Subscribe: Planet Plone
http://planet.plone.org/rss20.xml
Added By: Feedage Forager Feedage Grade A rated
Language: English
Tags:
code  community  conference  foundation  new  open  org  plone conference  plone org  plone  python  run  time  work  zope 
Rate this Feed
Rate this feedRate this feedRate this feedRate this feedRate this feed
Rate this feed 1 starRate this feed 2 starRate this feed 3 starRate this feed 4 starRate this feed 5 star

Comments (0)

Feed Details and Statistics Feed Statistics
Preview: Planet Plone

Planet Plone - Where Developers And Integrators Write



Fedora People: http://fedoraplanet.org



 



kitconcept GmbH: plone.restapi 1.0.0 released - A Story of Successful Open Source Collaboration

Fri, 19 Jan 2018 19:24:37 +0000

After more than three years of development and 25 alpha and one beta release, we are very happy and proud to announce the release of plone.restapi 1.0.0. plone.restapi is a RESTful hypermedia API for the Plone Open Source Content Management System. It exposes the unique and powerful features of Plone, including the core content management features as well as dynamic content type creation, workflows, permissions, versioning and more. plone.restapi builds a bridge between a stable and mature Open Source CMS that has been around for more than 15 years and modern state-of-the-art JavaScript-based solutions like React, Angular, Vue and others. A Little Bit of History PLOG 2014 The development of plone.restapi started in beautiful Sorrento, Italy at the Plone Open Garden in 2014 after I gave a talk about building an AngularJS application on top of Plone. A long discussion with Simone Deponti under the Italian sun, about REST API design principles and hypermedia (of course), led to the first commit and the development of a first proof-of-concept implementation. plone.rest and PLOG 2015 One year later we gathered in Sorrento again. Laurence Rowe, Ramon Navarro Bosch and I spent our days and nights discussing the details of the REST API design and drafted multiple endpoints. One of the main obstacles to building a RESTful API on top of Plone was the missing ZPublisher support for HTTP verbs such as PATCH, PUT or DELETE. In 2015, I sat together with Ramon Navarro Bosch in Sorrento (again) and we (he really did all the heavy lifting) started to build plone.rest, a small package that adds support for HTTP verbs to Plone. Plog 2015 from Abstract on Vimeo. Archetypes and Serializers We never planned to support Archetypes in plone.restapi. Though, when Thomas Buchberger and Lukas Graf came along and offered to build it, we did not object (of course not, this is Open Source). Their company 4teamwork planned to build a REST api on top of Plone for their OneGov GEVER platform. Instead of building something on their own, they decided to join forces and share their work and code with the community. Along the way, they heavily refactored the code, added tons of adapters for loose coupling and the ability to customize the JSON serialization. After this, we were confident to do a first alpha release of plone.restapi on June 14th 2016. Beethoven Sprint In March 2017, fourteen Plone developers from eight different countries gathered in Bonn, at the kitconcept office, for the Beethoven Sprint to work on plone.restapi and related topics. In addition to sorting out the last remaining design decision, many exciting new projects were started and announced. Angular At the Beethoven sprint, Eric Brehault started to work on an Angular SDK for plone.restapi. A release followed soon and Eric gave a very successful and crowded training at the Plone Conference 2017 in Barcelona. Today, Angular SDK is a mature package for Angular 2 that makes it really easy for front-end developers to interact with Plone and a fantastic starting point for newbies. Eric and I mentored Noel Varghese during last year’s Google Summer of Code to build a Progressive Web App for Plone in Angular 2. Noel gave a nice presentation of his successful project at the Plone Conference in Barcelona. React Rob Gietema and Roel Bruggink started to build a React-based front-end on top of plone.restapi at the Beethoven sprint in Bonn. Later that year, they went to Toulouse in September 2017 to implement the Pastanaga CSS together with the Plone Angular team. In November they visited Bonn again for the Pastanaga Sprint where we started to implement the new Pastanaga UI for plone-react. At kitconcept, we started to use plone-react with Pastanaga for an ongoing project. We can’t wait to release our work and contribute it back to the community. Vue.JS Inspired by the Angular SDK and[...]



T. Kim Nguyen: Configuring the ufw firewall to allow Cloudflare IP addresses

Wed, 03 Jan 2018 01:56:00 +0000

I have a Linode running Ubuntu 16.04, and I use the ufw firewall. I have a web site running on that server, originally accessible via HTTPS on port 443 from anywhere on the internet. The domain for that web site is managed via Cloudflare. I want the site to be available only through the domain, and not via the Linode's IP address. Cloudflare publishes the IP addresses it uses to access your web site: https://www.cloudflare.com/ips/ Here is a page describing the overall idea of using ufw to allow access to your web site only from those Cloudflare IP addresses: https://www.ajsalkeld.com/blog/tutorial/2016/08/01/how-to-use-ufw-to-whitelist-cloudflare-ips-ubuntu-debian-digitalocean/ In this repo https://github.com/Paul-Reed/cloudflare-ufw there is a script that does this: https://github.com/Paul-Reed/cloudflare-ufw/blob/master/cloudflare-ufw.sh I modified it a bit so that: it uses the /tmp directory it uses a unique filename (containing the current process ID) when retrieving the Cloudflare IP addresses it specifically allows connections only on port 443 (you may want to allow connections on port 80 as well or instead) it just outputs to the screen the commands that it would issue using ufw; If the commands look sane/good to you, copy and paste them into your terminal to run them Here is my script: #!/bin/shcd /tmpwget https://www.cloudflare.com/ips-v4 -O ips-v4-$$.tmpwget https://www.cloudflare.com/ips-v6 -O ips-v6-$$.tmpfor cfip in `cat ips-v4-$$.tmp`; do echo "ufw allow from $cfip to any port 443 proto tcp"; donefor cfip in `cat ips-v6-$$.tmp`; do echo "ufw allow from $cfip to any port 443 proto tcp"; done Once I ran the script and copied and pasted its output into a terminal, ufw was configured as follows: # ufw status numberedStatus: active     To                         Action      From     --                         ------      ----[ 1] 22                         ALLOW IN    Anywhere[ 2] 443/tcp                    ALLOW IN    103.21.244.0/22[ 3] 443/tcp                    ALLOW IN    103.22.200.0/22[ 4] 443/tcp                    ALLOW IN    103.31.4.0/22[ 5] 443/tcp                    ALLOW IN    104.16.0.0/12[ 6] 443/tcp                    ALLOW IN    108.162.192.0/18[ 7] 443/tcp                    ALLOW IN    131.0.72.0/22[ 8] 443/tcp                    ALLOW IN    141.101.64.0/18[ 9] 443/tcp                    ALLOW IN    162.158.0.0/15[10] 443/tcp                    ALLOW IN    172.64.0.0/13[11] 443/tcp                    ALLOW IN    173.245.48.0/20[12] 443/tcp                    ALLOW IN    188.114.96.0/20[13] 443/tcp                    ALLOW IN    190.93.240.0/20[14] 443/tcp                    ALLOW IN    197.234.240.0/22[15] 443/tcp                    ALLOW IN    198.41.128.0/17[16] 22 (v6)                    ALLOW IN    Anywhere (v6)[17] 443/tcp                    ALLOW IN    2400:cb00::/32[18] 443/tcp                    ALLOW IN    2405:8100::/32[19] 443/tcp                    ALLOW IN    2405:b500::/32[20] 443/tcp                    ALLOW IN    2606:4700::/32[21] 443/tcp                    ALLOW IN    2803:f800::/32[22] 443/tcp                    ALLOW IN    2c0f:f248::/32[23] 443/tcp                    ALLOW IN    2a06:98c0::/29 I tested by browsing to my web site's domain (e.g. https://mysite.com) and it worked. Then I tried to browse to my server's IP address (e.g. https://123.45.67.89) and it did not work, as expected and as intended. Update: January 3, 2018: Thank you to Florian Schulze who suggested[...]



kitconcept GmbH: Continuous Performance Analysis with Lighthouse and Jenkins

Fri, 22 Dec 2017 06:11:00 +0000

Lighthouse is an open-source, automated tool for improving the quality of web pages by Google. It measures the performance of a website and provides metrics for accessibility, best practices for modern web apps, search engine optimization, and assess web applications for adherence to Progressive Web App standards. Lighthouse Logo Together with WebPageTest and Google Page Speed Insights it is an indispensable tool to optimize your website performance. Installation Lighthouse can be installed in any JavaScript-based project by just running ‘npm install’: $ npm install lighthouse -g If you don’t have a package.json in your project, just install npm and run ‘npm init’ before installing. Running Lighthouse You can check the performance of any website by calling the ‘lighthouse’ command with the URL of the website you want to test. Append the --view parameter to show the HTML report, right after the command has finished: $ lighthouse https://kitconcept.com --view The report will give you five different ratings about PWA, performance, accessibility, performance best practices, and SEO. Lighthouse Results Continuous Performance Measurements If you run your performance test every now and then, you always risk to hurt your website performance without noticing. If a performance regression happens unnoticed, it is usually very hard and time consuming to figure out which change caused the performance regression. You can easily fix this and save lots of time when you run your performance tests and analysis continuously. Unfortunately Lighthouse does not allow you to set performance test specifications that your CI system can test against, like WebPageTest or Google Page Speed Insights do (we will cover those tools in later blog posts). Though, it is still very convenient to run the performance test on a regular basis for each commit and include them into your CI report. Install Lighthouse locally for CI When it comes to a Continuous Integration, a local installation is prefered over a global one, which is usually harder to manage and to maintain. Especially if you have multiple projects with different sets of package versions on your CI. Therefore we install Lighthouse locally in our project directory: $ npm install lighthouse --save-dev This command will install Lighthouse to your local package.json file. We recommend to use yarn or npm package-lock.json to lock down the package version you are using for a repeatable and stable project build. For convenience, we add a “lighthouse” script to our package.json: "scripts": { "lighthouse:ci": "node_modules/lighthouse/lighthouse-cli/index \ --output-path=./lighthouse-report.html --quiet \ --chrome-flags='--headless' https://kitconcept.com" } We call the locally installed lighthouse binary and set a static output path (by default, Lighthouse creates a file with the current date/time in the filename which makes it harder to publish on your CI). We also include the --quiet option and run it on headless chrome, so we don’t need to install and run an X server on our CI system. At the end, we hard-code our project URL into the command so we do not have to type it manually each time we run this command. Now we can just run: $ npm run lighthouse:ci and it will create a nice HTML report that we can publish in our CI. Configure Lighthouse for your local development environment For convenience, we also add a command that you can run locally: "scripts": { "lighthouse": "node_modules/lighthouse/lighthouse-cli/index \ --output-path=./lighthouse-report.html --quiet \ --chrome-flags='--headless' https://kitconcept.com/blog" } The --view parameter will fire up a browser with the report at the end of the performance analysis. This is something we clearly don’t want on our CI system. Publish Lighthouse Reports in Jenkins CI Travis and other lightw[...]



Jazkarta Blog: Jazkarta Sponsors Northwest Youth Leadership Summit

Thu, 07 Dec 2017 20:21:06 +0000

Jazkarta is pleased to have recently sponsored the North Cascades Institute‘s Northwest Youth Leadership Summit. This event is intended to empower Cascadia’s future leaders in conservation by: Enhancing their skills in preparation for job and college applications ​Connecting with regional environmental organizations and businesses to learn about jobs and internships Learning from like-minded peers about career options available in the conservation, outdoor and environmental fields More than 220 students participated and are now better equipped to take action towards conservation. The Summit was free to all participants to ensure that underrepresented youth are given opportunities to get involved in the outdoor and environmental fields. The sponsorship added another dimension to our existing partnership with North Cascades Institute. Just before the summit, we had given the non-profit’s Plone+Salesforce website a mobile refresh to make it work smoothly on phones and tablets. If we say so ourselves, the results are quite beautiful. Kudos to Neal Maher for the designs and to the Jazkarta team (Christine Winckler and David Glick) for a smooth implementation. North Cascades Institute is not the only environmental non-profit organization that Jazkarta is working with – we created The Mountaineers‘s website and the Washington Trails Association ‘s volunteer management system. Both organizations were involved in the Summit. It was hosted at The Mountaineers’ Seattle Program Center, here is one of the students using the climbing wall. Andrew Pringle of the Washington Trails Association led a breakout session titled “Trip Planning 101: An Introduction to Leading Backcountry Adventures”, and both organizations ran booths, talking with participants about activities, internships and employment options for young outdoor leaders.  Here’s Andrew at the WTA booth. We feel very lucky to be helping all of these organizations further their missions.   — Photos by North Cascades Institute staff Tagged: conservation, environment, north cascades institute, pacific northwest, sponsorship, the mountaineers, wta, youth [...]



