Minutes of the MiniTOP on the 2012-05-29

Setting

The MiniTOP will be held via telco 22:00 CEST

Attendees: marcus, magu, uli, michael, dirk

Topics

(skip to agenda)

Action items from last meeting Meeting Action Items

Software/Assessment/ActionItems

Development, Deployment, Discussion

  • OAO, Ted

    bug #943 change OA admin/assurer text

    needs 2nd test -> Fabian, Marc, Alex? {g} / needs 2nd review -> Ted, rejected

    {-}

    uli, Ted

    bug #824 Org User cert fix Case study

    Organisation User Certificates: Need UI improvement for proper production usage

    {0}

    uli, ted

    bug #823 email address removal fix

    No warning when removing e-mail address from account that certificates will be revoked
    checked by 4, needs 2nd review, deploy
    rejected

    {-}

    inopiae

    bug #920 Join - single name only (eg Indonesian)

    details under bug number

    {0}

    uli

    bug #859 admin console interface

    feature request: show activity on an account in the admin interface
    rejected, certs login doesn't modify "modified" field

    {r}

    Michael

    bug #540

    p20111113 CPS #7.1.2 "Certificate Extensions" adjustments - testing
    uli, marcus: needs full cert create tests
    duplicate report to bug#978
    tested by 3, 2nd review done, transfered
    Ken reported: still has problems, bug kept open

    {0}

    gagern, NEO

    bug #440 Problem with subjectAltName (CSR, renew certs)

    There seems to be a problem with the subjectAltName. Dupes, missing entries, and more, rejected, needs further development

    {r}

    neo

    bug #1025 Domain Dispute issue

    disputes rc and rc2 var prob
    needs work

    {r}

    dirk

    bug #1054 0001054: Review the code regarding the new point calculation

    Thawte patch part II
    needs further work

    {r}

Software Assessors: Review 1 / add to cacert-devel, add to testserver

  • Software-Assessors task

Testing

  • Testers task

    neo

    bug #1004 Stats page improvement

    tested by 2, needs 2nd review

    {0}

    neo

    Bugs #1159 it might be possible to execute commands on the signing server

    {0}

    inopiae

    bug #1065 Wrong wording when sending mails during the assurance process

    {0}

    inopiae

    bug #1162 calcutate (the passwords) hash in php instead of in mysql

    create test scenarios for the software testers /!\
    Full testing /!\

    {0}

    inopiae

    bug #0028 Wrong language for you've been assured & [CAcert.org] Client Certificate emails

    {0}

    inopiae

    bug #988 TTP cap form deployment

    {0}

Software Assessors: 2nd Review, Bundle Package to Critical Team

  • Software-Assessors task

    Ted

    bug #500 Get contact mail adress after resolving test

    tested by 3, requires review

    {0}

    Ted

    bug #1140 Show if a test is passed in learnprogress

    tested by 3, requires review

    {0}

    magu

    bug #1131 Rename _all_ Policies from .php to .html and fix all links

    global policy directory maintenance and update

    {0}

    inopiae

    bug #1010 Reorder the view on organisation certificates

    tested by 3

    {0}

Software Assessors: Bundle Package to Critical Team

  • Software-Assessors task

    inopiae

    bug #1139 Add new fields to the database

    tests through #500 and #1140, 2nd review done, requires transfer

    {0}

Awaiting Response from Critical Team

  • inopiae

    bug #411 Wrong text is made into link

    {g}


Agenda

1. Preface

  1. dirk topics
    1. Cebit brainstorming
      • dirk: request for events report
      • (2012-03-27) Marcus awaiting translation from Marc
      • (2012-04-03) Marcus will do upcoming (easter) weekend
      • (2012-04-17) no update
      • (2012-04-24) no update
  2. Marcus bugs list

2. bug #1023 Testing (6.php)

  1. Thawte points removal, final step
    • relates to 6.php
    • this also relates to TTP
    • dirk will work on this last weekend (2012-01-21)
    • current state: not yet finished
      • expected finishing? upcoming weekend (2012-01-23 to 2012-01-30)
      • not finished, upcoming weekend 2012-02-06?
      • not finished, last weekend 2012-03-12?
      • 2012-03-13: new bug#1023 bug#1023

      • transfered to git cacert
      • to test:
        • assure someone
        • w/ and w/o ttp
        • in all variations
      • Added to testserver Tue 13.3., Wed 14.3.

      dirk

      bug #1023 Consolidate changes into the Assure Someone page

      6.php global re-design project
      assurance, wot area (Thawte points removal effective)

