All Things Techie With Huge, Unstructured, Intuitive Leaps

Upcoming CloudKit Data Wipe

This email came from Apple:



Dear Developer,

We will be performing a server-side data wipe on all CloudKit public and private databases for iOS 8 beta and OS X Yosemite Developer Preview users on July 7, 2014.  The following iCloud features will be affected: iCloud Drive, iCloud Photo Library, and Mail Drop. 

Photos and videos stored in iCloud Photo Library will remain on their original iOS 8 devices and will upload to iCloud Photo Library again automatically. iCloud Drive can be re-enabled from Set up Assistant after upgrade. If you choose to store your documents in iCloud Drive, your Documents & Data will automatically be copied to iCloud Drive. iCloud Drive will not update across earlier seeds or operating systems. Attachments sent through Mail Drop will expire and need to be resent after you upgrade.

If you have any questions, visit the Apple Developer Forums.

Best regards, 
Apple Developer Technical Support

Getting Freshdesk.com SSO to work



We recently decided to use Freshdesk.com for our help desk, knowledge base etc.  Since we want our knowledge base to be private for clients only, Freshdesk requires a login.  We don't want to make our clients log in twice, so Freshdesk has this SSO or Single Sign On token system.

We use Java, and there was a java servlet showing how to sign on with a token.  However the online java in a repository didn't quite work.

Here is a working Java servlet for the Freshdesk SSO token system:

import java.io.IOException;
import java.math.BigInteger;
import java.net.URLEncoder;
import java.security.MessageDigest;

import javax.servlet.ServletException;
import javax.servlet.http.HttpServlet;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;

import com.application.User; (replace with your own user bean)

public class FreshDeskSSOServlet extends HttpServlet {

private static final long serialVersionUID = 7027717204177362374L;
private final String BASE_URL = "baseUrl including trailing slash" + "login/sso";
private final String sharedSecret = "put in shared secret";



@Override

public void doGet(HttpServletRequest request, HttpServletResponse response) throws IOException, ServletException {

try {
String url = this.getSSOURL();
response.sendRedirect(url);
} catch (Exception e) {
    System.out.println(e.getLocalizedMessage());
    System.out.println(e.getMessage());
}
}

private static String getHash(String text) throws Exception {
    MessageDigest m=MessageDigest.getInstance("MD5");
        m.update(text.getBytes(),0,text.length());
    return ""+new BigInteger(1,m.digest()).toString(16);
}



private String getSSOURL() {

String hash = null;
String url = null;
User user; //Get the user details using your current authentication system
String name = "First & Last Name";// Full name of the user
String email = "email@youraddress.com";// Email of the user
try {
hash = getHash(name + email + sharedSecret);
} catch (Exception e1) {
System.out.println(e1.getMessage());
e1.printStackTrace();
}

try {
name = URLEncoder.encode(name);
email = URLEncoder.encode(email);
url = BASE_URL + "?name="+name+"&email="+email+"&hash=" + hash; 


}catch (Exception e) {
//Handle appropriate code
System.out.println("There is an exception while constructing the URL");
e.printStackTrace();
}

return url;

}
}

Hope this helps.

Javascript Evaluation Errors in Eclipse

I have a big huge app developed in Eclipse Juno.  The app has a lot of stuff including some jQuery and other javascript frameworks.  Every time that I do a build, I get errors in the Problems tab.  When I look at them, they are all errors that Eclipse says that I have in the Javascript libraries, yet they work fine.  So what to do?

The obvious thing is to turn off the javascript evaluation in Eclipse.  This is how you do it:


  1. Right click your project
  2. Select Properties -> JavaScript -> Include Path
  3. Select Source tab. ( It's identical to Java Build Path Source tab )
  4. Expand JavaScript source folder
  5. Highlight Excluded pattern
  6. Click Edit button
  7. Click Add button next to Exclusion patterns box. (You can either use Ant-style wildcard patterns or click Browse button to mention the JavaScript file by name).
Hope this helps someone.

Joining Shutterstock.com


I take a lot of pictures.  A camera is never very far away from me.  I lead an eclectic life and I travel a lot.  I have lived in a lot of neat places.  I have a huge amount of pictures.  Some are good.  I decided that I might as well monetize my pics. I would sell them as stock photos.  Shutterstock seemed the place to do it.  They seem to charge the most for stock photos to consumers.

The first step is signing up.  No problem.  Took seconds to do. Then they want 10 of your best shots to evaluate.  I figure that most of my work is very good, so I picked 10 at random from a day's worth of shooting.  Here are my ten photos:











These are all high res, so you can click on any of them to get a larger version.

I figured that these ten photos were good enough to get me accepted as a photographer on the site.  Some of them may not be very marketable as stock photos, but they do demonstrate artistic and technical quality.

OK, so I had my portfolio.  The next step was the deal killer for me.  They wanted me to upload a piece of official government identification.  Not on your frigging life.

Every since LinkedIn was hacked and I found my password on the hacked site, do I trust anyone with my identity.  To upload a document like that is anathema to me. I am a crusader for data privacy.  I simply do not trust them with my info.

