[Zope] [Security issue] SQL injection in DTML or in connection objects

2020-02-12 Thread Michael Howitz
On behalf of the Plone security team I am announcing this security issue in Zope also here: CVE Identifier: CVE-2020-7939 Type: SQL injection Severity: 4.9 – MEDIUM Affected Zope versions: * Zope 2 older than 2.13.30 (2.13.30 is not yet released) * Zope 4 older than 4.2 For details see

[Zope] Security vulnerabiity 20110928: Arbitrary Code Execution (pre-announcement)

2011-09-28 Thread Tres Seaver
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 The Zope security response team is pre-announcing a fix for a vulnerability in Zope 2.12.x and Zope 2.13.x that allows execution of arbitrary code by anonymous users. This is a severe vulnerability that allows an unauthenticated attacker to employ

Re: [Zope-dev] [Zope] Security announcement update

2011-06-28 Thread Martijn Pieters
On Tue, Jun 28, 2011 at 15:30, Sascha Welter zopel...@betabug.ch wrote: It says Zope 2.10 and 2.11 users who have not installed PloneHotfix20110720 are not affected - can I conclude from that, that Zope 2.9 would not be affected either? Indeed, Zope 2.9 is not affected, with or without the

Re: [Zope-dev] [Zope] Security announcement update

2011-06-28 Thread Martijn Pieters
On Tue, Jun 28, 2011 at 15:40, Norbert Marrale norbertmarr...@yahoo.com wrote: Why must PluggableAuthService (+ its dependencies) even be installed? It is a dependency of Plone itself. -- Martijn Pieters ___ Zope-Dev maillist - Zope-Dev@zope.org

Re: [Zope-dev] [Zope] Security announcement update

2011-06-28 Thread Laurence Rowe
On 28 June 2011 14:40, Norbert Marrale norbertmarr...@yahoo.com wrote: This should be clarified too: You should, however, make sure that you are running either Zope 2.10.13 or Zope 2.11.8  and PluggableAuthService 1.5.5, 1.6.5 or 1.7.5 Why must PluggableAuthService (+ its dependencies) even

[Zope] Security announcement update

2011-06-28 Thread Laurence Rowe
This is an update on today's security hotfix release. The fix will be released at 15:00 UTC today, Tuesday 28th June, 2011 (11:00am US EDT.) Updated versions of Zope 2 containing the security fix will be released at the same time. For details on which versions of Zope and Plone are affected,

[Zope] Security Hotfix 20110622 released

2011-06-28 Thread Laurence Rowe
Last week, the Zope and Plone security teams announced the discovery of a serious security issue affecting all recent versions of Zope and Plone, as well as the planned release of a Hotfix to address this issue to be made today, June 28th at 1500 UTC. The Plone and Zope security teams

[Zope] Security announcement

2011-06-22 Thread Laurence Rowe
On behalf of the Plone and Zope Security Teams I'd like to draw your attention to a security announcement that has just been published. This is a pre-announcement only, it does not contain any vulnerability details. Your sites are a safe today as they were yesterday. However, as the problem

Re: [Zope] Security for objects being called

2008-09-17 Thread Paul Winkler
On Tue, Sep 16, 2008 at 08:55:33AM -0400, Thibaud Morel l'Horset wrote: Thanks for the response Paul. I don't see a Proxy tab on Page Templates though, only DTML methods: do I need to install an additional product for that? or is it configured somewhere else for Templates? Oops, right you are.

Re: [Zope] Security for objects being called

2008-09-17 Thread Dieter Maurer
Thibaud Morel l'Horset wrote at 2008-9-15 19:44 -0400: I'm trying to figure out how to prevent certain zope objects from being called directly but allow them to be called from another object. Here is an example: You have a ZPT page, let's originally call it 'test' test calls a

Re: [Zope] Security for objects being called

2008-09-16 Thread Paul Winkler
permission only available for Authenticated users, and as anonymous I can neither hit 'test' nor 'script'. Based on my understanding of the Zope security framework I don't think this is possible... hopefully someone can tell me I'm wrong though and show me how to do it :) http://plope.com

[Zope-dev] Increasing the Zope Security [EMAIL PROTECTED]

2008-09-01 Thread Andreas Jung
Hi there, I just submitted a possible security related Zope issue on Launchpad and noticed that the bug has been assigned to the Zope Security Team which consists only of Jim. I suggest that a number of competent developers of the Zope 2 and Zope 3 world volunteer to join the team in order

Re: [Zope-dev] Increasing the Zope Security [EMAIL PROTECTED]

2008-09-01 Thread Sidnei da Silva
that the bug has been assigned to the Zope Security Team which consists only of Jim. I suggest that a number of competent developers of the Zope 2 and Zope 3 world volunteer to join the team in order to make sense to the Zope Security team. Andreas -- ZOPYX Ltd. Co. KG - Charlottenstr. 37/1 - 72070

Re: [Zope] security assertion needed for dictionary?

2007-06-18 Thread tomvon
I have the exact same problem and have been unable to find a solution anywhere. Were you ever able to resolve this? sfmcfar wrote: I apologize for cross-posting from the plone newsgroup. but after posting this I realized that this was more of a Zope issue than a Plone one. I wish I

RE: [Zope] security assertion needed for dictionary?