      {0}

    • current state: patch removed from testserver, needs work (DEV)
    • (2012-03-27) back on testserver: bug #1023 (6.php), has a bug, needs work
    • 2 new bugs within meeting 2012-03-27
    • (2012-04-03) bugs analyze, empty results analyse, new patch transfered to testserver
    • current state 2012-04-17
      •   * dirk: didn't we concluded 14 days ago, that the current patch state is the revision similar on the production system
          * potential bugs on production system can be identified against wot.php on testserver (-> diff wot.php, if no difference bugs are also in production system)
          * Michael: diff is empty, this means wot.php is identical between production and testserver
          * Michael: didn't pushed one patch, as it has at least one error
          * Michael: fix and push to git / testserver, patch is transfered to testserver
          * testing: failures occured
          * last time we've added method transfer
           * if board=1, method empty -> results in garbage in database
          * new bug, that methods aren't checked that needs to be checked [[https://bugs.cacert.org/view.php?id=1032|bug#1032]]
          * req by Marcus to add maxpoints limit definition: 35 assurance points (by AP) in a f2f meeting, upto 50 assurance points possible though a subpolicy (currently none available), new bug [[https://bugs.cacert.org/view.php?id=1033|bug#1033]]
    • #1033 passed to production
    • 2012-04-24: 2nd review by neo bug #1023 (6.php) (next time)

    • 2012-05-05: dirk_: @neo ... is the review of 6.php done? / NEOatNHNG: almost
    • bug #1023 Testing (6.php)
      1. did some test and fixed small remaining bugs (removed dropdown for method when only assuer, new text for the date field as it is now prefilled with the actual date if started for the first time in a session)
      2. magu and marcus tested the last version, patch ready to review by dirk and deploy to production
      3. while testing on the bug we discovered a strage behavior of the WebDB and filed a dispute to this matter.
        • blocker

3. 2nd review of about 7 patches

4. Permissions Review

  1. dispute cases
    • new bug: bug #1038 Provide a script for board/tverify reset flags by arbitration a20110118.1

    • re bug #1003 Permissions review script, to incorporate new intermediate ruling

  2. Permissions review and revoke of board and tverify flag (bug #1003 and bug #1038)

    • Michael run the permission preview script. After finding some formating stuff and fixing it, the script was run a second time.
    • Afterwards Michael run the script revoke of board and tverify flag. The executing report was added as private to bug #1003

    • All tester please review your flags and mails on the test server and report ONLY in bug #1003.

5. next meeting

Minutes

  1. Cebit events report
    • request for events report - no update
    • uli: marcus please translate by yourself
  2. Marcus bugs list
    • bug#1023 related

      • bug#583 "Assure Somebody" allows future assurance dates

      • bug#648 send message from Assurer to Member

      • bug#802 Name parts should be designated in assurance form

      • bug#870 My Details - My Points show bugus time stamp

      • bug#914 Information about Practice on Name while entering an Assurance

      • bug#930 types wrong points in "Assure Someone" form

      • bug#931 Date of assurance in future don't throw any exception

      • bug#998 When entering an assurance in the WoT one line of the form the suffix is given in another line the suffix is missing.

      • bug#1000 Entering an assurance into the system after searching for an assurer causes a pre-filled location field

    • Others
      • bug#118 Secure TTP Form upload - outdated, conflicts with new procedure, closed

      • bug#428 Reminder language-drop-down-box doesn't keep "English" if you choose it again - cannot be reproduced, tested by 2, closed

      • bug#489 Pb on rewarding 2 points for an assurance

      • bug#567 case sensitive email: tested by 2, cannot be confirmed, closed

      • bug#767 Single-quotes escaped in Web-of-Trust contact form.

  3. Michael "Black Jack"
    • continued
    • win7 part finished, error messages needs some work
    • winxp part needs work
  4. congratulation to Michael in becoming Software-Assessment t/l
  5. bug#1023

    • dirk: finished, later there was one text correction, not yet reviewed by dirk
    • text change breaks translations
    • what are the next steps for thawte points revoke?
      • points settings codes eg 50 pts open gpg/pgp, which certs avail by how many pts
      • 15.php needs rename to 10.php
    • dirk: diff since last week is ok, 2nd review ok
    • to michael: please transfer
  6. Permissions Review - needs 2nd review (red flag raised) {-}
    • fix available, tested, next run close before
    • last run: 2012-03-30, next run 2012-06-30
    • to dirk: 2nd review bug#1003

  7. Bug from last week
    • uli: from arbitration PoV: if its so seriosly, we have to close webdb
    • neo: recommendation: to disable java script for all support engineers
    • uli: centralize through sql class project
      • 80% can be fixed with centralized class project code
      • needs to be implemented to all sql statements, complete codebase review
  8. next meeting 2012-06-05

Fixed Action Items since last or within meeting

Action Items New

Action items: Meeting Action Items