<?xml version="1.0"?><?xml-stylesheet type="text/xsl" href="http://www.codeplex.com/rss.xsl"?><rss version="2.0"><channel><title>P I</title><link>http://www.codeplex.com/pi/Project/ProjectRss.aspx</link><description>P. I.</description><item><title>Source code checked in, #11597</title><link>http://www.codeplex.com/pi/SourceControl/ListDownloadableCommits.aspx</link><description>Fix for permissions problem &amp;#40;regular user could not access root site properties&amp;#41;</description><author>DaveMo</author><pubDate>Sun, 08 Jun 2008 23:43:24 GMT</pubDate><guid isPermaLink="false">Source code checked in, #11597 20080608114324P</guid></item><item><title>Source code checked in</title><link>http://www.codeplex.com/pi/SourceControl/ListDownloadableCommits.aspx</link><description>Tidy up code for external release</description><author>DaveMo</author><pubDate>Wed, 12 Mar 2008 03:07:56 GMT</pubDate><guid isPermaLink="false">Source code checked in 20080312030756A</guid></item><item><title>Source code checked in</title><link>http://www.codeplex.com/pi/SourceControl/ListDownloadableCommits.aspx</link><description>Fix for build break</description><author>DaveMo</author><pubDate>Tue, 11 Mar 2008 03:52:29 GMT</pubDate><guid isPermaLink="false">Source code checked in 20080311035229A</guid></item><item><title>COMMENTED ISSUE: POST: AEU broken</title><link>http://www.codeplex.com/pi/WorkItem/View.aspx?WorkItemId=5547</link><description>Trying to add a new &amp;#40;unprovisioned&amp;#41; user to a page but when I click on the provision link I get &amp;#34;General access denied error&amp;#34;. ADAM is on the same box as SP but it is using the service account as SQL is on a diff box. The user IS added to ADAM and appears in the to be approved list but has &amp;#34;No Requestor&amp;#34; in the requestor field.&lt;br /&gt;Comments: ** Comment from web user: KevinE ** &lt;p&gt;Line 510 of ExternalCollaboration is throwing an access denied exception &amp;#40;um.setProvisioner&amp;#41;&lt;/p&gt;</description><author>KevinE</author><pubDate>Fri, 29 Feb 2008 21:53:30 GMT</pubDate><guid isPermaLink="false">COMMENTED ISSUE: POST: AEU broken 20080229095330P</guid></item><item><title>CREATED ISSUE: POST: AEU broken</title><link>http://www.codeplex.com/pi/WorkItem/View.aspx?WorkItemId=5547</link><description>Trying to add a new &amp;#40;unprovisioned&amp;#41; user to a page but when I click on the provision link I get &amp;#34;General access denied error&amp;#34;. ADAM is on the same box as SP but it is using the service account as SQL is on a diff box. The user IS added to ADAM and appears in the to be approved list but has &amp;#34;No Requestor&amp;#34; in the requestor field.&lt;br /&gt;</description><author>KevinE</author><pubDate>Fri, 29 Feb 2008 20:39:19 GMT</pubDate><guid isPermaLink="false">CREATED ISSUE: POST: AEU broken 20080229083919P</guid></item><item><title>Source code checked in</title><link>http://www.codeplex.com/pi/SourceControl/ListDownloadableCommits.aspx</link><description>First stab at removing all traces of Microsoft from code.  Also, changed GUIDs for installer package and product.</description><author>billcan</author><pubDate>Fri, 29 Feb 2008 01:53:16 GMT</pubDate><guid isPermaLink="false">Source code checked in 20080229015316A</guid></item><item><title>Source code checked in</title><link>http://www.codeplex.com/pi/SourceControl/ListDownloadableCommits.aspx</link><description>make the cUserManager class contain reverts and add some helper routines.  Modify web parts to be more impersonate-agnostic.  </description><author>jeffreyhamblin</author><pubDate>Fri, 29 Feb 2008 00:12:16 GMT</pubDate><guid isPermaLink="false">Source code checked in 20080229121216A</guid></item><item><title>CREATED ISSUE: SEC: UM delete user doesn't remove users from sites</title><link>http://www.codeplex.com/pi/WorkItem/View.aspx?WorkItemId=5487</link><description>When a user request is denied they are removed from any sites they had been added too. However when a user is deleted using the User Manager they are NOT removed from any sites.&lt;br /&gt;</description><author>KevinE</author><pubDate>Fri, 22 Feb 2008 23:54:49 GMT</pubDate><guid isPermaLink="false">CREATED ISSUE: SEC: UM delete user doesn't remove users from sites 20080222115449P</guid></item><item><title>CLOSED ISSUE: SEC: HTML Encode for Update my profile/User Manager</title><link>http://www.codeplex.com/pi/WorkItem/View.aspx?WorkItemId=5468</link><description>We need to make sure input from the user is not displayed unfiltered on the admin&amp;#39;s browser.&lt;br /&gt;Comments: Verified. Build 9687</description><author>KevinE</author><pubDate>Fri, 22 Feb 2008 22:33:28 GMT</pubDate><guid isPermaLink="false">CLOSED ISSUE: SEC: HTML Encode for Update my profile/User Manager 20080222103328P</guid></item><item><title>CLOSED ISSUE: SEC: Old password can match new password</title><link>http://www.codeplex.com/pi/WorkItem/View.aspx?WorkItemId=5466</link><description>We are using the wrong change password method on changeqa...&lt;br /&gt;Comments: Verified. Build 9687</description><author>KevinE</author><pubDate>Fri, 22 Feb 2008 22:32:34 GMT</pubDate><guid isPermaLink="false">CLOSED ISSUE: SEC: Old password can match new password 20080222103234P</guid></item><item><title>CLOSED ISSUE: SEC: Cross-Site-Scripting issue, Update My Account Profile page.