And when I saw the royalties (you can google them), I decided that Shutterstock.com was not for me.  The deal killer was them wanting identity information in the form of government documentation.  No thanks.  Live Free or Die.

By the way, all images are copyrighted by me.

Typepad Major Outage this Weekend


This weekend, I went to read one of my favorite blogs, and I got a 404 not found error.  Since this blog is slightly political, and somewhat critical of the government in a banana republic, I was concerned because the owner is also a friend of mine.  This is the government that arrested a prosecuted an activist who posted the picture of a person who died while suffering injuries in police custody.  Yes, the Bahamas is that country, and corruption and political interference in basic freedoms (speech, sexual orientation, equality of women) is a fact of life there.

As it turns out, Typepad was down with a major outage for the weekend.  They did have Twitter reports as to their status.  I feel better about my software bugs when major sites screw up.

I had to laugh at Typepad though.  They had this disclaimer:

This page (http://www.typepad.com/) is currently offline. However, because the site uses CloudFlare's Always Online™ technology you can continue to surf a snapshot of the site. We will keep checking in the background and, as soon as the site comes back, you will automatically be served the live version. Always Online™ is powered by CloudFlare | Hide this Alert

The CloudFlare thing didn't work. So much for CloudFlare. Here is a worse one for you though.  Since I was worried about my friend who is the author of the blog, I went to a website to check if TypePad was up or down.  The website is www.downrightnow.com.  I queried it about TypePad.  They said that TypePad was up -- possibly because the server was able to deliver a 404 HTTP error.  That was useless.

Calling A MySQL Stored Procedure From The Command Line With Output Parameters



I had a junior programmer ask me how to do stored procedure calls from the MySQL command line that had output parameters.  It had stumped him, and he had no other choice but to use the command line instead of a GUI tool, because he was working remotely on a Linux server.

Here is how to do it.  Suppose that the stored procedure has two input parameters and two output parameters.  Here is the syntax:


call doStoredProcedure('param1', 'param2', @t, @s);
select @t, @s;

The second line retrieves the output of the stored procedure.

Hope this helps someone.

Very Cool Gear and iOS app -Tile


OK, I gotta admit that this is very cool.  It works on bluetooth and networking.  Unfortunately it doesn't work with my beloved Android.  More information is here:  http://www.thetileapp.com/

C# - Determine if a Form is Open


I had a requirement to determine if a form was open in Visual Studio using C#.  If it wasn't open, I wanted to open a new one, and if it was, I wanted to pop it to the front.  Obviously, I needed a method to see if there was one.

Here is the code for the method:

 private Boolean checkFormOpen(string formName)
        {
            Boolean openForm = false;
            FormCollection fc = Application.OpenForms;
            foreach (Form namer in fc)
            {
                if (namer.Name.Equals(formName))
                {
                   openForm = true;
                }
            }

            return openForm;

        }

I just call this method and pass the handle of the Form name to it.  Hope this helps.

C# - Truncating FileName

Some people, especially lawyers and bankers who create documents, often have an essay for the filename.  Most systems are quite adept at handling very long filenames, but for practical reasons, I recently had to truncate a filename to 250 characters in a C# .Net program.

You simply cannot truncate with a substring, because you will lose the file extension.  Also, in the past, you could always bet that a file extension is always three characters preceded by a dot "," like .doc, or .jpg.  However now there is a good possiblity that you encounter a 5 character file extension including the dot.

So the algorithm is to get a string of the last 5 characters of the very long file name.  Then you get a substring of the first 245 characters.  The number in the substring is an index number that begins at zero, so it is 245 - 1 or 244.  Here is the code snippet:

if (filename.Length > 250)
   {
     
     String t1 = filename.Substring(0, 245);
     String t2 = filename.Substring(filname.Length - 6, 5);
     filename = t1 + t2;
   }

Hope this helps someone.

AOL Troubles ?



I mentioned in a previous blog entry that AOL was hacked and I got an email from them.  After that, I notice that I am getting AOL errors that I never had before.  I got to give them full marks for creativity in delivering the bad news with their zoid thing, but take a look at the second notice.  My settings were not available.  That's generally a sign of system cancer.

However, once the messages went away, I never got them again, so it looks like a fix.  These sorts of things make me feel better about the bugs in my own enterprise system.

Promox Product Review



I was just introduced to the open source server virtualization tool PROXMOX and I have to say that I am fairly pleased.

It was easy to set up.  You can administer the machines with a web interface and with a console, you can switch containers by typing vzctl enter and the number, and you are there.

I give this tool two thumbs up for a small virtualization effort.  I haven't used this in a large production environment.

AOL Hacked

I got this note in email box from AOL:

AOL

Dear AOL User,

At AOL, we care deeply about the safety and security of your online experience. We are writing to notify you that AOL is investigating a security incident that involved unauthorized access to AOL's network and systems. Recently, our systems alerted us to an increased incidence of email users receiving spam emails from "spoofed" AOL email addresses. AOL's security team immediately began investigating the cause of the spoofed emails. Spoofing is a tactic used by spammers to make it appear that the message is from you in order to trick the recipient into opening it. These emails do not originate from the AOL Mail system – the addresses are just edited to make them appear that way. AOL is working with other email providers like Gmail, Yahoo! Mail and Outlook·com to stamp out spoofing across the industry, and we have implemented measures that will significantly limit its future occurrence.

