Tuesday, 2018-06-26

*** mordred has quit IRC01:49
*** jamesmcarthur has joined #storyboard01:55
*** jamesmcarthur has quit IRC02:00
*** mordred has joined #storyboard02:07
*** noama has joined #storyboard03:34
*** diablo_rojo has quit IRC04:37
*** lifeless has joined #storyboard05:16
*** strigazi has quit IRC05:17
*** strigazi has joined #storyboard05:19
*** strigazi_ has joined #storyboard05:24
*** strigazi has quit IRC05:27
*** udesale has joined #storyboard05:44
*** openstackgerrit has quit IRC06:04
*** noam has joined #storyboard07:01
*** noama has quit IRC07:04
*** florianf has joined #storyboard07:24
*** florianf has quit IRC07:25
*** tosky has joined #storyboard07:41
*** noam__ has joined #storyboard07:45
*** noam has quit IRC07:46
SotKthanks dhellmann!07:51
*** jamesmcarthur has joined #storyboard08:03
*** jpich has joined #storyboard08:05
*** jamesmcarthur has quit IRC08:08
*** noam__ has quit IRC08:13
*** lifeless has quit IRC09:16
*** dtantsur|afk is now known as dtantsur09:18
*** strigazi_ is now known as strigazi09:47
*** udesale has quit IRC11:33
dhellmannwoot!12:33
*** dtantsur is now known as dtantsur|brb13:22
*** frickler has quit IRC13:26
*** frickler has joined #storyboard13:26
*** udesale has joined #storyboard13:31
SotKoh, I wonder if the pecan dev server unquotes the path before splitting it to pass to the _route method of controllers14:07
SotKin answer to my wondering from last night14:07
*** jamesmcarthur_ has joined #storyboard14:12
*** dtantsur|brb is now known as dtantsur14:45
fungihrm, maybe. i played around with all manner of possible hacks in _route() last night, to no avail14:52
fungii found plenty of ways to completely break the projects method, but none to properly unquote the project argument14:53
fungiSotK: you have ssh/sudo access on storyboard-dev... editing /usr/local/lib/python2.7/dist-packages/storyboard/api/v1/projects.py in place and then doing a `sudo service apache2 restart` should allow you to evaluate it if you get a chance14:54
fungii was testing like `wget --no-check-certificate -qO- https://storyboard-dev.openstack.org/api/v1/projects/openstack%2Fpatrole`14:55
*** jamesmca_ has joined #storyboard15:12
*** udesale has quit IRC16:09
*** jpich has quit IRC16:28
*** jamesmca_ has quit IRC16:28
*** jamesmca_ has joined #storyboard16:29
*** jamesmca_ has quit IRC16:34
*** dtantsur is now known as dtantsur|afk17:15
*** jamesmcarthur_ has quit IRC19:01
*** jamesmcarthur has joined #storyboard19:56
*** jamesmcarthur has quit IRC20:17
*** noama has joined #storyboard20:18
*** jamesmcarthur has joined #storyboard20:34
dhellmannis it possible to specify that a task applies to a certain branch? I feel like I saw something about that in the schema...20:44
dhellmannfungi, SotK : why are you quoting the / in the URL there?20:45
dhellmannoh, that's an API link20:45
dhellmannI guess people are less likely to type those in by hand20:46
fungidhellmann: you can supply non-escaped shashes in project names directly to the api and it handles that fine20:50
dhellmannoh, ok, good20:50
fungiproblem is storyboard-webclient wants to do url escaping on parameters which are piped through it20:50
fungiso the current idea is to have the api also support unescaping those if necessary20:51
dhellmannis it doing that itself, or is that done by some library it uses?20:51
fungibut something's not quite right (yet) with the implementation there20:51
fungigood question, i'm not quite sure what causes the initial escaping. could be apache itself even?20:51
fungii guess i could look at the apache access log to find out. checking20:52
fungi2001:470:e0d6:0:96de:80ff:feec:f9e7 - - [26/Jun/2018:20:53:48 +0000] "GET /api/v1/projects/openstack%2Fpatrole HTTP/1.1" 404 732 "https://storyboard.openstack.org/" "Mozilla/5.0 (X11; Linux x86_64; rv:60.0) Gecko/20100101 Firefox/60.0"20:54
fungiso i guess the api is encapsulating there20:54
fungier, i mean the webclient is encapsulating20:54
fungiwhen hitting the api endpoint20:55
dhellmannI wonder if we could just make it stop doing that in this case20:55
dhellmannmaybe that's a bad idea from a security standpoint20:56
persiaGiven the amount of fussing that was involved in trying to get everything to be quoted in the past, it probably makes sense to carefully dequote those few strings where "dangerous" characters may appear.21:22
*** noama has quit IRC21:28
fungiyeah, i'm okay with the current approach if we can figure out all the right places where we need unquoting. apparently https://review.openstack.org/577081 just wasn't quite enough21:28
*** lifeless has joined #storyboard21:38
*** jamesmcarthur has quit IRC21:54
*** tosky has quit IRC23:08

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!