</title><link>http://www.codeplex.com/pi/WorkItem/View.aspx?WorkItemId=5486</link><description>The Update My Account Profile page is allowing HTML code to be input in the profile data and displayed on the User Manager.&lt;br /&gt;Comments: Verified. Build 9687</description><author>KevinE</author><pubDate>Fri, 22 Feb 2008 22:26:32 GMT</pubDate><guid isPermaLink="false">CLOSED ISSUE: SEC: Cross-Site-Scripting issue, Update My Account Profile page. 20080222102632P</guid></item><item><title>CREATED ISSUE: SEC: Cross-Site-Scripting issue, Update My Account Profile page.</title><link>http://www.codeplex.com/pi/WorkItem/View.aspx?WorkItemId=5486</link><description>The Update My Account Profile page is allowing HTML code to be input in the profile data and displayed on the User Manager.&lt;br /&gt;</description><author>KevinE</author><pubDate>Fri, 22 Feb 2008 22:26:21 GMT</pubDate><guid isPermaLink="false">CREATED ISSUE: SEC: Cross-Site-Scripting issue, Update My Account Profile page. 20080222102621P</guid></item><item><title>CLOSED ISSUE: SEC: Can change password without entering old password</title><link>http://www.codeplex.com/pi/WorkItem/View.aspx?WorkItemId=5467</link><description>On the update profile page.&lt;br /&gt;Comments: Verified. Build 9687</description><author>KevinE</author><pubDate>Fri, 22 Feb 2008 22:22:25 GMT</pubDate><guid isPermaLink="false">CLOSED ISSUE: SEC: Can change password without entering old password 20080222102225P</guid></item><item><title>CREATED ISSUE: SEC: Min age password policy</title><link>http://www.codeplex.com/pi/WorkItem/View.aspx?WorkItemId=5475</link><description>If the domain password policy has a minimum age then the user&amp;#39;s CANNOT change their password until that min age has expired. This will effect our first time login process, especially if user workflow is turned off. Basically the scenario is a user get&amp;#39;s added to a site &amp;#40;approved if WF on&amp;#41; and before the min age has expired they try to login for the first time. ADAM will not allow them too reset their password when they get to the Update Profile part of their first time login. If everybody will have a day or more gap between creating new users and their first login this is a non issue.&lt;br /&gt;</description><author>KevinE</author><pubDate>Thu, 21 Feb 2008 01:00:48 GMT</pubDate><guid isPermaLink="false">CREATED ISSUE: SEC: Min age password policy 20080221010048A</guid></item><item><title>Source code checked in</title><link>http://www.codeplex.com/pi/SourceControl/ListDownloadableCommits.aspx</link><description>Removed reference for ActiveDS.</description><author>billcan</author><pubDate>Wed, 20 Feb 2008 19:53:27 GMT</pubDate><guid isPermaLink="false">Source code checked in 20080220075327P</guid></item><item><title>CREATED ISSUE: SEC: HTML Encode for Update my profile/User Manager</title><link>http://www.codeplex.com/pi/WorkItem/View.aspx?WorkItemId=5468</link><description>We need to make sure input from the user is not displayed unfiltered on the admin&amp;#39;s browser.&lt;br /&gt;</description><author>billcan</author><pubDate>Wed, 20 Feb 2008 18:47:05 GMT</pubDate><guid isPermaLink="false">CREATED ISSUE: SEC: HTML Encode for Update my profile/User Manager 20080220064705P</guid></item><item><title>COMMENTED ISSUE: SEC: Old password can match new password</title><link>http://www.codeplex.com/pi/WorkItem/View.aspx?WorkItemId=5466</link><description>We are using the wrong change password method on changeqa...&lt;br /&gt;Comments: CS 9763 - Changed SetPassword to ChangePassword and added error text to resource files.</description><author>DaveMo</author><pubDate>Wed, 20 Feb 2008 18:43:57 GMT</pubDate><guid isPermaLink="false">COMMENTED ISSUE: SEC: Old password can match new password 20080220064357P</guid></item><item><title>COMMENTED ISSUE: SEC: Can change password without entering old password</title><link>http://www.codeplex.com/pi/WorkItem/View.aspx?WorkItemId=5467</link><description>On the update profile page.&lt;br /&gt;Comments: CS 9763 - Changed SetPassword to ChangePassword and added error text to resource files.</description><author>DaveMo</author><pubDate>Wed, 20 Feb 2008 18:43:26 GMT</pubDate><guid isPermaLink="false">COMMENTED ISSUE: SEC: Can change password without entering old password 20080220064326P</guid></item><item><title>Source code checked in</title><link>http://www.codeplex.com/pi/SourceControl/ListDownloadableCommits.aspx</link><description>5466 &amp;#38; 5467 - The problems indicated with these bugs are a result of using ADSI SetPassword instead of ChangePassword. Now using ChangePassword. Add resource error messages that attempt to describe what a &amp;#34;constraint violation&amp;#34; might be.</description><author>DaveMo</author><pubDate>Wed, 20 Feb 2008 18:41:15 GMT</pubDate><guid isPermaLink="false">Source code checked in 20080220064115P</guid></item><item><title>CREATED ISSUE: SEC: Can change password without entering old password</title><link>http://www.codeplex.com/pi/WorkItem/View.aspx?WorkItemId=5467</link><description>On the update profile page.&lt;br /&gt;</description><author>billcan</author><pubDate>Wed, 20 Feb 2008 18:29:20 GMT</pubDate><guid isPermaLink="false">CREATED ISSUE: SEC: Can change password without entering old password 20080220062920P</guid></item></channel></rss>