As part of the process of adding more UnitTests to TeamMentor (while using WebStorm) I’m starting to convert some of QUnit Tests written a while back into JsUnitRunner (which I can execute directly from WebStorm’s IDE)
The process is quite easy since WebStorm already supports JsUnitRunner, which is explained in detail in this JetBrains JavaScript unit testing support blog post.
A personal blog about: transforming Web Application Security into an 'Application Visibility' engine, the OWASP O2 Platform, Application/Data interoperability and a lot more
Friday, 25 January 2013
Wednesday, 23 January 2013
Trying out SendGrid for cloud-based emailing (with nice intro video)
I need a solution to send emails (TeamCity build events, TeamMentor user’s activities, etc…), which basically means that I need an SMTP server.
Looking around it looks like there are 4 solutions:
Looking around it looks like there are 4 solutions:
- build an manage an SMTP server
- use a google gmail account (via smtp)
- use Amazon Simple Email Service Beta (Amazon SES)
- use SendGrid
The power of Static Analysis to create solid code (in this case JSLint)
I just spent some time using JSLint inside WebStorm cleaning up and refactoring the TeamMentor’s GlobalVariables.js file, so that It shows the much desired green box (top right)
Labels:
Security as TAX,
TeamMentor
Can Git be used instead of Word's 'Track Changes'
Absolutely.
Text changes are just a simplified version of source code :)
Here are a number of really amazing 'non-code' stuff that is happening with Git's content-versioning capabilities:
Text changes are just a simplified version of source code :)
Here are a number of really amazing 'non-code' stuff that is happening with Git's content-versioning capabilities:
Labels:
Git
Great Visualization presentation and style from Hans Rosling
From Arvind's Fantastic data visualizations post, here are two TED videos that show Hans Roslin's brilliant way to present lots of data, using powerful visualization tools and animation:
Labels:
Visualization
Daniel Pradilla on 'Stop punishing your users and learn some design'
Daniel Pradilla has a great post on Stop punishing your users and learn some design which is also been discussed on reddit
Try F# online (using Silverlight)
Just noticed the http://www.tryfsharp.org/ which looks really good:
Labels:
Education,
O2 Platform,
REPL
Why does YouTube still require Flash in Jan 2013!!!!
I thought flash was over and I find it ridiculous that I need to have it just to see a Video:
Downloading O2 Platform v4.5 and manually updating the scripts
Here is how to manually update the O2.Platform.Scripts if you are running the version available for download (vs from a GitHub clone)
You start by downloading the O2 Platform it from:
You start by downloading the O2 Platform it from:
Labels:
O2 Platform
Tuesday, 22 January 2013
PoC - Selenium - Gui with 3 Hijacked Browser Windows.h2
While working on TeamMentor’s browser automation using Selenium, I created a pretty cool PoC/Script where I was able to show natively the 3 main browsers (IE, Firefox and Chrome) in the same Application/GUI.
The O2 Platform script is called PoC - Selenium - Gui with 3 Hijacked Browser Windows.h2, and this is what it looks like when opened up:
The O2 Platform script is called PoC - Selenium - Gui with 3 Hijacked Browser Windows.h2, and this is what it looks like when opened up:
Labels:
O2 Platform,
Selenium,
TeamMentor,
WinAPI
TeamMentor’s Javascript-based Event Driven Architecture
Arvind is looking at TeamMentor’s Javascript (see Studying TM architecture) and he is trying to figure out how certain methods or WebServices are called. In this post I'm going to try to point him on the right direction and explain some of TeamMentor’s event-driven architecture.
TeamMentor’s GUI is 100% Html/Javascript based (i.e. with no asmx or other-type of server side dynamic code).
This means that the data shown in the GUI is all fetched via AJAX (using jQuery).
To see this in action, look at the some of the calls made during main page load.
TeamMentor’s GUI is 100% Html/Javascript based (i.e. with no asmx or other-type of server side dynamic code).
This means that the data shown in the GUI is all fetched via AJAX (using jQuery).
To see this in action, look at the some of the calls made during main page load.
Labels:
Javascript,
TeamMentor
Saturday, 19 January 2013
Using TeamCity and NUnit to Start WebServer, Run Selenium Tests and Stop WebServer
Following the move to split the TeamMentor Brower automation tests into the UnitTests_WebAutomation repository, I just committed a bunch of git pushes (from here up to here) and customized a TeamCity project , so that TeamCity EC2 box will:
Labels:
NUnit,
Selenium,
TeamMentor
Is O2 like Humane Assessment?
Dennis Groves pointed me to http://www.humane-assessment.com/ saying “This looks a lot like the O2 Platform” and I have to say that at first glance, yes, yes it does:
Labels:
O2 Platform,
To Read
Talking a look at how AppScan Source creates WAFL files for ASP.NET ASMX WebServices
To try to understand how to improve AppScan’s Source support for ASP.NET based Frameworks (see Ian’s post Extending AppScan's Web Application Framework to support ASP.NET MVC) a good place to start is to look at how AppScan’s Source already does (a bit of) that for ASP.NET *.asmx based WebServices (where AppScan Source is able to successfully create Tainted Callbacks for methods tagged with the [WebMethod] attribute)
AppScan Source uses the powerful IBM research technology called F4F (Framework For Frameworks) which in practice is a bunch of *.jar files that create WAFL files.