PLONE.ORG: 20171128

Tue, 28 Nov 2017 00:00:00 +0000

(image) Several XSS and redirect fixes, and a sandbox escape fix.



PLONE.ORG: Security patch released 20171128

Tue, 28 Nov 2017 00:00:00 +0000

This is a routine patch with our standard 14 day notice period. There is no evidence that the issues fixed here are being used against any sites. CVE numbers not yet issued. Versions Affected: All supported Plone versions (4.x, 5.x). Previous versions could be affected but have not been tested. Versions Not Affected: None. Nature of vulnerability: Low severity, no data exposure or privilege escalation for anonymous users. The patch was released at 2017-11-28 15:00 UTC. Installation Full installation instructions are available on the HotFix release page. Standard security advice Make sure that the Zope/Plone service is running with minimum privileges. Ideally, the Zope and ZEO services should be able to write only to log and data directories. Plone sites installed through our installers already do this. Use an intrusion detection system that monitors key system resources for unauthorized changes. Monitor your Zope, reverse-proxy request and system logs for unusual activity. Make sure your administrator stays up to date, by following the special low-volume Plone Security Announcements list via email, RSS and/or Twitter These are standard precautions that should be employed on any production system, and are not tied to this fix. Extra Help If you do not have in-house server administrators or a service agreement for supporting your website, you can find consulting companies at plone.com/providers There is also free support available online via the Plone forum and the Plone chat channels. Q: When will the patch be made available?A: The Plone Security Team will release the patch at 2017-11-28 15:00 UTC. Q. What will be involved in applying the patch?A. Patches are made available as tarball-style archives that may be unpacked into the products folder of a buildout installation and as Python packages that may be installed by editing a buildout configuration file and running buildout. Patching is generally easy and quick to accomplish. Q: How were these vulnerabilities found?A: The vulnerabilities were found by users submitting them to the security mailing list. Q: My site is highly visible and mission-critical. I hear the patch has already been developed. Can I get the fix before the release date? A: No. The patch will be made available to all administrators at the same time. There are no exceptions. Q: If the patch has been developed already, why isn't it made available to the public now? A: The Security Team is still testing the patch against a wide variety of configurations and running various scenarios thoroughly. The team is also making sure everybody has appropriate time to plan to patch their Plone installation(s). Some consultancy organizations have hundreds of sites to patch and need the extra time to coordinate their efforts with their clients. Q: How does one exploit the vulnerability?A: This information will not be made public until after the patch is made available. Q: Is my Plone site at risk for this vulnerability? How do I know if my site has been exploited? How can I confirm that the hotfix is installed correctly and my site is protected? A: Details about the vulnerability will be revealed at the same time as the patch. Q: How can I report other potential security vulnerabilities? A: Please email the Plone Security Team at security@plone.org rather than publicly discussing potential security issues. Q: How can I apply the patch without affecting my users? A: Even though this patch does NOT require you to run buildout, you can run buildout without affecting your users. You can restart a multi-client Plone install without affecting your users; see http://docs.plone.org/manage/deploying/processes.html   Q: How do I get help patching my site? A: Plone service providers are listed at plone.com/providers  There is also free support available online via the Plone forum and the Plone chat channels Q: Who is on the Plone Se[...]



T. Kim Nguyen: fail2ban configuration error fix

Sun, 26 Nov 2017 16:09:00 +0000

(image)

If you have this in your /etc/fail2ban/jail.local configuration file:

# "bantime" is the number of seconds that a host is banned.
bantime = 31536000 # 1 year

# A host is banned if it has generated "maxretry" during the last "findtime"
# seconds.
findtime = 604800 # 7 days

and you get these errors when you restart fail2ban (service fail2ban restart):

WARNING Wrong value for 'findtime' in 'ssh'. Using default one: '600'
WARNING Wrong value for 'bantime' in 'ssh'. Using default one: '600'

change it to this (put the comment on a separate line):

# "bantime" is the number of seconds that a host is banned.
# 1 year
bantime = 31536000

# A host is banned if it has generated "maxretry" during the last "findtime"
# seconds.
# 7 days
findtime = 604800

This is explained in the following bug report:

fail2ban: Incorrect parsing of commented text after reading a value from config file

If you want to set a permanent ban time, use a negative number.

# "bantime" is the number of seconds that a host is banned.
# permanent ban
bantime = -1






kitconcept GmbH: Pastanaga Sprint Bonn 2017

Thu, 23 Nov 2017 17:02:37 +0000

Pastanaga is a new user experience framework for the web, designed by Albert Casado. Pastanaga was first presented in March 2017, at the Plone Open Garden in Sorrento. In July, we started with an initial implementation during the Midsummer Sprint in Jyväskylä, Finnland. Pastanaga was also present at the recently held Plone Conference in Barcelona, where Albert gave a presentation on it. In addition, Eric Steele, the Plone release manager, gave us the opportunity to present Pastanaga to the audience during his keynote on the first day of the conference. With all the positive feedback and energy we took from the Plone Conference, we wanted to push things further and we just couldn’t wait until our “Beethoven Sprint”, which is planned for early 2018. Therefore we decided to organize a small and focused sprint at our office in Bonn to work on the implementation of Pastanaga. The Pastanaga Minimal Viable Product As an Open Source community (and software engineers) with many years of experience in designing and building complex Content Management System applications, we sometimes have the tendency to try to solve all problems at once. Over the years we encountered and solved many complex problems and when we build something new, this can be both a source of wisdom as well as a baggage that you carry around. This sometimes led to a situation where we were over-engineering solutions, to solve all the problems that we encountered over the years at once. Enhancements sometimes stayed around for years without really becoming production ready and usable in real-world projects. To avoid this from happening when working on implementing Pastanaga, we decided in Jyväskylä to focus on a Minimal Viable Product. A Minimum Viable Product (MVP) is a product with just enough features to satisfy early customers, and to provide feedback for future product development. The Pastanaga MVP needs to provide what we consider the essentials of a Content Management System: A site administrator can and add, edit, and delete a page A user can view the created pages and navigate the site structure In order to be usable for public facing website projects, we added two additional technical requirements: The page should be fully rendered within 500 milliseconds Google should be able to crawl the contents of the website Those requirements might sound very simple, but they are actually not. Pastanaga aims to leverage the editing experience and reduce the complexity that we took for granted over the years. We aim to simplify the user experience for the editors by getting rid of things that we got used to. For instance, adding an image to a page should be as simple as just dragging and dropping an image to the page and Plone will take care about the heavy lifting of automatically uploading and resizing the image. You can find a list of all the user stories that we plan to implement as part of the MVP here: https://github.com/plone/pastanaga#minimal-viable-product Having the goals and scope for this set the only thing that was needed was a bunch of Plone devs and three days and nights of coding. Sprint Day One After the sprinters arrived, we started with our sprint planning session. We decided to focus on the implementation of the Pastanaga MVP and work on the other issues (e.g. plone.restapi) only if we need them for the MVP. .@robgietema giving us an introduction to plone-react. #plone #sprint pic.twitter.com/Ga6Bsd3l2J— kitconcept (@kitconcept_gmbh) November 15, 2017 After the planning meeting, Rob gave us an introduction to plone-react, a ReactJS-based implementation of the Plone UI that he and Roel worked on over the past months and that we decided to use as a basis for our MVP. Pastanaga sprint planning meeting at our office in Bonn. #plone #Sprint pic.twitter.com/FDpjv5w[...]



PLONE.ORG: Successful Google Summer of Code 2017

Thu, 16 Nov 2017 17:47:26 +0000

(image)

Google Summer of Code ("GSoC") is an annual international program open to university students in which Google awards stipends to all students who successfully complete a free and open-source software  project.

The Plone community is proud to announce four successful projects were completed for GSoC 2017. 

All five GSoC students were offered sponsorship by the Plone Foundation to travel to Barcelona for the Plone Digital Experience 2017 conference. Oshane, Mikko, Noel, and Shriyansh Agrawal (content import and export) were able to attend and present their work to enthusiastic audiences.

Cris Ewing was our new-for-2017 coordinator of the Plone community's GSoC involvement. The Plone Foundation Board expresses its gratitude to him on behalf of the entire Plone community for having managed this very important project.

We also truly appreciate the time and effort of our GSoC students and their mentors in continuing to move Plone forward.

On to 2018, for which we have already begun soliciting project ideas




PLONE.ORG: Plone Foundation Officers 2017-2018

Wed, 15 Nov 2017 20:25:00 +0000

(image)

All seven Plone Foundation Board members' nominations were accepted at the Annual General Meeting held in Barcelona on October 20, 2017: 

  • Paul Roeland
  • Alexander Loechel
  • Carol Ganz
  • Chrissy Wainwright
  • Víctor Fernández de Alba
  • Philip Bauer
  • T. Kim Nguyen

At the first Board meeting of the new term on November 2, 2017, the officers of the Foundation were voted in. The officers are elected annually:

  • President: Paul Roeland
  • Vice President: Alexander Loechel
  • Secretary: Chrissy Wainwright
  • Treasurer (non-voting): Jen Myers

Apart from these official Foundation roles, there are further roles and tasks that the Board attends to:

  • Marketing lead: T. Kim Nguyen
  • Framework team liaison: Philip Bauer
  • Security team liaison & Higher Education liaison: Alexander Loechel
  • Communications/Marketing team lead: T. Kim Nguyen
  • Front End team lead: Víctor Fernández de Alba
  • Foundation Membership committee co-chairs: Érico Andrei, T. Kim Nguyen

For more information on the Plone Foundation or its board, visit plone.org/foundation, or drop an e-mail to .

Plone is an open source web content management system excelling in usability, accessibility, and versatility. The Plone Foundation is a US 501(c)3 tax-exempt organization that protects and promotes Plone.




PLONE.ORG: Thank you, Barcelona!

Wed, 15 Nov 2017 18:02:40 +0000

(image)

The Plone Digital Experience Conference 2017 in Barcelona was an exhilarating success, bringing together the Plone, Python web, and modern JavaScript front end communities in the beautiful city of Barcelona. 

(image) (image) (image) (image)

Some statistics: 

  • 10 training classes
  • 6 keynotes
  • 52 presentations 
  • 180 attendees from 21 countries
  • 2 organizing companies, 18 sponsors, 4 partners
  • 70 sprinters
  • 4 Google of Summer of Code 2017 students
  • 1 truly memorable conference dinner
  • 1 official Plone band 
  • dozens of volunteers

Some artifacts:

  • Speakers' slides can be found for almost all the presentations (video recordings still to come).
  • Photos of the conference
  • Tweets during the conference 

On behalf of the Plone community, thank you 2017 organizing team!

