Re: [Zope] Nasty subtle security bug - Me Too

2000-09-26 Thread Shane Hathaway
On Tue, 26 Sep 2000, Martijn Faassen wrote: > Shane Hathaway wrote: > > Martijn Faassen wrote: > > > General problem description: > > > > > > For a ZClass instance/external methods that is only viewable by > > > users with a particular role, the view operation fails if that role > > > is o

Re: [Zope] Nasty subtle security bug - Me Too

2000-09-26 Thread Martijn Faassen
Shane Hathaway wrote: > Martijn Faassen wrote: > > General problem description: > > > > For a ZClass instance/external methods that is only viewable by > > users with a particular role, the view operation fails if that role > > is only added to a user in a place deeper in the folder tree th

Re: [Zope] Nasty subtle security bug - Me Too

2000-09-25 Thread Shane Hathaway
Martijn Faassen wrote: > General problem description: > > For a ZClass instance/external methods that is only viewable by > users with a particular role, the view operation fails if that role > is only added to a user in a place deeper in the folder tree than the > folder where the Extern

Re: [Zope] Nasty subtle security bug - Me Too

2000-09-25 Thread Martijn Faassen
Martijn Faassen wrote: [snip] > In fact I misreported that moving the external method to a subfolder > solved all problems -- it still fails (at least in 2.2.2, perhaps it worked > in 2.1.6), as long as the local role needed to execute it is added to the > user in a subfolder below it). If the ro

Re: [Zope] Nasty subtle security bug - Me Too

2000-09-25 Thread Martijn Faassen
Brad Clements wrote: > On 25 Sep 2000, at 21:01, Martijn Faassen wrote: > > > In Zope 2.2.2, the user cannot execute the external method E either. > > Instead, the calling DTML code raises a NameError, basically saying our > > external method does not exist. > > > I'll also dump this description

Re: [Zope] Nasty subtle security bug - Me Too

2000-09-25 Thread Brad Clements
On 25 Sep 2000, at 21:01, Martijn Faassen wrote: > In Zope 2.2.2, the user cannot execute the external method E either. > Instead, the calling DTML code raises a NameError, basically saying our > external method does not exist. > I'll also dump this description into the collector, but posted to