AppScan Source uses the powerful IBM research technology called F4F (Framework For Frameworks) which in practice is a bunch of *.jar files that create WAFL files.
Tuesday, 15 January 2013
Using PostSharp to monitor WebServices Calls (deployed via TeamCity to Azure)
I just added PostSharp StarterEdition to TeamMentor
I’ve always been a fan of AoP / PostSharp, and as I need to add a number of method-driven-events-mapped-as-attributes, the time has come to use PostSharp (which is also much more mature than a couple years ago).
The registration, download and install was quite smooth
I’ve always been a fan of AoP / PostSharp, and as I need to add a number of method-driven-events-mapped-as-attributes, the time has come to use PostSharp (which is also much more mature than a couple years ago).
The registration, download and install was quite smooth
Labels:
PostSharp,
TeamMentor
Monday, 14 January 2013
Creating a Server-Side Google Analytics data submitter (in VisualStudio using C# REPL)
Following from Sending messages to TeamCity and UnitTest to check if the Google Analytics file has changed post, now that we have the ga.js hosted on TeamMentor’s code base (used to handle the original client side request), we need to add the ability to submit server-side data to Google Analytics (GA).
To do that we will need to replicate the client-site (JavaScript based) request sent to GA (Google Analytics) servers.
To do that we will need to replicate the client-site (JavaScript based) request sent to GA (Google Analytics) servers.
Labels:
REPL,
TeamMentor,
VisualStudio
Sunday, 13 January 2013
Asp.Net App_Code AppInitialize non-documented featured (invoked before Application_Start)
I was looking for a way to apply website specific customizations to TeamMentor (i.e. code that should be website specific, not TeamMentor.Corelib.dll specific).
The key requirements are that this code:
The key requirements are that this code:
- is executed as soon as possible (and only once),
- is not placed inside the Global.asax file and
- it can be used to apply targeted customization to the code in TeamMentor's CoreLib.dll
Labels:
TeamMentor
Saturday, 12 January 2013
OWASP Principles based on NHS?
For a while now, my view is that OWASP's Mission, Focus and Vision should just be: "WEB APPLICATION SECURITY"
That's it. OWASP's community and scope is so wide (a great thing) that trying to be even more specific will end up in a massive thread and unproductive discussion (where just about everybody will be a bit right about something)
Labels:
OWASP,
Philosophy
Private threads are SO inefficient, Application Security Knowledge is available at the point of Need, and Password Hashes over SSL
On the topic of Can you put this on a Hyperlinkable location? I just wrote this on an (internal TM Dev) thread about Client Side Password Hashing:
It is really painful how the current 'closed doors conversation' culture is so strong (even in a company as open and relaxed as SI)
The only thing wrong with this thread is that we are having this on a private channel. This means that:
- all the efforts put in here will be eventually lost (into the email pit),
- we lose the ability to cross-reference (and re-read) the points made here in the future
- we don't get to view/see/learn from other points of view/knowledge/experiences,
- we don't expose the process/journey that we are taking (which is very valuable for somebody in the future faced with the same questions)
It is really painful how the current 'closed doors conversation' culture is so strong (even in a company as open and relaxed as SI)
Labels:
Philosophy,
Security
My iPhone 5 was stolen yesterday
While I was at a local Starbucks on a conf call using Skype.
If I got the the sequence of events right:
If I got the the sequence of events right:
Labels:
Philosophy
Sending messages to TeamCity and UnitTest to check if the Google Analytics file has changed
Since it is a really bad idea for websites to load Javascript files from external domains, my objective is to host the Google Analytics ga.js file directly in TeamMentor’s Javascript folder (i.e. not load ga.js from Google's server (which btw, is what most websites do)).
The only potential side-effect of hosting this file natively, is if Google changes the content of the ga.js file (where we are would be using an out-of-date version that could cause problems in the way the data is processed by Google). So to handle that case, I’m going to write a unit test to compare the 'TeamMentor hosted version' with the version at http://www.google-analytics.com/ga.js (this UnitTest needs to also be executable from TeamCity)
The only potential side-effect of hosting this file natively, is if Google changes the content of the ga.js file (where we are would be using an out-of-date version that could cause problems in the way the data is processed by Google). So to handle that case, I’m going to write a unit test to compare the 'TeamMentor hosted version' with the version at http://www.google-analytics.com/ga.js (this UnitTest needs to also be executable from TeamCity)
Labels:
TeamCity,
TeamMentor,
Unit Tests
Friday, 11 January 2013
Using Selenium to Login using Multiple Browsers
Following from yesterday's posts:
- Coding Firefox in C# in real-time using Selenium's Firefox driver and
- OpenQA.Selenium.DriverServiceNotFoundException on Chrome
Labels:
NUnit,
Selenium,
TeamMentor,
Unit Tests
Is the TeamMentor Development/SDL team as good as it gets? (from a security point of view)
Thursday, 10 January 2013
Writing custom C# scripts when Edit-and-Continue is not possible
Due to limitations of Edit-and-Continue, we can’t make code changes here:
Labels:
REPL,
VisualStudio
Subscribe to:
Posts (Atom)