  • Victor Fernandez de Alba
  • Ramon Navarro Bosch
  • Agata Avalo
  • Albert Casado
  • Timo Stollenwerk
  • Philip Bauer
  • Paul Roeland
  • Kim Nguyen
  • Sally Kleinfeldt
  • Mikel Larreategi
  • Eric Bréhault

(image)




PLONE.ORG: Security vulnerability pre-announcement: 20171128

Fri, 10 Nov 2017 16:30:00 +0000

This is a routine patch with our standard 14 day notice period. There is no evidence that the issues fixed here are being used against any sites. CVE numbers not yet issued. Versions Affected: All supported Plone versions (4.x, 5.x). Previous versions could be affected but have not been tested. Versions Not Affected: None. Nature of vulnerability: Low severity, no data exposure or privilege escalation for anonymous users. The patch will be released at 2017-11-28 15:00 UTC. Preparation This is a pre-announcement of availability of this security fix.  The security fix egg will be named Products.PloneHotfix20171128 and its version will be 1.0. Further installation instructions will be made available when the fix is released. Standard security advice Make sure that the Zope/Plone service is running with minimum privileges. Ideally, the Zope and ZEO services should be able to write only to log and data directories. Plone sites installed through our installers already do this. Use an intrusion detection system that monitors key system resources for unauthorized changes. Monitor your Zope, reverse-proxy request and system logs for unusual activity. Make sure your administrator stays up to date, by following the special low-volume Plone Security Announcements list via email, RSS and/or Twitter These are standard precautions that should be employed on any production system, and are not tied to this fix. Extra Help Should you not have in-house server administrators or a service agreement for supporting your website, you can find consulting companies at plone.com/providers There is also free support available online via the Plone forum and the Plone chat channels. Q: When will the patch be made available?A: The Plone Security Team will release the patch at 2017-11-28 15:00 UTC. Q. What will be involved in applying the patch?A. Patches are made available as tarball-style archives that may be unpacked into the products folder of a buildout installation and as Python packages that may be installed by editing a buildout configuration file and running buildout. Patching is generally easy and quick to accomplish. Q: How were these vulnerabilities found?A: The vulnerabilities were found by users submitting them to the security mailing list. Q: My site is highly visible and mission-critical. I hear the patch has already been developed. Can I get the fix before the release date? A: No. The patch will be made available to all administrators at the same time. There are no exceptions. Q: If the patch has been developed already, why isn't it made available to the public now? A: The Security Team is still testing the patch against a wide variety of configurations and running various scenarios thoroughly. The team is also making sure everybody has appropriate time to plan to patch their Plone installation(s). Some consultancy organizations have hundreds of sites to patch and need the extra time to coordinate their efforts with their clients. Q: How does one exploit the vulnerability?A: This information will not be made public until after the patch is made available. Q: Is my Plone site at risk for this vulnerability? How do I know if my site has been exploited? How can I confirm that the hotfix is installed correctly and my site is protected? A: Details about the vulnerability will be revealed at the same time as the patch. Q: How can I report other potential security vulnerabilities? A: Please email the Plone Security Team at security@plone.org rather than publicly discussing potential security issues. Q: How can I apply the patch without affecting my users? A: Even though this patch does NOT require you to run buildout, you can run buildout without affecting your users[...]



Starzel.de: Obstacles on the road towards Plone 2020

Fri, 10 Nov 2017 09:45:00 +0000

During the sprint at the Plone Conference 2017 in Barcelona, Plone achieved a major milestone towards what is often called "Plone 2020". This is basically the effort to modernize Plone's backend and achieve Python 3 compatibility. In 2020, support for Python 2.7 will officially end, hence Plone 2020. A necessary part of that effort was to migrate Zope to Python 3, a daunting task that was only possible by a flurry of activity that combined the efforts of many stakeholders (not only the Plone Community). Learn more about that in Hanno Schlichting's talk once the video is on the website, and on many blog posts on the Gocept Blog. Getting Plone to run on that newest version of Zope (currently Zope 4.0b2) was another story and took a lot of work (some details are in my post here. Finally in Barcelona, in a daring move we merged all the work that had been done for that PLIP https://github.com/plone/Products.CMFPlone/issues/1351 and decided that the result will be called Plone 5.2. But by that time not all tests were green (that's why it was daring). We worked hard to get the tests to pass and to fix some issues we found when testing manually. By the way: At the same sprint we started to prepare Plone itself for Python 3 by fixing all imports to work in both Python 2 and Python 3. But that is a tale for another blog post. So, despite out best efforts, even one week after the conference I was not yet able to fix all the tests, and so I created at ticket to track the remaining issues. Here this story about two erroring tests in Products.CMFFormController actually begins. Here is the spoiler: I did not really solve the issue but finally worked around it. But I still think the approach I took might be of interest to some. The two breaking tests, test_attacker_redirect and test_regression, were passing when I ran them in isolation or when I ran all test of Products.CMFFormController with ./bin/test -s Products.CMFFormController. To add insult to injury, Products.CMFFormController is basically dead code but is still used by some of our legacy ControllerPageTemplates. So how could I find the issue since the traceback was not really helpful? Here is the relevant part of the log from jenkins: #### Running tests for group Archetypes #### Running Products.Archetypes.tests.attestcase.Archetypes:Functional tests: [...] Running plone.app.testing.bbb.PloneTestCase:Functional tests: Tear down Testing.ZopeTestCase.layer.ZopeLite in 0.000 seconds. Set up plone.testing.zca.LayerCleanup in 0.000 seconds. Set up plone.testing.z2.Startup in 0.101 seconds. Set up plone.app.testing.layers.PloneFixture in 9.722 seconds. Set up plone.app.testing.bbb.PloneTestCaseFixture in 2.628 seconds. Set up plone.app.testing.bbb.PloneTestCase:Functional in 0.000 seconds. Error in test test_attacker_redirect (Products.CMFFormController.tests.testRedirectTo.TestRedirectToFunctional) Traceback (most recent call last): File "/usr/lib/python2.7/unittest/case.py", line 329, in run testMethod() File "/home/jenkins/workspace/plone-5.2-python-2.7-at/src/Products.CMFFormController/Products/CMFFormController/tests/testRedirectTo.py", line 97, in test_attacker_redirect handle_errors=False, File "/home/jenkins/workspace/plone-5.2-python-2.7-at/src/Zope/src/Testing/ZopeTestCase/functional.py", line 43, in wrapped_func return func(*args, **kw) File "/home/jenkins/workspace/plone-5.2-python-2.7-at/src/Zope/src/Testing/ZopeTestCase/functional.py", line 127, in publish wsgi_result = publish(env, start_response) File "/home/jenkins/workspace/plone-5.2-python-2.7-at/src/Zope/src/ZPublisher/WSGIPublisher.py", line 254, in publish_module with load_app(module_info) as new_mod_info: Fil[...]



CodeSyntax: Content translation endpoint for plone.restapi

Mon, 06 Nov 2017 15:03:25 +0000

(image) plone.restapi ships with content translations support endpoint since version 1.0a22. In this post I will explain the history behind this and the decisions taken to implement it.



Asko Soukka: Plone Conference Barcelona 2017

Fri, 03 Nov 2017 07:35:54 +0000

It was awesome to be back at Plone Conference this year. Finally! We have had participation in Plone conferences in 2009, 2011–2012 and 2014–2017, but for me the previous one was years ago: Plone Conference Bristol in 2014. Needless to say that I have missed the warm and welcoming atmosphere of a Plone conferences, and It's my pleasure to report that Barcelona did not let me down. Even the weather was still warm there in this October.This year there was no single big Plone news at the conference. The latest major release of Plone CMS was released already two years ago, and the next feature release is still waiting for its gold master. Yet, there was still a lot of good news, and putting all the puzzle pieces together resulted in a clear picture of the future of Plone.Disclaimer: These are obviously just my personal opinions on all these things Plone...Published originally at http://tech.blog.jyu.fi/2017/10/plone-conference-barcelona-2017.htmlPlone Conference Barcelona was so much of fun that I took a piece of it with me back home.Plone 2020 and beyondAt first, let's say it clear that Plone CMS remains to be a safe bet for a long-term enterprise CMS solution. If there ever was any doubt, whether Plone could make it to Python 3 in-time before the end of Python 2.7 maintenance in 2020, that should be no more. Plone will make it.All the major blockers seem to have been solved, and the rest is just hard work left for our community (check some related talks by Alexander and Hannoabout the recent events on that). Python 3 version of Zope application server powering Plone is already in beta, and it is scheduled to be released within a year. Plone, for sure, has still plenty of packages to be ported from Python 2.7 to Python 3, but there are already many sprints scheduled to continue that work in near future (including the already completed Barcelona Conference sprints). We might even have an alpha version of Plone on Python 3 before end of 2018.In addition that, it's always good to mention, that Plone Foundation has continued to do its usual great job in all the possible paper work around managing Plone's copyrights and trademarks.All these should be good and relaxing news for any long-term Plone user.Let's go frontend!The greatest challenge for Plone CMS seems to be keeping up with the ever increasing UX expections of the day, while complying with the high accessibility standards. After Plone 5 rewrote the default theme and whole front-end resource management in Plone, there are no longer blockers for using any current front-end tech with Plone. But just being able to use some tech is not enough – also the real work for better UX needs to be done. And even a lot has been done for Plone 5 and 5.1, that work seems to never end.Plone Conference Barcelona included a great amount of front-end, user experience and accessibility related talks to educate our community. So many that I can only mention a few.At first, there were talks regarding the current Plone user interface: Johannes gave a bit technical, but very comprehensive talk how the new frontend resource registries in Plone 5 really work. My talk instructed, how to combine the ancient powers of Zope application server with the modern Plone 5 theming support to achieve shorter iterations and faster deployments when developing new UX features. Our Rikupekka talked about our migration experiences from Plone 4 to Plone 5, and gave a demo about of the UI features we have developed using the approach I discussed in my talk. Finally, I want to mention Wildcards' Kim's talk about Castle CMS, which really showcased, how much difference well lead and focused UX development [...]



PLONE.ORG: Plone Conference 2018 will be in Tokyo, Japan!

Fri, 27 Oct 2017 15:33:00 +0000

The annual Plone Conference will be held in Tokyo, Japan, on November 5 - 11, 2018! Tokyo is a unique, exciting city of modern and traditional charms, and its infrastructure is rapidly evolving to welcome overseas guests for the Olympic and Paralympic Games in 2020. It will be the first Asian city to host the Plone Conference. The first PyCon APAC in Tokyo was held in 2013 and it attracted more than 500 participants. PyCon JP is an annual conference held in Tokyo since 2011 and the number of participants has been rapidly increasing.   Organizers Manabu Terada, Takeshi Yamamoto, Zenichiro Yasuda, and Takanori Suzuki submitted the winning conference proposal, vetted by the Plone Foundation Board and announced at the Foundation's Annual General Meeting held last week in Barcelona.     The conference will be promoted on Asian/Japanese media to grow the well-established Japanese Plone user base, and 1-day Conference tickets will be offered to increase local participation. Simultaneous translation will be provided for keynotes and other tracks.  Venue The Conference will be held at Ota City Plaza, a conference venue located in an area called Kamata. Kamata is famous for being the center of manufacturing and high technology of Japan. The venue is only 3 minutes-walk from Keikyu Kamata station and there are numerous hotels in walking distance. There are many restaurants and bars (or “Izakaya”, a Japanese pub) for local people to enjoy, so the participants can enjoy Tokyo’s nightlife at a reasonable price while indulging themselves in the local atmosphere. Two large halls will accommodate more than 300 in theater style each at the Ota City Plaza. Aside from these halls, there are 8 conference rooms which have the capacity for holding training, breakouts and tutorials. Microphone (wired and wireless), projector and screen are prepared for all halls and conference rooms. Conference Track Themes Python Web (Django, Pyramid, WSGI and more) Frontend (JavaScript, Design) Database (ZODB, NEO, SQLAlchemy, MySQL, PostgreSQL and more) Training – November 5 (Mon) to 6 (Tue), 2018 (2 days) Training will be held at the Ota City Industrial Plaza, which is also the venue for the Conference. Training will consist of 3 to 4 sessions, led by professionals who are globally known for their achievement. There will be a session in Japanese for local users. Wifi will be available for participants.  Conference – November 7 (Wed) to 9 (Fri), 2018 (3 days) The Conference will consist of 3 tracks. Each day's program will follow a theme. One of the keynotes will be given by a Japanese speaker known for their accomplishments (it will be simultaneously translated into English). In order to increase the number of local participants, in addition to the 3 tracks, there will be an entire track in Japanese presented by well-known Japanese speakers.  Sprint – November 10 (Sat) to 11 (Sun), 2018 (2 days) As always, sprints will be a part of the conference schedule and will be open for all (not limited to conference ticket purchasers).  Overview of Tokyo Tokyo, Japan’s bustling capital city, is a modern, vibrant megalopolis which combines business, knowledge, creativity, and innovation. The city is the epitome of fusion where over 400 years of history and Japanese tradition juxtapose, providing a unique experience for all visitors. There is always something for everyone — visitors can choose from over 100,000 restaurants, enjoy any one of its 80 plus parks, immerse in the aesthetics of the Japanese tea ceremony, or indulge in a night of unique Japanese culture at a K[...]