Although our investigation is still underway, we have determined that there was unauthorized access to AOL users' email addresses, postal addresses, contact information (as stored in the AOL Mail "Address Book"), encrypted account passwords, and encrypted answers to security questions that we ask when a user resets his or her password. We believe spammers have used this contact information to send spoofed emails that appeared to come from roughly 2% of our email accounts.

Importantly, at this point, we have no indication that the encryption on the passwords or the answers to security questions was broken. Likewise, there is no indication that this incident resulted in disclosure of users' financial information, including debit and credit cards, which is also fully encrypted.

Nevertheless, as a precautionary measure, we strongly encourage you to reset your password used for any AOL service and, when you do so, you should take the time to change your account security question and answer. You may reset your password and account security question at account.aol.com.

In addition, there are steps you can take to protect yourself from cyber risks. They include:
  • If you receive a suspicious email, do not respond or click on any links or attachments in the email.
  • When in doubt about the authenticity of an email you have received, contact the sender to confirm that he or she actually sent it.
  • Never provide personal or financial information in an email to someone you do not know. AOL will never ask you for your password or any other sensitive personal information over email.
  • If you believe you are a victim of spoofing, consider letting your friends know that your emails may have been spoofed and to avoid clicking the links in suspicious emails.
We place a premium on the security of our systems and our users' information. We are implementing additional measures to address this incident, and we are working with law enforcement to pursue the matter.

If you have any further questions, additional information and an extensive Q&A can be found at faq.aol.com. We apologize for any inconvenience, and we are addressing the situation as quickly and forcefully as we can.

Bud Rosenthal
Bud Rosenthal, AOL Membership Group CEO

Sender address rejected: not owned by user

I don't use MS Outlook at all.  I think that because it is Microsoft, it is extremely vulnerable to viruses, hackers, bots and spammers.  It is an easy gateway for malware and everything bad about the internet.  It hasn't even been configured on my machine.

However, I am writing a program for inviting people to our app, and I needed to get Outlook contacts to send them an email (that will be the subject of another blog post).  So I configured Outlook and the base email address was an AOL email address that I rarely use except for testing and for signing up for things where I don't want them to know my real identity (like the kajillions of white papers and secrets that one can get just for giving someone your email address -- a spam feedlot of sorts).

Well, it was supposed to be painless and take a few seconds.  I let the wizards set up Outlook for me and then of course, I had to test it.  I sent an email to my other email address.  Immediately it was rejected.  The error message was:

Your message did not reach some or all of the intended recipients.

      Subject: Test 
      Sent: 05/05/2014

The following recipient(s) cannot be reached:

      'test@test.com' on 05/05/2014 11:19 AM
             <test2@aol.com>: Sender address rejected: not owned by user test2

I thought -- WTF!!!  It had just used that identity to create an account for me using the account wizard.  It had just authenticated me to aol using that identity.  It was a total mystery.

I burned over an hour trying to de-bug this.  Here is the simple solution.  I went to Accounts on Outlook and clicked on the account to show the properties. The username was test2.  When I go into the web interface of AOL mail and sign in, I just put in test2 and the password.  Outlook knew that the domain was AOL.com because it had just automatically used those exact same credentials to create the account.  To make it work, I simply modified the username to include the domain -- ie. instead of test2, I put in test2@AOL.com and it worked.

This has done nothing to change my opinion of Microsoft products.  They are still a piece of crap.

Getting Google Contacts with JSP

I found this blog entry incredibly helpful in getting Google contacts using JSP.  It even sends emails through the Google SMTP.  It's a great resource:

http://javasantoshanand.blogspot.com/2013/06/how-to-get-gmail-contacts-using-jsp.html

I'd like to thank the author for putting it up.

The Myth of Apple and Great Design


Common wisdom says that Apple products are great designs.  Not only can that statement be construed as a myth, it could also be a lie.

Don't get me wrong -- Apple products have great aesthetics, but that isn't enough.  This was proven to me when my iPod Nano, 6th Generation failed.

Quite simply, the power button doesn't work.  What happened, is that the membrane switch didn't quite reach the aluminum switch, so there is a shim on the membrane switch, about the thickness of a piece of scotch tape.  The shim is the size of a pepper grain.  It is glued in place.  The glue fails, the shim falls off, and the on/off button doesn't work any longer.  Piece of Crap design for reliability.

But its not over yet.  To fix it, you get a heat gun, and you apply heat to the screen.  You then pry it off with a guitar pick.  Can you imagine -- the screen is only glued on.  It gets worse.  There is an aluminum shield underneath, and it is held on by screws.  The battery is also held in a piece of metal with screws.  The screws are different sizes.  When you finally get to the membrane switch mechanism, it is held in with tape.  Crap mechanical design.

Here's the worst part - Apple charges you $149 to fix this.  They go in, find the little black shim and glue it on again.

This design is the equivalent of wrapping feces in Christmas gift wrap.  It looks good, but once you open it, the design stinks to high heaven.