Re: [Tiki-devel] God, save us from secdb and help on tarball checking
Fabio Montefuscolo <[email protected]>
| Newsgroups | gmane.comp.cms.tiki.devel |
|---|---|
| Message-ID | <CAF4KPBQxaX4VM0JWhUqvo==n6-zWdn1_Y5q_RJ-LQvt0reGzwA@mail.gmail.com> |
Any help is welcome https://gitlab.com/tikiwiki/tiki/-/merge_requests/868 On Wed, Aug 25, 2021 at 8:43 AM Fabio Montefuscolo < [email protected]> wrote: > Does anyone know if we ever used that severity column? > > Thanks > > On Tue, Aug 24, 2021 at 12:40 AM Fabio Montefuscolo < > [email protected]> wrote: > >> Is this the only script using that tiki-admin_security.php ? >> >> On Tue, Aug 24, 2021 at 12:39 AM Fabio Montefuscolo < >> [email protected]> wrote: >> >>> How to use secdb nowadays? >>> >>> On Mon, Aug 23, 2021 at 2:37 PM Jonny Bradley via TikiWiki-devel < >>> [email protected]> wrote: >>> >>>> Sounds good to me as long as we can replicate the functionality within >>>> tiki in php (so without a new dependency on md5sum), which should be >>>> possible I’d have thought. >>>> >>>> We recently escaped an issue about duplicated rows conflicting with a >>>> new shorter index key on the file path due to utf8mb4, but luckily it was >>>> only the old zendsearch library which named removing anyway. But next time… >>>> >>>> So +1 🤓 >>>> >>>> jonny >>>> >>>> On 23 Aug 2021, at 18:12, Fabio Montefuscolo < >>>> [email protected]> wrote: >>>> >>>> >>>> What would be legacy files? ... for each tiki version, a secdb file >>>> would be generated with hash of all files in the release. I don't remember >>>> of using secdb in Tiki uprades using svn/git. >>>> >>>> On Mon, Aug 23, 2021 at 1:44 PM Brendan Ferguson <[email protected]> >>>> wrote: >>>> >>>>> I think the way secdb works is that every install adds or updates the >>>>> new files into the database. So if you had several older versions of Tiki >>>>> installed in the past, legacy files show up as legacy, with a legitimate >>>>> check. Will your changes preserve this behaviour? >>>>> >>>>> Brendan >>>>> >>>>> >>>>> >>>>> On Aug 23, 2021, at 12:24 PM, Fabio Montefuscolo < >>>>> [email protected]> wrote: >>>>> >>>>> Hello all! >>>>> >>>>> I am coming back with the proposal of having secdb as regular text >>>>> file, compatible to md5sum linux tool. >>>>> >>>>> Actually, what I do to test tarballs other than running the installer >>>>> is getting the md5sum compatible file. To that, I have to load the secdb >>>>> into MySQL and then dump it again. More precisely >>>>> >>>>> 1. cat db/tiki-secdb_23.0_mysql.sql | docker-compose exec -T db >>>>> mysql -ptikiwiki tikiwiki >>>>> 2. echo "select concat(md5_value, ' ', filename) from tiki_secdb;" >>>>> | docker-compose exec -T db mysql -ptikiwiki tikiwiki -N -s > ../calc >>>>> 3. md5sum -c ../calc >>>>> >>>>> >>>>> I wonder if we can reduce the steps above to a single step and at the >>>>> same time, we free the user from loading 5,1Mb table into MySQL. If for >>>>> some reason thinks his checksum file is corrupted, he always can grab a >>>>> fresh one from our gitlab. The latest one for 23.0 for example is >>>>> https://gitlab.com/tikiwiki/tiki/-/raw/tags/23.0/db/tiki-secdb_23.0_mysql.sql >>>>> . >>>>> >>>>> I agree it is good to have a checking tool, but not in MySQL, that >>>>> impacts the installation process and also the backup process. >>>>> >>>>> If windows is a concern, we can find a solution to check that on >>>>> Windows. >>>>> >>>>> What do you think? >>>>> >>>>> Thanks >>>>> _______________________________________________ >>>>> TikiWiki-devel mailing list >>>>> [email protected] >>>>> https://lists.sourceforge.net/lists/listinfo/tikiwiki-devel >>>>> >>>>> >>>>> _______________________________________________ >>>>> TikiWiki-devel mailing list >>>>> [email protected] >>>>> https://lists.sourceforge.net/lists/listinfo/tikiwiki-devel >>>>> >>>> _______________________________________________ >>>> TikiWiki-devel mailing list >>>> [email protected] >>>> https://lists.sourceforge.net/lists/listinfo/tikiwiki-devel >>>> >>>> _______________________________________________ >>>> TikiWiki-devel mailing list >>>> [email protected] >>>> https://lists.sourceforge.net/lists/listinfo/tikiwiki-devel >>>> >>> _______________________________________________ TikiWiki-devel mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/tikiwiki-devel