Asko Soukka: Building instant features with advanced Plone themes

Mon, 23 Oct 2017 20:26:32 +0000

Plone, ”The Ultimate Enterprise CMS”, ships with built-in batteries for building sophisticated content management solutions without writing a single line of new Python code. For example, a fresh installation of Plone allows to build custom structured content types with custom HTML views, define custom state based workflows, customize various user interface elements, and finish the user experience by configuring custom event triggered content rules to react on users' actions. Not to mention the Diazo based theming tool, which allows unlimited tweaking of the resulting HTML.All this by just clicking and typing things through-the-web (TTW) with your browser.Yet, still some say that Plone is a difficult to customize and extend.The flip side of customizing Plone TTW is that it's way too easy to lost track of your customizations. That adds to technical debt and therefore cost of maintaining those customizations over years and upgrades to future Plone releases. The suggested solution to avoid those problems has long been to avoid TTW customizations altogether, in favor of customizing everything using ”buildout-installed file-system Python packages”. But that makes customizing Plone feel unnecessary difficult and technical.At Plone Conference 2017 I gave a talk, where I showed an alternative way for this: if it was possible to bundle all those customizations together, for example in TTW managed theme, maintaining those customizations would no longer be the blocker.Customizing Plone could be made easy again.RequirementsTechnically, Plone has supported exporting and importing most of the possible TTW customizations for more than ten years, but the user interface for that has been cumbersomely technical. Finally, Plone 4.1 introduced a new Diazo based theming feature with easy to use theming control panel and theme editor. And now, with only a couple of extra packages in your Plone setup, Plone theming features get super powers to apply site customizations with any theme.To complete the following example, you need a Plone site with these two extra Python packages installed: collective.themesitesetup and collective.themefragments.As usual, those can be installed by customizing and running buildout[instance]eggs = ... collective.themesitesetup collective.themefragmentsor you can try out with the official Plone docker image:$ docker run -p 8080:8080 -e PLONE_ADDONS="collective.themesitesetup collective.themefragments" plone fgCase of the day: Wall of imagesAs an example feature, we build a simple folder view that displays a list of varying size images in an optimal grid layout using popular Masonrylayout library, with help an another library called imagesLoaded.To summarize, building that view requires:Providing JS bundles for both Masonry and imagesLoadedRegistering those bundles into Plone resource registryA folder view template that renders images in that folderWay to configure that view on a folderJS code to initialize Masonry layout on that viewGetting started with themingTo get a fast start, we create a dummy theme base named demotheme that simply re-uses styles and rules from Barceloneta, the default theme of Plone 5. Your theme base should contain the following files:./index.html./rules.xml./scripts./styles.css./manifest.cfgAt first, ./index.html is just a copy of the same theme file from Barceloneta: Plone Theme



CodeSyntax: Summary of Plone Conference 2017

Mon, 23 Oct 2017 11:18:53 +0000

(image) It is hard to summarize an event like this year Plone Conference. The number of talks, events and trainings, and the quality of them make it hard to explain everything, but I will try to give an overview.



Maurits van Rees: Sprint wrap-up Sunday

Sun, 22 Oct 2017 14:04:09 +0000

(image)

Sprint document is on Google Docs.

  • Pyramid: a few more documentation updates.
  • Plone and Zope 4. Down to seven failing tests, very good. Everything is merged, the master branch of CMFPlone is using Zope4, the PLIP job is gone.
  • Plone to Python 3. We decides to use six, which is a dependency of Zope anyway. Lots of PRs. Experimenting with sixer, which 'sixifies' the code automatically. GenericSetup: slowly working through incompatibilities.
  • Plone rest api. Some issues solved. plone.app.event stores start and end date timezone aware, and the rest of the dates are timezone naive, and there is no hint in the schema on what is naive or not, so that gives us problems, evaluating how to fix it.
  • VueJS SDK. Implementing traversal. Creating edit forms out of schema. You can add views with a plugin. Automatic testing with Travis is setup. Next: component. Editor.
  • Pastanaga Angular. plone/pastanaga-angular. Demo time! mr.developer work done.
  • Pastanaga.io, creating mocks.
  • Guillotina, made pastanaga-angular work with guillotina, you can login, browse content, navigation. guillotina_cms layer. Robot framework tests, with robotframework.guillotina for test setup.
  • Plone CLI. I can show you. Main setup is in place. plonecli create addon collective.todo; plonecli build; plonecli serve. Or in one command: plonecli create addon collective.todo build serve.
  • WSGI in plone.recipe.zope2instance. All merged. Python 3 compatible.
  • websauna. Pyramid 1.9 support is 100% done. In another week we can release a new version.
  • pas.plugins.ldap. Problem that tests are not running on Travis. We now know what is happen, but not yet why, when half a year ago it worked. We got LDAP running locally on Mac, so it becomes easier to test and fix.
  • docs.plone.org upgrade guide, just came in, documented one PLIP.
  • JSON Schema Builder with JavaScript. Demo time! You can click a form together, save it as json, and view it with Angular. From there you could save or mail the filled in data. You can do validation. We have collective.easyform which is Plone only, but this is more general: it's just json on the back end and front end. [Very impressive!]
  • Update XML-RPC to support dexterity. First pull request done.
  • Mixed bag. Removed all robot screen shots from documentation, they live under CMFPlone now, making it easier for others to write and test. Mixed results from Chrome and PhantomJS, also changing from version to version. With that, for papyrus, our documentation build system, we no longer need to build Plone.



Maurits van Rees: Sprint wrap-up Saturday

Sat, 21 Oct 2017 15:32:46 +0000

(image)

Sprint document is on Google Docs.

  • Working on moving Pylons to the Plone Foundation. Tedious, painstaking work. PRs for documentation and some bugs.
  • Eric made coredev branch 5.2. Merged Zope 4 PLIP changes into that. Same amount of failures as yesterday, working on getting the build green. Work on porting databases, some mosaic problems are being fixed, most add-ons are okay. Wrote documentation for some code changes you have to do.
  • Plone to Python 3. We tried to fix all the imports in all the Plone packages that break on Python 3. Long list of PRs in the Google Doc. GenericSetup Python 3 branch that we first got to work on Python 2 again. Working through the usual string issues. Some semantic issues for PropertyManagers that we need to fix in Zope first. Gil made a list of which packages are not Python 3 yet, already in June, we ask him to update it.
  • Plone rest api. Problem with root users. There is a PR which disables that, but I have a workaround ready now.
  • VueJS SDK. plone.vuejs package, but may be renamed. Just basic stuff. Test setup. Started on some features, like traversal.
  • Pastanaga Angular. Travis setup. Universal. A mr.developer for Angular. Login form is done. Work on API and SDK.
  • Pastanaga React. Struggling with several issues.
  • Pastanaga.io, talking about license, fund raising.
  • Guillotina some work done, PR.
  • Plone CLI. Front end working. Fixing stuff in bobtemplates.
  • WSGI in plone.recipe.zope2instance. PR merged into master. Should be there in Plone 5.2. Support in the core buildout for the WSGI parts: wsgi.cfg config file. Basically done.
  • websauna. Pyramid 1.9 support is 80% done. Work on cookie cutter template to support Docker images. Will become easier to startup.
  • plone.org improvements, made mockups to make packages more visible. Set of icons will be reviewed. Should be discussed with website team. Make the listing more emotional.
  • pas.plugins.ldap. Fred chatted with Jens how we can merge back improvements from Asko and Zest. Documentation, that might be later merged to docs.plone.org. Also some collective.recipe.solr work.
  • docs.plone.org upgrade guide, worked on documenting the PLIPs, restructuring a bit
  • JSON Schema Builder with JavaScript. Browser view with drag and drop, save in dexterity object. Angular app that traverses to the end point of the schema. Missing is the order of the fields which is not correct, and actions.
  • Mixed bag. Fixes for docs.plone.org, new theme release with better version dropdown. Meeting with Manabu to talk about Tokyo. Server consolidation planning. Contributor agreements signed, 2.5 of them.



Maurits van Rees: Lightning talks Friday

Fri, 20 Oct 2017 16:07:31 +0000

Andreas Jung: Collaborative content creation with smashdocs Web based collaborative editor. Better than Google docs: it can be hosted by yourself. Intelligent documents. HTML and XML export. Tracking of changes. Chat and discussion. Docx import and export Integrates with the Plone sharing tab. Content life cycle indicator. See https://www.creating-content-together.info Naoki Nakanishi: Microcontrollers and Plone I work at CMScom and I like IoT (Internet of Things). Microcontrollers can connect to Plone easily. This is because Plone has RESTful API products. We program the microcontrollers with the MicroPython language. This has the useful urequest and ujson modules. It supports many microcontrollers. I have a rough concept, but I will start to develop this from tomorrow. Maik Derstappen: bobtemplates.plone I have been working on bobtemplates.plone: mrbob bobtemplates.plone:addon -O collective.todo You can now actually add a content type in an existing package, using a sub template. It will currently overwrite code, so you want to start with a clean git checkout. See my talk this afternoon. Unrelated: Plone Tagung 2018 is planned on 20 March in Berlin. Main topics of this conference will be in German, but if others want to join in English, you are welcome. Érico Andrei: several packages contentrules.slack: post to a slack channel when something happens in your Plone Site. collective.selectivelogin: restrict login https://pypi.python.org/pypi/contentrules.slack/ Alexander and Sally: Plone 5 add-ons We had nominations and votes for Plone 5 add-ons. We had problems with losing the papers where you could vote, so this is with a grain of salt. The top results: plone.restapi eea.facetednavigation plone.app.mosaic collective.easyform On plone.org we have a list of add-ons which are managed by hand. There is a list of Plone releases, where the versions are not sorted right (alphabetically, so 1, 10, 11, 2, 3, etc). So this needs to be improved. During Google Summer of Code work was done here, getting information from PyPI. It still needs work, especially design work can help a lot, to present is nicer. Nathan and Ramon: Docker, guillotina Docker Compose is the new buildout? This might be a pattern that works for you. We have a CMS on top of guillotina: https://github.com/guillotinaweb/guillotina_cms Lots of other packages: https://github.com/guillotinaweb Charles Beebe: Inclusion > Diversity Inclusion is more than diversity. Thank you all, this is my first Plone conference and I felt welcome. I never thought I would feel comfortable to do a presentation the first time I came to a conference. Have you ever felt uncomfortable during a conference? You may 'cover' yourself, hiding something of you. That does not help. Even 45 percent of white males in America do this. Do you make people feel at home? It does not have to be complicated. I got a cake from my colleagues when I got engaged. Philip: Plone 2020 Plone 5.1 master branch with small changes works on Zope 4. In Brasil Paul Everitt said: "You are dragging the dead body of Zope with you." In 2020 Python 2 is no longer supported. We investigated and found out that Zope is actually not dead. Plone 5.2 will use Zope 4, discussed yesterday. Plone minus Archetypes minus ZServer plus Python 3 will be some Plone version. Some sprint will focus on this area: Alpine City Sprint Innsbruck in January 2018 Amsterdam Spring 2018 Where we are now, felt impossible in Brasil 2013. Roel Bruggink: d[...]



