You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@shindig.apache.org by Stanton Sievers <si...@gmail.com> on 2011/10/26 15:51:59 UTC

Review Request: Security tokens aren't returned on the iframeurl as part of a metadata response when the gadget uses OAuth

-----------------------------------------------------------
This is an automatically generated e-mail. To reply, visit:
https://reviews.apache.org/r/2572/
-----------------------------------------------------------

Review request for shindig and Brian Lillie.


Summary
-------

If a gadget uses OAuth but requires no other features that depend on the "security-token" feature, a security token is not returned on the iframeurl when it should be. This stems from the fact that ModulePrefs.getViewFeatures() doesn't pick up the artificially added "security-token" feature that gets added by the FeatureVisitor if the OAuthVisitors found oauth tags. 


Diffs
-----

  http://svn.apache.org/repos/asf/shindig/trunk/java/gadgets/src/main/java/org/apache/shindig/gadgets/spec/ModulePrefs.java 1189151 
  http://svn.apache.org/repos/asf/shindig/trunk/java/gadgets/src/test/java/org/apache/shindig/gadgets/spec/ModulePrefsTest.java 1189151 

Diff: https://reviews.apache.org/r/2572/diff


Testing
-------

Updated existing JUnits and added new JUnits.


Thanks,

Stanton


Re: Review Request: Security tokens aren't returned on the iframeurl as part of a metadata response when the gadget uses OAuth

Posted by Stanton Sievers <si...@gmail.com>.
-----------------------------------------------------------
This is an automatically generated e-mail. To reply, visit:
https://reviews.apache.org/r/2572/
-----------------------------------------------------------

(Updated 2011-10-27 12:06:49.082022)


Review request for shindig and Brian Lillie.


Changes
-------

Sorry Ryan, I thought I had added JIRA.  Patch included in the JIRA and linked to in the review.


Summary
-------

If a gadget uses OAuth but requires no other features that depend on the "security-token" feature, a security token is not returned on the iframeurl when it should be. This stems from the fact that ModulePrefs.getViewFeatures() doesn't pick up the artificially added "security-token" feature that gets added by the FeatureVisitor if the OAuthVisitors found oauth tags. 


This addresses bug SHINDIG-1651.
    https://issues.apache.org/jira/browse/SHINDIG-1651


Diffs
-----

  http://svn.apache.org/repos/asf/shindig/trunk/java/gadgets/src/main/java/org/apache/shindig/gadgets/spec/ModulePrefs.java 1189151 
  http://svn.apache.org/repos/asf/shindig/trunk/java/gadgets/src/test/java/org/apache/shindig/gadgets/spec/ModulePrefsTest.java 1189151 

Diff: https://reviews.apache.org/r/2572/diff


Testing
-------

Updated existing JUnits and added new JUnits.


Thanks,

Stanton


Re: Review Request: Security tokens aren't returned on the iframeurl as part of a metadata response when the gadget uses OAuth

Posted by Brian Lillie <br...@us.ibm.com>.
-----------------------------------------------------------
This is an automatically generated e-mail. To reply, visit:
https://reviews.apache.org/r/2572/#review2862
-----------------------------------------------------------


LGTM

- Brian


On 2011-10-26 13:51:59, Stanton Sievers wrote:
> 
> -----------------------------------------------------------
> This is an automatically generated e-mail. To reply, visit:
> https://reviews.apache.org/r/2572/
> -----------------------------------------------------------
> 
> (Updated 2011-10-26 13:51:59)
> 
> 
> Review request for shindig and Brian Lillie.
> 
> 
> Summary
> -------
> 
> If a gadget uses OAuth but requires no other features that depend on the "security-token" feature, a security token is not returned on the iframeurl when it should be. This stems from the fact that ModulePrefs.getViewFeatures() doesn't pick up the artificially added "security-token" feature that gets added by the FeatureVisitor if the OAuthVisitors found oauth tags. 
> 
> 
> Diffs
> -----
> 
>   http://svn.apache.org/repos/asf/shindig/trunk/java/gadgets/src/main/java/org/apache/shindig/gadgets/spec/ModulePrefs.java 1189151 
>   http://svn.apache.org/repos/asf/shindig/trunk/java/gadgets/src/test/java/org/apache/shindig/gadgets/spec/ModulePrefsTest.java 1189151 
> 
> Diff: https://reviews.apache.org/r/2572/diff
> 
> 
> Testing
> -------
> 
> Updated existing JUnits and added new JUnits.
> 
> 
> Thanks,
> 
> Stanton
> 
>


