038) +++ docs/enterprise/trunk/Release_Notes_Old/en-US/CP07_Release_Notes.xml 20= 12-01-24 22:41:45 UTC (rev 14039) @@ -1,6 +1,6 @@ + %BOOK_ENTITIES; ]>
Modified: docs/enterprise/trunk/Tuning_Guide/en-US/Book_Info.xml =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D --- docs/enterprise/trunk/Tuning_Guide/en-US/Book_Info.xml 2012-01-24 21:21= :57 UTC (rev 14038) +++ docs/enterprise/trunk/Tuning_Guide/en-US/Book_Info.xml 2012-01-24 22:41= :45 UTC (rev 14039) @@ -5,11 +5,11 @@ ]> Tuning Guide - A guide to tuning the performance of JBoss Enterprise Portal P= latform 4.3. + For use with JBoss Enterprise Portal Platform 4.3. JBoss Enterprise Portal Platform 4.3 4.3.7 - 1 + 100 This Installation Guide documents tuning of JBoss Enterprise P= ortal Platform. Modified: docs/enterprise/trunk/Tuning_Guide/en-US/Revision_History.xml =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D --- docs/enterprise/trunk/Tuning_Guide/en-US/Revision_History.xml 2012-01-2= 4 21:21:57 UTC (rev 14038) +++ docs/enterprise/trunk/Tuning_Guide/en-US/Revision_History.xml 2012-01-2= 4 22:41:45 UTC (rev 14039) @@ -7,6 +7,20 @@ Revision History + + 4.3.7-100 + Tue Jan 24 2011 + + Jared + Morgan + jmorgan [at] redhat [dot] com + + + + Prepared for JBoss Enterprise Portal Platform 4.= 3.0 CP07 GA. + + + 1-1.5 Fri Jul 15 2011 Modified: docs/enterprise/trunk/User_Guide/en-US/Book_Info.xml =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D --- docs/enterprise/trunk/User_Guide/en-US/Book_Info.xml 2012-01-24 21:21:5= 7 UTC (rev 14038) +++ docs/enterprise/trunk/User_Guide/en-US/Book_Info.xml 2012-01-24 22:41:4= 5 UTC (rev 14039) @@ -7,7 +7,7 @@ JBoss Enterprise Portal Platform 4.3 4.3.7 - 1 + 100 This document is intended for those using JBoss Portal as End-Us= ers. This is a "Where do I Click?" Guide. Modified: docs/enterprise/trunk/User_Guide/en-US/Revision_History.xml =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D --- docs/enterprise/trunk/User_Guide/en-US/Revision_History.xml 2012-01-24 = 21:21:57 UTC (rev 14038) +++ docs/enterprise/trunk/User_Guide/en-US/Revision_History.xml 2012-01-24 = 22:41:45 UTC (rev 14039) @@ -7,6 +7,20 @@ + 4.3.7-100 + Tue Jan 24 2011 + + Jared + Morgan + jmorgan [at] redhat [dot] com + + + + Prepared for JBoss Enterprise Portal Platform 4.= 3.0 CP07 GA. + + + + 1-1.10 Fri Jul 15 2011 --===============7031343608682681462==--