Maurits van Rees: Éric Bréhault: Building a Cathedral Over Decades

Fri, 20 Oct 2017 14:38:30 +0000

(image)

When you build a CMS, you might start small, but you end up with a very large stack. For Plone, some of this stack is more than fifteen years old.

What do we want to work on for the future? Zope 4! Guillotina! Headless CMS! Everything! So many challenges and huge projects! In a business situation you would probably say this is bad. So why is Plone still alive? Emotions and culture.

Emotion

A software developer feels like a parent to his code. An open source community is like a shared parent group. Why does this work? Love.

Open source is not business. I can prove that. Business means you are busy. Busy means you are not free. Not free means you are not open. Clear.

The business world talks about disruption. It is violent. Okay for the business world.

Business values a 10x developer. Open source knows: the only way to be a 10x developer, is to have ten developers be twice as good.

Nine couples cannot make one baby in one month. One couple makes a baby in nine months, and it takes a village to raise the baby. Open source community.

Results versus process. Process provides emotions. Results provide money.

Developing with each other is sharing emotion. The Plone community is not just sharing code, it is sharing emotions. It feels good to share.

Empathy: feel what someone else is feeling. It is not something that you decide to do. Empathy makes it possible to share emotions. Empathy is the first open source process.

We are emotion addicts. This is true for Plone developers just as much as for Justin Bieber fans.

I think people are altruists by nature, not egoists. We want to do something for another. Our need for emotion is bigger than our need for money.

Emotion is why Plone is still alive.

Culture

Culture is how Plone is still alive.

Our everyday miracle is: pluggability. This comes at a price. Would we release a module without tests, or with a funky css selector? No. People who build Plone add-ons are following the rules, so it is safe to install.

Old Greeks had the word 'Pharmaka' for something that heals, but can also be dangerous. 'Per aspera ad astra': through difficulties to the stars. We give core commit rights to anyone who wants to join us.

The Plone community as a whole has knowledge, a diamond mine.

Building a cathedral

Plone is like the Sagrada Familia. It was created by someone who has left, and it is still being built.




Maurits van Rees: Maik Derstappen: Subtemplates in bobtemplates.plone or on the way to plonecli

Fri, 20 Oct 2017 13:58:33 +0000

(image)

A long time ago, creating a Plone package was as simple as using ZopeSkel and then ZopeSkel sub templates to add for example a new content type. But ZopeSkel is dead.

Plone is using the new mr.bob already for years, with bobtemplates.plone as main template for a new Plone project. But there were only basic templates, no list of templates, no way to add a content type or other things with a sub template, a hard to remember command. So let's fix that!

My vision: give me a tool which helps for:

  • creating different projects, like an add-on or a buildout
  • extending packages with content types, vocabularies, a theme
  • provide best practice skeletons

Something like this:

$ pip instll plonecli
$ plonecli -l
templates:
 - addon
   - content_type
   - portlet
 - buildout
$ plonecli add content_type

Standalone templates:

  • addon: basic Plone addon
  • buildout: development/project buildout
  • theme_package: full stand-alone theme package, based on Barceloneta, with grunt setup

Sub templates:

  • content_type: Dexterity CT with XML or zope.schema
  • vocabulary: dynamic vocabulary
  • theme: advanced theme, including themesitesetup and themefragments
  • more to come: tile, behavior, portlet

I have a fork of mr.bob that can list templates.

On plonecli you could use shorter, more easier to remember commands, and I want autocompletion to make it even easier.

We will sprint on this, so please join.




Maurits van Rees: Hanno Schlichting: Zope on Python 3

Fri, 20 Oct 2017 13:30:23 +0000

I am currently still the release manager for Zope. There is now a actually a release team. Plone is built up like this: Python is the programming language. On top of this is the ZODB and the ZCA (Zope Component Architecture) Then the ZTK (Zope ToolKit), just a bunch of packages. Above it is Zope (2.x/4.x) Then CMF Then the Plone CMS Unrelated to Plone: Pyramid sits on top of the ZCA. Grok sits on top of the ZTK. The ZTK (like zope.interface and zope.component) was already mostly Python 3 compatible at the moment when we started working on compatibility for Zope. Jason Madden has done a lot and Marius Gedminas, Tres Seaver, a bunch of others.. There is very little development on the ZTK level, mostly just letting it work on newer Python versions. Alexander Loechel already gave a talk on this conference about porting RestrictedPython. We no longer call Zope Zope2, but just Zope. This is version 4. Forget about version 3. ZODB and the ZTK support Python 2.7, 3.4, 3.5, 3.6, PyPy, PyPy3. Status page of Python 3 compatibility for Zope related packages: https://zope3.pov.lt/py3/ More on the ZTK: https://zopetoolkit.readthedocs.io/ Zope 4.0 beta 2 has been released. That means no new major features should be introduced, focusing on bug fixes. Zope supports Python 2.7, 3.4, 3.5, 3.6. There is no support for PyPy or PyPy3. RestrictedPython is a big reason there, because that is currently just not possible on PyPy. For Acquisition you also have to use a C implementation, so no PyPy. On https://blog.gocept.com you can find some good reports and stories about the Zope porting sprints. CMF 2.4 beta is released. It targets Zope 4 compatibility. Currently only Python 2.7, but progress is being made on Python 3 support. The Plone community is also busy with that. Some other changes in Zope 4, not Python 3 related: The distribution name was changed from Zope2 to Zope. Zope2 is now a meta distribution, depending only on Zope. This is similar to ZODB3 being renamed to ZODB. Please keep Zope2 as dependency in your own package, unless it really only works on Zope 4. Zope now uses WSGI, and there is a separate ZServer project. ZServer was written in the days of Python 1.5, so really old. We wanted to get rid of that and use WSGI instead. But to not completely lose the old code, we made this new ZServer project. The WSGI server only supports HTTP, not for example FTP. Also not WebDav as that was really to hard, although it is built on top of HTTP. Probably ZServer is never going to be ported to Python 3. So with WSGI you use something like waitress or gunicorn or Apache mod_wsgi to call Zope. There are more optional projects for Zope now: ExternalMethod PythonScripts MailHost TemporaryFolder Sessions SiteErrorLog (instead just use the standard Python logging and the WSGI solutions for logging) Some of these have been ported to Python 3, some not. More changes: There now is a WSGI based zope.testbrowser. The old test browser was based on mechanize, which was not maintained and not ported, and that was not going to happen. There is full IPv6 support in waitress. Chameleon page templates is in Zope, without needing five.pt anymore. zope.globalrequest is in Zope, without needing five.globalrequest anymore. Upcoming minor change: support for unicode object ids under Python 3. Zope 4 was started five or six years ago. The idea was first to remove lots of things to make it simple[...]



Maurits van Rees: Johannes Raggam: Resource Registry Demystified

Fri, 20 Oct 2017 11:34:39 +0000

The rewrite of the RRs (resource registries) started in 2013 or 2014 and landed in Plone 5.0. I would recommend using Plone 5.1, as various things have been improved there. With the RR you register and deploy JS and CSS. You can organise dependencies, and optimise resources and number of requests. The resources are grouped into bundles, they are concatenated and minified. Add-ons can easily register their resources. Cache headers are set automatically. In Plone 4 there were no formally defined dependencies, so that made it hard to manage. You just had a list, and that order was used. In Plone 5, the RRs are based on plone.registry, RequireJS, LESS and the command line interface of gulp. Instead of LESS, a lot of projects have switched to using SASS now. RequireJS is also less popular. So there is still room for advancement. The Plone 5 way solves dependency management, but it is complexer and harder to debug. I have had my problems with it, but usually it works quite well, and is a huge improvement over Plone 4. The js/config file in mockup contains configuration on how the javascript in Plone should be built. In Products/CMFPlone/static/plone you can see how the plone bundle is defined, and what it requires. You can still define legacy resources, which work like they did in Plone 4. They are wrapped by some code that temporarily undefines the define and require definitions, otherwise you get errors. In Products/CMFPlone/static/plone.less all the needed LESS definitions are imported or defined, used for creating our CSS. LESS is very handy for defining for example a text color once and use it in lots of places. [In Plone 4 we did this by using DTML files.] You can customise and override the plone and plone-loggedin bundles in your code, if you maybe do not need everything that Plone offers by default. collective.lazysizes has a good example of defining resources and bundles. In its registry.xml it uses condition="have plone-5" to only apply this part on install when the site is Plone 5. With ./bin/plone-compile-resources -b plone you compile the plone bundle resources. This is also possible TTW, but I recommend the command line tool. Future Use webpack for compiling bundles. Asko Soukka has started with this for Plone. You can already use it, but it is too early for Plone core. There are some things to fix. I would like to not use RequireJS anymore, which would make it easier to use webpack; instead, ReactJS would be better. The legacy resources currently need special configuration, and that is not very expandable. PLIP 1955 for RR improvements, but on hold now for lack of time and vision PLIP 1653, restructure CMFPlone static resources [...]



Maurits van Rees: Devon Bernard: Lean React - Patterns for High-Performance

Fri, 20 Oct 2017 10:37:00 +0000

(image)

Get a normalised state for your json data. Think about how to structure your data so you don't duplicate data, and you have quick retrieval. For example use the normalizr library.

Use Redux development tools to give you hints or boiler plate for a new test.

Use components. When you use them, make sure they don't block other components: if four other components are not getting shown until a fifth one is ready, that is not a good idea. Give the user the information that is already there. Already show a skeleton on the page of how the component is going to look, so you only need to fill in some extra stuff and the user can already see how the component will look like.

Watch the component life cycle: which part is taking the most time?

Check if repainting is really needed before you do it: maybe a data value gets set but it is the same as the old value. Catch this and save on rendering. Use the Chrome Render Tools.

Use local, non-committed environment files to make differences between local development and production. .env may contain the default values for everyone, committed, and .env.local has your local tweaks, and you let git ignore that.

Use route wrappers to for example ease checking for anonymous or authenticated users, and do some calculations in there, so you don't need to do that in all kinds of places.

Offline first: have some javascript that runs in the background for hijacking netword requests. If you are offline, this should queue the network requests for later. IndexedDB could be more useful here than localstorage.

Use the ESLint command line utility to check the quality of your code, including your fellow developers.

Find me on Twitter: @devonwbernard.




Maurits van Rees: Alexander Loechel: Modern Python Testing

Fri, 20 Oct 2017 09:52:19 +0000

I have worked in the German air force. They have rules on how to write software. For example, you start with user requirements. In open source, who is writing down user requirements? The requirements are there, but they are often implicit. Write tests that test the requirements. 'Testing leads to failure. Failure leads to understanding.' A test is a specific set of assertions. You can test requirements, design, interfaces, code/implementation, documentation (embedded code), conventions. The basis for tests in Python is the unittest module. It has lots of specific assertions, like assertEqual, assertIsNotNone, etc. But why can't we simply use assert? That is what the pytest module does instead. It makes writing the test simpler. It is by now the de facto standard in the Python world. It has a pluggable add-on system. There is unittest2, nose, nose2, but today they are mostly outdated. Use pytest. Robot framework is used by Plone to do web testing with a real browser. Richard Feynman: 'The first principle is that you must not fool yourself, and you are the easiest person to fool.' For test runners we have the unittest testrunner, zope.testrunner, pytest-testrunner, gocept.pytestlayer. Such a runner collects tests for execution and shows the outcome to the user. If you use unittest, you can use these. A test runner can interact with other tools, like coverage. On a command line you can usually run python setup.py test to run tests. Or you have scripts to run it, like buildout can install with a recipe. You want to run your tests automatically on a test server: Travis CI has Linux and MacOSX machines, and are perfect for pure Python tests Circle CI has Docker containers for Linux and MacOSX Appveyor tests on Windows. On Travis you can use travis_retry in your .travis.yml file to retry a command three times. This can help when there is a temporary network problem. tox is a test invocation tool. You use it to run your tests on multiple environments, for example Python 2 and 3, or with an extra package installed. You can use additional helpers like pyenv for virtual environments. One of the environments can apply isort, or run zest.releaser, even if these environments are not run by default. Or you can run a linter and have it report on your code quality. My wishes for better practices in Plone: Adapt tox on all packages. Switch to different package structure and enforce that, like bobtemplates.plone, with docs, src, Tests. Maybe do not ship with the tests in the PyPI releases: this code will not be run in production. Tests belong in the source distribution, but not in binary packages like wheels or eggs. The unit tests should be tested within the actual package. Integration tests could live somewhere else. See http://plone-best-practices-discussion.readthedocs.io/ See the slides.[...]