Re: Review Request: Security tokens aren't returned on the iframeurl as part of a metadata response when the gadget uses OAuth

Posted by Henry Saputra <hs...@apache.org>.
-----------------------------------------------------------
This is an automatically generated e-mail. To reply, visit:
https://reviews.apache.org/r/2572/#review2865
-----------------------------------------------------------

Ship it!


+1

- Henry


On 2011-10-26 13:51:59, Stanton Sievers wrote:
> 
> -----------------------------------------------------------
> This is an automatically generated e-mail. To reply, visit:
> https://reviews.apache.org/r/2572/
> -----------------------------------------------------------
> 
> (Updated 2011-10-26 13:51:59)
> 
> 
> Review request for shindig and Brian Lillie.
> 
> 
> Summary
> -------
> 
> If a gadget uses OAuth but requires no other features that depend on the "security-token" feature, a security token is not returned on the iframeurl when it should be. This stems from the fact that ModulePrefs.getViewFeatures() doesn't pick up the artificially added "security-token" feature that gets added by the FeatureVisitor if the OAuthVisitors found oauth tags. 
> 
> 
> Diffs
> -----
> 
>   http://svn.apache.org/repos/asf/shindig/trunk/java/gadgets/src/main/java/org/apache/shindig/gadgets/spec/ModulePrefs.java 1189151 
>   http://svn.apache.org/repos/asf/shindig/trunk/java/gadgets/src/test/java/org/apache/shindig/gadgets/spec/ModulePrefsTest.java 1189151 
> 
> Diff: https://reviews.apache.org/r/2572/diff
> 
> 
> Testing
> -------
> 
> Updated existing JUnits and added new JUnits.
> 
> 
> Thanks,
> 
> Stanton
> 
>


Re: Review Request: Security tokens aren't returned on the iframeurl as part of a metadata response when the gadget uses OAuth

Posted by Paul Lindner <li...@inuus.com>.
-----------------------------------------------------------
This is an automatically generated e-mail. To reply, visit:
https://reviews.apache.org/r/2572/#review2863
-----------------------------------------------------------

Ship it!


LGTM


- Paul


On 2011-10-26 13:51:59, Stanton Sievers wrote:
> 
> -----------------------------------------------------------
> This is an automatically generated e-mail. To reply, visit:
> https://reviews.apache.org/r/2572/
> -----------------------------------------------------------
> 
> (Updated 2011-10-26 13:51:59)
> 
> 
> Review request for shindig and Brian Lillie.
> 
> 
> Summary
> -------
> 
> If a gadget uses OAuth but requires no other features that depend on the "security-token" feature, a security token is not returned on the iframeurl when it should be. This stems from the fact that ModulePrefs.getViewFeatures() doesn't pick up the artificially added "security-token" feature that gets added by the FeatureVisitor if the OAuthVisitors found oauth tags. 
> 
> 
> Diffs
> -----
> 
>   http://svn.apache.org/repos/asf/shindig/trunk/java/gadgets/src/main/java/org/apache/shindig/gadgets/spec/ModulePrefs.java 1189151 
>   http://svn.apache.org/repos/asf/shindig/trunk/java/gadgets/src/test/java/org/apache/shindig/gadgets/spec/ModulePrefsTest.java 1189151 
> 
> Diff: https://reviews.apache.org/r/2572/diff
> 
> 
> Testing
> -------
> 
> Updated existing JUnits and added new JUnits.
> 
> 
> Thanks,
> 
> Stanton
> 
>


Re: Review Request: Security tokens aren't returned on the iframeurl as part of a metadata response when the gadget uses OAuth

Posted by Ryan Baxter <rb...@gmail.com>.