Maurits van Rees: Nathan Van Gheem: Introduction to Python Asyncio

Fri, 20 Oct 2017 09:48:06 +0000

This is about the Python 3 core asyncio library. "This module provides infrastructure for writing single-threaded concurrent code using coroutines, multiplexing I/O access over sockets and other resources, running network clients and servers, and other related primitives." The first time I read that I was like: what? Asynchronous programming using async and await syntax. Any network activity should not block other code, that is the main idea. This is useful because web applications use TCP sockets. It is a way to improve performance and scale web applications. Also think of microservices. The optimised event loop allows you to handle a larger number of requests per second. You can have long running requests with very little performance impact. With standard Plone that is impossible. Requirements: Python 3.4. How are typical web servers designed like Flask, and Django? Each request is tied to a thread, so you are limited to handling number of threads and processes you run. Threads are expensive (GIL, context switching, CPU). If no threads are available, further requests are blocked, waiting for an open thread. Threads are blocked by network traffic, for example to a database server. With asyncio, requests can be tied to tasks. You can have lots of tasks per thread, and if a task needs to wait for network traffic, it does not hurt you. But be careful: if anywhere in your code you use the requests library instead of asyncio, that will block your network traffic. We have Futures`.  ``asyncio.run_until_complete with ensure_future wraps your asynchronous call in a Future object. You can have long running Tasks. Tasks, futures and coroutines are very similar, in the beginning you don't need to worry about that. Gotcha: everything must be async. Async functions need to be run by the event loop. If you run it manually, it will not do anything. If you don't call an async function using await it will never be run either. asyncio is single threaded: only one event loop can run in a thread at a time. Running multi threaded code in asyncio is unsafe. You can have multiple threads, each having their own event loop. You can get the feel of multiprocessing by using asyncio.gather With an 'executor' you can make synchronous code asynchronous. Typically it is a thread executor. Try to avoid it, but it is a tool that you can use if needed. See concurrent.futures. asyncio comes with an amazing subprocess module, so you can await the result of executing a command on the terminal. The event loop is pluggable, for example tokio. More and more libraries are popping up using asyncio: aiohttp: client and server library aioes for elastic search asyncpg for postgres aioredis aiobotocore aiosmtpd for smtp [See https://github.com/aio-libs for more.] Debugging is more difficult than regulare sequential programs, the pdb is tricky. aioconsole allows you to have a Python prompt with an asyncio loop already setup for you. guillotina uses asyncio. In Python 3.7 you have an execution context, which is going to be nice. Questions and answers: You cannot do WSGI with asyncio. But Tornado uses asyncio. What was hardest? Wrapping your head around it all. Is this only for network calls? Or also useful for disk access? There is an add-on for that. I tried it and then it was kind of a hack. Do you h[...]



Maurits van Rees: Bert JW Regeer: I broke what? Taking over maintenance on existing (well loved) projects.

Fri, 20 Oct 2017 08:42:00 +0000

Existing code needs love too! Look at the truth behind open source apps on commitstrip. You can help open source projects by becoming a maintainer. I became maintainer of WebOb. What I was told: don't mess it up. There was no existing maintainer at the time. It was handed over to the Pylons project for maintenance, but no single person was responsible for it. They all stepped back. Side-track: imposter syndrome. See Denys Mishunov's talk yesterday. Usually you get extra responsibility gradually: for example first commit rights, then release rights. You may think you are not good enough for extra responsibility, but probably you are. You have all these nice ideas and good intentions. You push out some alphas and betas, all seems okay. You make a full release. Then a bug report comes in because you removed something that you did not expect anyone to use. Code grows over time. All kinds of code is there because it fixed an actual problem for an actual user. So you are faced with backwards compatibility. How much of it do you do? It depends on whether you are using a library or a tool. Libraries need to maintain more backwards compatibility. For a command line tool, the only API is the tool, not its internals. Can you afford to lose your users? Someone can fork your code and maybe rename it and create an alternative tool. Testing: if you have 100 percent test coverage, and you change something and a test breaks, then you can more easily see what is wrong. Does the test simply need to be rewritten for the new situation? Or is the test breakage a hint that something will break for a user, letting an old bug resurface? You sometimes have to make a breaking change. Give a deprecation warning then. Joel Spolsky: 'Single worst strategic mistake: rewrite the code from scratch.' This was about NetScape 6, and allowed Internet Explorer to catch up and take over. It is an option, but probably not the best. So. You took over. You are now the gate keeper. You are a temporary guardian. Eventually someone else is going to take over. You should start looking at mentoring opportunities. Find ways to engage others, engage the community. Create pull requests instead of pushing to master. Reach out to other communities, consumers of your code. Can you help them? People may ask or tell you to just accept this pull request. Just push out a new version. Just is a bad word. Push back and insist on them following the standards of your project. If you require 100 percent test coverage, don't review the pull request. I have received bad bug reports, so now I myself write better bug reports. I push myself to do better. Maybe even try to provide a fix for a bug upstream. Be friendly when someone does crazy or seemingly stupid things in a pull request. A good question to get clarity is: 'What are you trying to accomplish?' Twitter: @bertjwregeer.[...]



Maurits van Rees: Mark Pieszak: Rendering JavaScript on the Server? Welcome to Angular Universal.

Fri, 20 Oct 2017 07:58:54 +0000

(image)

[Sorry Mark, I came in late.]

SSR = server side rendering

Create an app.module.ts and an app.server.module.ts

  • Static SSR is done at build time.
  • Dynamic SSR is done at run time.

SSR gotchas:

  • If you use window or document, the server does not know what to do: this only lives in the browser. If you must, create a WindowService and use dependency injection to provide different versions. Use isPlatformBrowser() as much as possible. Hide things from node. Not all parts need a server version.
  • Be careful with timeouts, because they will let your server wait.

Conclusion:

  • Universal makes SEO possible.
  • Universal gives really fast initial painting of your app, and you keep the interactivity. Can be two to three times faster on mobile.
  • Be mindful of browser-specific things you might be using in your code.
  • Choose third party libraries carefully, as they need to be mindful of the pitfalls as well.
  • It takes a bit of work, but it is worth it

Further reading:




Maurits van Rees: Annual membership meeting Plone Foundation

Thu, 19 Oct 2017 16:11:39 +0000

(image)

Plone Foundation president Paul Roeland presents the report of the past board year. Documents can be found on plone.org.

There were lots of sprints, most of them sponsored by the Foundation.

Eric Steele was interviewed by podcast init, which you should listen to.

At http://smile.amazon.com you can by stuff from Amazon and have Amazon give a percentage to the Plone Foundation, at no cost to you.

Sad is that long time Python organiser Jean Ferri from Brasil passed away.

Financials. Summary: we are doing fine, and can afford to spend a bit more. We would like more sponsorships, like providers on plone.org.

The entire current board nominate themselves for the new board, and there are unfortunately no other candidates, so we can have an easy vote.

Erico motions to approve the candidates. Maurits seconds this motion. Philip and Alexander abstain. Otherwise everyone says aye. The old board is hereby the new board.

Erico: Is the Foundation supporting bitcoin donations? The Free Software Foundation does.

Paul: Not at the moment. Depends on our bank account.

Matthew: Does the Foundation have an environmental policy?

Paul: We have recommendations. For this conference it does not really work, also because we have a caterer.

Paul: We may want to open up the Plone Foundation to family and friends, like guillotina and Pyramid. Pyramid lacks a legal framework currently. This needs careful reflection before we do anything, but the board is initially open and positive to it.

Paul: We are sometimes in difficult discussion with the Zope Foundation, which does not technically exist anymore, linked to the Zope Corporation, which technically does not exist. So the situation is unclear. We are working on it.

Philip: At Zope sprint in Halle there was consensus to unwind the Zope Foundation and incorporate everything in the Plone Foundation.

Alexander motions to adjourn the meeting and go party. Fred seconds. All say aye.

Thank you and have a great party. Party responsibly and be there tomorrow at nine for the keynote speaker.

Oh, there were two proposals for the next Plone conference. The board did due diligence and found that only one was viable. It will be announced tomorrow.




Maurits van Rees: Lightning talks Thursday

Thu, 19 Oct 2017 15:43:05 +0000

Andreas Jung: Plone and the blockchain Blockchain is the base technology behind bitcoin, but it is not bound to crypto currencies. It is a distributed data structure, usually based on peer to peer. No central entity of control. Each block has a hash of its previous block, timestamp, transaction root, and a nonce. Use cases: auditing, financial transactions, logistics, QA, legal, automotive, others. What does this have to do with Plone and CMS? Some ideas: revision safety audit trail verification of content integrity and authenticity Our use case: collaborative editing environment. So we created SmashDocs. Using Plone and BigChainDb. Erico Andrei: Websauna Websauna is a web framework based on Pyramid. https://tokenmarket.net is created with that, also with blockchain BTW. Miko says hi! I am using it too, and helping him. We want you on board as well, and we can sprint on it. Also we want to improve Pyramid. Move Websauna to Pyramid 1.9. Documentation. User testing. See https://websauna.org. Alexander, Anton: Ploneconf and PyconWeb Why don't we make a PyconWeb conference? We did that last year. Next one starting on 9 June 1918. See you at https://pyconweb.com Fred van Dijk: Music to your ears Confession: I am a bit of an audiophile. When I talk with people about how they listen to music, I get sad. Lot of people use a ten euro headphone. "I don't hear a difference with more expensive ones." I am convinced that a better audio setup helps you work better. What is the weakest link? Music source (up the settings), D/A converter (underestimated component), cables (spend twenty euros, that's the sweet spot), headphones (ten euro and you expect quality?). If you divide the costs over the number of hours you listen music: I came at six cents an hour. Especially the D/A converter (USB) really helped me. Nejc Zupan: A few Pyramid goodies by Niteo pyramid_force_https pyramid_redirect pyramid_heroku Releases are on PyPI, enjoy! Manuel Reinhardt: Giesing 2060 Science fiction writing project about an area of Munich in the year 2060. Using Plone, two content types, snippets that give links to other story snippets, different story lines, you can read through it in various ways. If you like reading or writing science fiction or Python code, or both, have a look at http://giesing2060.de Alexander Pilz: Ten years of Euphorie A Plone success story. This is a software to guide employers and employees for mandatory health and safety risk assessment. In 2007 Euphorie was created by Wichert Akkerman and Cornelis Kolbach, with the NuPlone interface (currently still working on Plone 5 actually). In 2008 adopted by Europe. In 2016 interest by an industry client of ours. Why was this successful with Plone? Customisation and enhancement was made easy. Good security. Open source. Now they no longer need to cary kilos of paperwork to factories. Jens Klein: Alpine City Sprint I invite you to come to Innsbruck to work with us on the next Plone. Today on an open space we discussed that we may be using Zope 4 on Plone 5.2, and we can work on that. Welcome January 2018 in Austria. We always visit a special place as well, now a space lab, with simulation for Mars [...]



Maurits van Rees: Denys Mishunov: debugger; for Developers

Thu, 19 Oct 2017 14:59:52 +0000

It's been a long time since I have been in the Plone community. Good to see so many old friends! Literally old. :-) I am Denys and I have a problem. I am a developer. Should I use Angular or React? Plone? I am not going to talk about that. I am going to talk about us as humans. Goldman's dilemma, phrased in 1982: 'If I had a magic pill and it would let me win every match for the next five years, and then kill me, would I take it?' A lot of people would do that, for five years of success. There is no such pill, no single road to success. As developer your life begins, you read a first book, you do a first project, you get your first job as developer, things look good. But: our program starts raising errors. When that happens, you stop, debug, and fix. Perfectionism One of the bugs is: perfectionism. 'Denys, your work style is like champagne. The company that we merge with, their style is more like prosecco. Less good, but at a party no one notices the difference.' Perfectionism can be really good and bad. It can be healthy and unhealthy, positive and negative. Steve Jobs was a perfectionist. That worked out good for consumers, but he could be hard to work with, having problems picking the perfect beige color. Several perfectionist problems: Perfectionist paralysis. This can be one reason for procrastination, waiting for an ideal moment to start with an ideal project. Fear of failure: not getting a perfect result. They want perfect tasks, where they know they will succeed. Picking a detail. Unnecessary task. 'This can be improved. It is not hard, it would not take more than fifteen minutes.' And you spend a day on something that does not give value, or even makes things worse. Perfectionists never know when to stop. So stop being a perfectionist? No, make your perfectionism positive. Henry Ford was a perfectionist, constantly improving the design, and never going in production. He failed at two companies before investors stopped him. Think: 'My product should be perfect. And this release/feature/commit moves me one step closer to this perfect result.' Stephen Hawking: 'Perfection simply doesn't exist.' Imposter phenomenon You think that your success is due to luck/timing/etc. You think that others might discover that you are not as skilled as they think you are You think that others are more intelligent than you are. Will Smith: 'What people think is my self confidence, is actually my fear.' Lots of people have this. Among them very successful people. Both men and women have this, also in science, shown by studies. I read websites, Twitter, news feeds, RSS, I get a lot of information, but I cannot read everything. And I still have to work. So I stopped reading them. I may skim the titles, and open a few browser tabs, and leave them open for a few days. I did not want to read it, but my imposter syndrome wanted to read it. What do we do about it? Embrace imposterism. When you are about to read yet another news story: stop and enjoy. You are learning. Measure yourself with your own yard stick. That is a good comparison. Communicate your fears. Writer Neill Gaiman met Neill Armstrong. 'If[...]



David "Pigeonflight" Bain: Plone Conf 2017 Day 2: Timo Stollenwerk: Building Bridges - The Headless Future of Plone

Thu, 19 Oct 2017 08:48:00 +0000

I decided to try a Maurits van Rees and live blog a conference talk.Talk by Timo Stollenwerk on Building Bridges - The Headless Future of PlonePlone's headless futureWorking on what we call headless these days started in 2014You already heard a part of this from the Keynote (about Pastanaga UI etc..) on the first day so I won't repeat that.My ultimate goal is to bring the vision to reality.A few observationsMobile is overtaking Desktop (Plone is mobile ready but Pastanaga aims to have the best experience on every device)Open Source is Mainstream (Plone is different, today large open source projects are coming from large players like Facebook and Google, this helps to make open source more mainstream). Github looked at contributions last year and visual studio code was the project that had the most contributions... Microsoft!!)Javascript is taking over (Javascript is becoming more important, if you are a web developer in 2017 you have to learn modern Javascript)The Web is everywhere (I visited my Uncle who is a Doctor, 5 years ago and noted that he was using a web app on his desktop for viewing scans of the body)In recent studies they discovered that swift is losing popularity because web technologies are taking over. The web is coming back with technologies like Electron (Desktop) and Cordova (mobile)Isn't it a great time to be a Web, Javascript, Open Source developer in 2017?We're hearing that the CMS market is deadIf we see it in other sectors we say it is more efficient but when it happens to us we don't want to transform ourselves for the better. I think we are living in exciting times...If JS is so great why don't we just go with it and build a CMS with Javascript?Why do we keep using Python and Plone?I love Python (wasn't my first language, but the first one I loved, I still miss Python with every line of Javascript I write). I can live with Javascript for the tooling and the community but would prefer to keep Python. I can't imagine using Node on the backend because I think Python is doing a way better job on the backend.Plone the community. In the last year I've been to Jenkins, CI and testing conferences but there's no place like Plone. I went to a JS conference alone. Usually when you go to a conference alone you need to make an effort to talk to persons. Then I went to the sprint but out of 1000 persons there were only 20 or 30 persons at the Sprint. When I speak to Python conference attendees they ask me, how do you get people to come and even pay for a flight to Plone conferences, it's like magic!Plone the Software is still unique (permissions, traversal, workflows)Plone the CMS (as Eric says, Plone is doing Breadcrumbs since 2001) Go out and try all the Javascript CMSes, they all have awful user interfaces, they have nice libraries and everything you can imagine but lack the basic functionality of a CMS. I couldn't just jump and move to another system because I'd only have half or 10% of the current functionailty I have now.  We don't want to become Grandpas and isolate the new JS communities who have lots of energyWhat do we have now?Stabilising JS frameworks, it's not too hard to switch [...]



PLONE.ORG: Plone Digital Experience Conference 2017 is live, from Barcelona!

Wed, 18 Oct 2017 09:10:00 +0000

(image)

Organizers Victor Fernandez de Alba and Ramon Navarro Bosch warmly welcomed 180 participants to the Plone Conference 2017 in their home city of Barcelona, the origin of so many parts of Plone, not the least of which is the Barceloneta theme that comes with Plone 5.

Sebastià Villa, president-delegate for Information Technology at Universitat Politècnica de Catalunya (UPC), also welcomed the conference to the beautiful venue on its campus, and saluted Plone for its contribution to the UPC, while challenging the community to continue its innovation in the direction of enhanced user experience.

In the first keynote of the day, Plone release manager Eric Steele spoke to the natural process of renewal that the Plone community has already gone through in its transition from the original generation of contributors to us, the second generation. Timo Stollenwerk laid out his vision of the combination of Albert Casado's Pastanaga user interface design and Plone's REST API, forming a new direction for the future of Plone that opens it to a much larger world of modern JavaScript front end developers.

The two conference training days have been an overwhelming success, with 90 attendees learning new skills and trying new technologies at our hands-on workshops and classes.

The conference schedule continues with today's and two more days' full slate of talks, keynotes, open spaces, lightning talks, and two days of sprints.

The annual Plone conference is an open, inviting, inclusive event hosted in cities around the world. 

For more information about the conference and the ongoing schedule of activities, see the conference site at 2017.ploneconf.org

(image)

(image)




PLONE.ORG: Conference talk schedule is live!

Sat, 07 Oct 2017 18:31:15 +0000

(image)

See the conference schedule for the full week of Oct. 16-22, 2017: 

  • training classes
  • keynotes, talks, lightning talks, open spaces
  • Plone Foundation annual general meeting
  • dinner party
  • sprints

https://2017.ploneconf.org/schedule/




PLONE.ORG: Nominations Open for Plone Foundation Board of Directors

Sat, 09 Sep 2017 00:50:00 +0000

If you have an interest in helping the governance of Plone, and particularly the energy and time to pitch in, please consider nominating yourself to serve on the Plone Foundation board of directors for 2017-2018. About Board Membership The Plone Foundation is a not-for-profit, public-benefit corporation with the mission to "promote and protect Plone". That has meant that the board is involved in: protecting the trademark, copyrights and other intellectual property, including considering licensing and usage issues; hiring the release manager; working with various committees, including marketing and membership; handling "other stuff in the community" as needed, e.g. helping craft policy on plone.org and plone.com about commercial listings but not: directing Plone development. The board facilitates, but does not direct, the development of Plone itself. While there's lots of work that happens online, much of the critical business of the board is conducted during video meetings every two weeks — typically, board meetings last about an hour to 90 minutes though occasionally they can run over to handle time-critical issues.  Please consider whether this fits your schedule, since missing more than an occasional meeting severely limits the ability of the board to reach quorum and conduct business. Historically, board meetings have been organized to occur during daytime hours in America and evening hours in Europe, currently at Thursday nights, 19.00 UTC in northern hemisphere summer and 20.00 UTC in northern hemisphere winter. That can always change with new board members. In addition, there is a board mailing list (private), where we discuss things in addition to the meetings. This is a working board. Be ready to regularly take on and complete responsibilities for board business. The board writes no code and makes no development decisions. It is much more concerned with marketing, budgets, fundraising, community process and intellectual property considerations. You do not need to be a Foundation member to serve on the board (in fact, board leadership is an excellent way to become a Foundation member). All you need is to get an active Foundation member to second your nomination. The Plone Foundation is interested in broadening the diversity of our leadership, with regards to gender, ethnicity, and geography. If you have questions about the nomination process, contact the board: board@plone.org Nomination Process Log in on plone.org and go here: https://plone.org/foundation/meetings/membership/2017-membership-meeting/nominations Add a page there with your name in the title. For the body, discuss: Who you are Why you're interested What you think you can add to the Plone Foundation Most importantly, the name(s) of one or more Plone Foundation members who "second" your nomination Once ready, click "submit for publication" in the workflow drop-down menu to get a reviewer to look at your nomination. Nominations will be accepted until October 15 2017, 23.59, UTC. The election will be conducted [...]



David "Pigeonflight" Bain: Help two Plonistas get from Jamaica to Barcelona (Catalonia) for the 2017 Plone Conference

Thu, 07 Sep 2017 01:23:00 +0000

Jamaica to Catalonia for Plone Conference 2017TL;DR - David Bain and Oshane Bailey are looking to attend the 2017 Plone Conference via crowd funding.Sept 20, 2017 Update: We will mostly be walking so this reduces our transportation costs, we've adjusted our target to reflect this. We've extended the campaign until September 27.Sept 17, 2017 Update: We're finding some cheaper fares, adjusting our target to reflect thisSept 16, 2017 Update: Oshane has been offered a free room, this will lower the overall target furtherUpdate: It looks like there are more cost effective accommodation options, as a result, we've further adjusted our estimates.Update: We have found some cheaper flights via Google Flights so we're adjusting our estimates down by $2,000.   (David's the one on the right).This is a manually managed crowdfunding tracker updated by David (no AI was harmed in the creation of this tracker) We are trying to get from Jamaica to Catalonia for the 2017 Plone conference.  Our target is to raise a significant part of the roughly USD$7,000 USD$5000 USD$4,400 USD$3,700 USD$2,900 needed to cover airfare, accommodation etc.How to support usYou can contribute to our travels via Paypal (see the button below), funds go to my Paypal account.Why support us?Support us so that we can deliver training, talks and participate in the sprints*.Getting us there will allow David to deliver training and a talk or two, Oshane will be able to share his Google Summer of Code experiences and participate in his first face to face community sprint after the conference. Oshane worked this summer on improving the theme editor experience, here are some links with more information about what he did...https://community.plone.org/t/gsoc-2017-improving-the-theme-editor-experience/3906https://community.plone.org/t/thank-you-for-the-support-during-gsoc-2017/4792We're hoping he'll be able to present his experience as a talk at the conference.David has been an active part of the community for many years. He delivered training and two talks at the last conference and has been invited to be part of the training team at the 2017 conference as well.Both of us are really excited to participate this year, however the cost of airfare is prohibitive.* While Oshane will stay for the sprints, due to family commitments, David won't be able to stay for the sprints. Rough Breakdown of expenses[...]



PloneExpanse: Identifying and fixing broken objects in a Plone website

Wed, 06 Sep 2017 17:30:18 +0000

(image) I’ve removed plone.app.stagingbehavior from a website because the new plone.app.iterate has the same functionality. In addition, the p.a.s package was overriding adapters that I wanted to write. Now, my problem was that I could no longer save any related items, I would get an error: Module ZPublisher.Publish, line 138, in publish Module ZPublisher.mapply, line 77, in mapply Module ZPublisher.Publish, line 48, in call_object Module plone.z3cform.layout, line 66, in __call__ Module plone.