> On 2011-10-27 00:08:02, Ryan Baxter wrote:
> > LGTM, I found the JIRA but can you attach the patch to it?
> > https://issues.apache.org/jira/browse/SHINDIG-1651

Committed revision 1189772.


- Ryan


-----------------------------------------------------------
This is an automatically generated e-mail. To reply, visit:
https://reviews.apache.org/r/2572/#review2871
-----------------------------------------------------------


On 2011-10-27 12:06:49, Stanton Sievers wrote:
> 
> -----------------------------------------------------------
> This is an automatically generated e-mail. To reply, visit:
> https://reviews.apache.org/r/2572/
> -----------------------------------------------------------
> 
> (Updated 2011-10-27 12:06:49)
> 
> 
> Review request for shindig and Brian Lillie.
> 
> 
> Summary
> -------
> 
> If a gadget uses OAuth but requires no other features that depend on the "security-token" feature, a security token is not returned on the iframeurl when it should be. This stems from the fact that ModulePrefs.getViewFeatures() doesn't pick up the artificially added "security-token" feature that gets added by the FeatureVisitor if the OAuthVisitors found oauth tags. 
> 
> 
> This addresses bug SHINDIG-1651.
>     https://issues.apache.org/jira/browse/SHINDIG-1651
> 
> 
> Diffs
> -----
> 
>   http://svn.apache.org/repos/asf/shindig/trunk/java/gadgets/src/main/java/org/apache/shindig/gadgets/spec/ModulePrefs.java 1189151 
>   http://svn.apache.org/repos/asf/shindig/trunk/java/gadgets/src/test/java/org/apache/shindig/gadgets/spec/ModulePrefsTest.java 1189151 
> 
> Diff: https://reviews.apache.org/r/2572/diff
> 
> 
> Testing
> -------
> 
> Updated existing JUnits and added new JUnits.
> 
> 
> Thanks,
> 
> Stanton
> 
>


Re: Review Request: Security tokens aren't returned on the iframeurl as part of a metadata response when the gadget uses OAuth

Posted by Ryan Baxter <rb...@gmail.com>.
-----------------------------------------------------------
This is an automatically generated e-mail. To reply, visit:
https://reviews.apache.org/r/2572/#review2871
-----------------------------------------------------------

Ship it!


LGTM, I found the JIRA but can you attach the patch to it?
https://issues.apache.org/jira/browse/SHINDIG-1651

- Ryan


On 2011-10-26 13:51:59, Stanton Sievers wrote:
> 
> -----------------------------------------------------------
> This is an automatically generated e-mail. To reply, visit:
> https://reviews.apache.org/r/2572/
> -----------------------------------------------------------
> 
> (Updated 2011-10-26 13:51:59)
> 
> 
> Review request for shindig and Brian Lillie.
> 
> 
> Summary
> -------
> 
> If a gadget uses OAuth but requires no other features that depend on the "security-token" feature, a security token is not returned on the iframeurl when it should be. This stems from the fact that ModulePrefs.getViewFeatures() doesn't pick up the artificially added "security-token" feature that gets added by the FeatureVisitor if the OAuthVisitors found oauth tags. 
> 
> 
> Diffs
> -----
> 
>   http://svn.apache.org/repos/asf/shindig/trunk/java/gadgets/src/main/java/org/apache/shindig/gadgets/spec/ModulePrefs.java 1189151 
>   http://svn.apache.org/repos/asf/shindig/trunk/java/gadgets/src/test/java/org/apache/shindig/gadgets/spec/ModulePrefsTest.java 1189151 
> 
> Diff: https://reviews.apache.org/r/2572/diff
> 
> 
> Testing
> -------
> 
> Updated existing JUnits and added new JUnits.
> 
> 
> Thanks,
> 
> Stanton
> 
>