TestTheDocs: Tips For Writing Documentation

Mon, 04 Sep 2017 10:45:36 +0000

(image) Prologue Being busy now for more than month improving the documentation for the Plone trainings with lots of interesting and eye opening moments it is time for some words of wisdom :) First of all I would like to say thank you for all people who took time to contribute you are awesome ! As I said already before, writing documentation is not easy. Besides the knowledge about the topic you write about, you need to know how to reach your audience (tone of voice), how to structure and how to write your docs in a appealing way (more on that later).



TestTheDocs: Create Plone Training Documentation With Ease

Mon, 21 Aug 2017 10:12:40 +0000

(image) Creating Documentation Is Hard Writing documentation is not easy !. There is much more involved than just writing. You have to think about the tone, the audience, the structure of the docs and much more. Making It A Bit Easier To make this process a bit easier and with the hope to get the Plone Training Documentation better organized and unified we are happy to announce the first release of Cookiecutter Templates For Plone Training.



PLONE.ORG: Announcing the Plone Conference 2018 selection process

Mon, 14 Aug 2017 13:46:00 +0000

(image)

With Plone Conference 2017 drawing near, it is time to begin planning for our next conference in 2018.The annual Plone Conference brings together users, integrators, developers, designers, and other interested folk from throughout the world for a week of training, talks, and sprinting. Plone conferences are also an expression of community spirit: they are organized by a company, user group, or other entity with ties to and a history with the Plone community and are in essence not-for-profit events.

The Plone Foundation is soliciting proposals to host the 2018 Plone Conference. The selection process this year begins in time to allow for final selection of the conference venue during this year's Conference. The extended timeline allows groups and organizations interested in hosting the 2018 Plone Conference (or beyond) to work with the Barcelona team for hands on experience during this year's conference.

Let's revisit where we've been so we can determine where we might want to go: we've traveled the world from New Orleans, Louisiana, USA for the first Plone Conference to:

  • Vienna, Austria
  • Seattle, Washington, USA
  • Naples, Italy
  • Washington, D.C., USA
  • Budapest, Hungary
  • Bristol, UK
  • San Francisco, CA, USA
  • Arnhem, Netherlands
  • Brasilia, Brazil
  • Bucharest, Romania
  • Boston, MA, USA

and this year to Barcelona, the capital of Catalunya in Spain. But, there are many places yet to explore! If you have a place in mind, don't be shy: submit a proposal!

The Plone Foundation will accept proposals beginning September 1 through September 28, 2017.

The Foundation Board of Directors will review proposals and open those that are viable for voting by the Foundation membership between October 9–13, 2017. The winning proposal will be announced at the end of Plone Conference 2017 in Barcelona.

Everything you need to know to submit a proposal, including the full schedule for the process and in-depth requirements for hosting, is outlined in the official Plone Conference 2018: Call for Proposals.

On behalf of the entire Plone community, we look forward to your conference proposals!




TestTheDocs: ttd-textlint released

Mon, 14 Aug 2017 11:38:39 +0000

(image) 0.0.1 Released ! We are happy to announce the first release of ttd-textlint. The Plone Conference 2017 is getting closer. You should attend ! Even if you are not using Plone there are plenty interesting topics and a truly awesome community ! As you may know, there is also training included, yes that is right, no extra costs for trainings as the fees are already included into the ticket price !



David "Pigeonflight" Bain: Why you had problems figuring out Plone (the webinar)

Thu, 03 Aug 2017 22:32:00 +0000

Presenting... Why you had problems figuring out Plone (the webinar). Okay, that's not the actual name of the webinar. Instead, we went with the more descriptive but slightly less clever Plone for Newbies - The Big Picture.The Big Picture is about understanding the model.If you're a developer about to begin your journey of Plone development, The Big Picture aims to fill out your understanding of how the pieces of Plone fit together. Thinking of it as a purpose built system lays a strong foundation for success.Only smart persons use PloneI've heard someone suggest that you have to be really smart to use Plone (implying that it is hard to use). I call it the "this helicopter is harder to use than my bicycle" problem. Every time I benefit from Plone's link integrity support, flexible access control model or use cut and paste to move content around I'm glad I'm not using a "bicycle". I like to point out Plone's comprehensive suite of tools which you'll be glad exist when you need them. For developers, once you accept that you're looking at a "helicopter" you need to spend a little time "understanding the model". As you understand the purpose of the major controls you'll find it easier to use the system to solve problems.Why Plone? Now is the right time, with an increase of cybersecurity related issues, organizations should be looking to adopt secure platforms. I've been using Plone for more than 15 years, and I can confidently recommend it as a secure platform. In case you took your eye of Plone for a few years, now is a great time to give it a second look, it has kept up with modern development practices and remains an excellent choice for your content management needs.Why a webinar? My target audience isn't in one geographic location, the most effective way to reach them is a virtual medium and webinars provide a well-known, tried and tested approach.Additionally, I have run one or two webinars before, if you count online training courses. Of course, it is different when you are doing more than just showing up, reaching out to a "less captive" audience and convincing them to commit 90 minutes to a webinar. So this is new ground for me. I am learning a lot from this experience and have had a fleeting thought, maybe I'll take all this webinar and Plone stuff and do the "meta" thing, build a webinar management tool on top of Plone. You never know.[...]



PloneExpanse: Restore missing blobs from blob cache

Thu, 03 Aug 2017 13:40:28 +0000

(image) I had a curious case of missing-but-present blobs in an old Plone service, configured with a Zeo server and 2 Zope instances. The root of the problem (I think) was that the blob folder configuration was broken: the Zope client instances were configured with shared blobs to “off”, but they were really sharing the same caching folder. In the end, the blobs were loaded by the Zope services and everything appeared to be working, but when I’ve tried to move the blobstorage folder to a new machine, I ended up with missing blobs.



PLONE.ORG: Submit your talks, take classes, and see the full keynote lineup: Plone Digital Experience Conference 2017 in Barcelona

Wed, 02 Aug 2017 18:40:00 +0000

(image)

Hear ye, hear ye!

We are accepting talk proposals now: submit your talk for any of the three tracks (Plone, Python web frameworks, modern JavaScript).

See our complete lineup of keynotes

  • Denys Mishunov (all-round frontend developer)
  • Éric Bréhault (Plone Framework Team member / Makina Corpus)
  • Eric Steele (Plone Release Manager / Salesforce)
  • A. Jesse Jiryu Davis (Staff Engineer at MongoDB)
  • Simona Cotin (Cloud Developer Advocate for Microsoft)
  • Mark Pieszak (Angular Universal team member)

Check out the list of training classes that you can take FOR FREE (included in your conference ticket) and use the training signup form to reserve your spot.

Buy your tickets now before all the early bird discounts are gone!

Image credit: https://www.flickr.com/photos/x-ray_delta_one/8378622137




PLONE.ORG: Report from Midsummer Sprint 2017

Mon, 17 Jul 2017 13:55:00 +0000

There were 18 participants at Midsummer Sprint in total. The participants included, of course, the organizers, the local development team for Plone based and related services, a GSOC student working on a Plone Foundation mentored topic, a professional UX designer and many well known names from the Plone community. While the sprint was unable to fix as many content editing related issues as was hoped for, it definitely managed to get the best out of its participants: The local developers submitted their Plone contributor agreements to be able to push their patches upstream, they learned how those patches were made, tested and reviewed in practice, and they got to know many experienced Plone developers in person. They researched and fixed many Plone 5 issues with PloneFormGen. Maik Derstappen did spectacular work at the sprint by cleaning up and fixing the code base for a major security feature of Plone called safe HTML transform. Peter Holzer continued on earlier work by Jens Klein and introduced an optional Show Toolbar permission to control when the full toolbar is shown, and an alternative member tools dropdown menu to show a minimal set of required actions (including logout) for logged-in users when the real toolbar is not shown. Peter Holzer and Asko Soukka redesigned the Translate menu of Plone Multilingual support to be much simpler and more consistent with the other menus in Plone's editing toolbar. Stephan Klinger championed to implement the PLIP for adding the missing redirection management UI for Plone, based on the existing (but lacking) RedirectionTool add-on. Eric Steele and Philip Bauer completed the long-awaited refactoring of Plone login forms. Sven Strack, Paul Roeland and Alexander Loechel worked on better tools for building and testing the documentation, a better theme for the upcoming Plone 5.1 documentation, better readability of the documentation on mobile devices, improved documentation on how to contribute to the Plone documentation and more. In addition, Paul fixed a few reported accessibility issues in Plone 5. Other interesting developments at the sprint included Maik implementing sub-templates into bobtemplates.plone, Alexander adding tox-based test setup into bobtemplates.plone and Jussi Talaskivi enhancing plone.docker. Albert Casado completed the design for Pastanaga UI components and composed a visual style guide to help with the reference implementation and later adaptations. Victor Fernández de Alba and Timo Stollenwerk supplemented Albert's work by bootstrapping a ReactJS-based reference implementation of the Pastanaga design. For more details, see the final report on Plone Midsummer Spring 2017. [...]



TestTheDocs: Henry Alpha 1 Released

Sun, 16 Jul 2017 16:55:19 +0000

(image) First Alpha We’re happy to announce the first alpha release of henry ! Get it from GitHub ! Make sure to read the release notes ! Status At the Plone Midsummer Sprint we gave a talk about the state and future of the docs. During this talk we introduced henry to the Plone Community. Throughout the sprint week, participants started already using henry for building the docs. Even henry is still alpha and has some rough edges it works already.



PLONE.ORG: Report from Plone Open Garden 2017

Wed, 05 Jul 2017 19:50:00 +0000

Report authors: Christine Baumgartner, Jens Klein, Fred Van Dijk Plone Roadmap and Future Directions Plone community members from around the world once again met for the 11th Plone Open Garden (PLOG) at the Hotel Mediterraneo in beautiful Sorrento, Italy, from April 18 to April  22, 2017. The aim of the gathering near Naples was to discuss and refine the roadmap for Plone 6 to continue work on the new Plone Headless CMS initiative to decide on a new way of integrating Plone with its increasingly important JavaScript components. PLOG’s new stewards “PLOG is a strategic sprint for the Plone community,” explained Jens Klein, a returning attendee from Austria and member of the Plone Framework Team. For the first time since PLOG's founding by Abstract Technology in 2007, the organization of the sprint was handed off to the general Plone community. Thanks to the gracious efforts of Abstract’s Vicente Barone, Rosario Savarese, and Maurizio Delmonte, the transfer went off without a hitch, continuing the tried-and-true formula that has worked for years. “Networking, getting a feeling of current directions of the project, and identifying integrators' operational needs” are the reasons why Christian Theune traveled to PLOG from Germany to participate in discussions. New opportunities with the Plone Headless CMS The web’s front end, rendered by JavaScript running in the browser, has been evolving away from server-generated HTML and toward pure client-based rendering, which provides faster, richer user experiences, especially on mobile devices. The fast pace of JavaScript framework development has made it difficult for developers to choose a framework that will be around for the long haul. In contrast, Plone as a back end storage system is stable, secure, and scalable, and comes with a complete, time-tested set of data management, workflow, and authorization functions. With the Headless CMS initiative, the Plone community has found a way to combine Plone’s back end strengths with the richness of the rapidly changing JavaScript landscape. The Plone community’s decision in 2014 to proceed with the adoption of a full API and accompanying REST API has come to fruition by making possible the decoupling of the rapidly changing JavaScript front end from Plone's stable back end.   Plone as a headless CMS, in turn, offers the JavaScript world a mature and flexible back end on which to build its web and mobile applications. In a video presentation at PLOG, Ramon Navarro-Bosch from Barcelona and Nathan Van Gheem from Green Bay, USA, shared their experiences experimenting in depth with the headless CMS approach using an Angular-based client with Plone’s REST API. Eric Bréhau[...]