2007-06-18 Thread Doyon, Jean-Francois
) To see exactly what it is ... It might be an instance of some object that has a __str__ that makes it look like a dictionary? J.F. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of tomvon Sent: June 18, 2007 11:36 To: zope@zope.org Subject: Re: [Zope

Re: [Zope] transfer zope security-properties

2007-06-08 Thread Dieter Maurer
Einar Næss Jensen wrote at 2007-6-4 19:53 +0200: ... How can I copy the associated securityinformation about a zclass instance into my new diskbased instance? Roles and permissions. In a product, permissions are automatically created by using them (to protect a method). What roles do you have

[Zope] transfer zope security-properties

2007-06-04 Thread Einar Næss Jensen
I'm on the run for transfering my poorly designed zclasses into real diskbased ones. I've gotten pretty far in only a couple of weeks thanks to this mailinglist and the irc channel on freenet. Thanks everyone! Today I have this question: How can I copy the associated securityinformation about a

[Zope] Security class attribute

2006-01-26 Thread Peter Bengtsson
Now in Zope 2.9 I get these warnings:: 2006-01-26 14:31:45 WARNING Init Class Products.MyProduct.Homesite.FilesContainer has a security declaration for nonexistent method 'FileManagement' That's understandable because I've coded it like this:: class MyProduct(...):

RE: [Zope] Security class attribute

2006-01-26 Thread Brian Lloyd
, 2006 9:44 AM To: [Zope] Subject: [Zope] Security class attribute Now in Zope 2.9 I get these warnings:: 2006-01-26 14:31:45 WARNING Init Class Products.MyProduct.Homesite.FilesContainer has a security declaration for nonexistent method 'FileManagement' That's understandable because

Re: [Zope] Security class attribute

2006-01-26 Thread Peter Bengtsson
26, 2006 9:44 AM To: [Zope] Subject: [Zope] Security class attribute Now in Zope 2.9 I get these warnings:: 2006-01-26 14:31:45 WARNING Init Class Products.MyProduct.Homesite.FilesContainer has a security declaration for nonexistent method 'FileManagement' That's understandable

Re: [Zope] Security issue with manage_page_header

2006-01-24 Thread Martijn Pieters
On 1/24/06, [EMAIL PROTECTED] [EMAIL PROTECTED] wrote: My site, including the bug, is currently public and to be demoed in two days. Any assistance or guidance is greatly appreciated. Switch on VerboseSecurity in etc/zope.conf; this will give you much more info on what the security engine state

[Zope] Security issue with manage_page_header

2006-01-23 Thread Stacy . Ladnier
I have patched the Navigation and Management so the drop-down containing 'Set Preferences' and 'Logout' is displayed in the menu frame. The 'Set Preferences' displays a customized page to the user to set a unique set of options for my application. My product consists of several additional roles

[Zope] Zope Security

2006-01-12 Thread michael nt milne
HiJust a quick query about Zope security etc. I've got an installation on a Windows server using Apache, which also hosts internal email/data etc. This is behind a router/firewall. Just wondering if there are any Zope security issues that I should be aware of? How secure is Zope? ThanksMichaelPS

[Zope] Re: Zope Security

2006-01-12 Thread Tres Seaver
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 michael nt milne wrote: Hi Just a quick query about Zope security etc. I've got an installation on a Windows server using Apache, which also hosts internal email/data etc. This is behind a router/firewall. Just wondering if there are any Zope

[Zope] Re: Zope Security

2006-01-12 Thread Tres Seaver
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 I wrote: I would rate Zope overall as a reasonably secure platform. Because the builk of it, including all the socket handling code, is written in If you look at the list of security alerts (hotfixes, see you will note that the *vast*

Re: [Zope] Zope security and packing the database

2005-10-12 Thread Chris Withers
Cameron Beattie wrote: def main(): urllib._urlopener = MyUrlOpener() url = %s/Control_Panel/Database/manage_pack?days:float=%s % \ *sigh* url whacking, bleugh! If I use the backup user then urllib can't get the url due to no authentication so errors as follows: What roles do

Re: [Zope] Zope security and packing the database

2005-10-11 Thread Chris Withers
Cameron Beattie wrote: I have created a script based on zope_pack from the Zope book which allows a username and password to be specified when it is called. I wish to create a user specifically for this purpose that only has the ability to pack the ZODB. What permission is ZODB packing

Re: [Zope] Zope security and packing the database

2005-10-11 Thread Cameron Beattie
I have created a script based on zope_pack from the Zope book which allows a username and password to be specified when it is called. I wish to create a user specifically for this purpose that only has the ability to pack the ZODB. What permission is ZODB packing protected by? I don't know.

[Zope] Zope security and packing the database

2005-10-10 Thread Cameron Beattie
I have created a script based on zope_pack from the Zope book which allows a username and password to be specified when it is called. I wish to create a user specifically for this purpose that only has the ability to pack the ZODB. I've created a custom role and a user that has this role.

[Zope] security for ZPT-based Product

2005-07-11 Thread Milos Prudek
How can I manage permissions for imported ZPT files? Relevant lines from my Product: from AccessControl import ClassSecurityInfo class MyClass(): security=ClassSecurityInfo() comment_add_form=PageTemplateFile('zpt/comment_add_form',globals()) My goal is to limit access to

Re: [Zope] security for ZPT-based Product

2005-07-11 Thread Andreas Pakulat
On 11.Jul 2005 - 18:27:57, Milos Prudek wrote: How can I manage permissions for imported ZPT files? Relevant lines from my Product: from AccessControl import ClassSecurityInfo class MyClass(): security=ClassSecurityInfo()

Re: [Zope] security for ZPT-based Product

2005-07-11 Thread Jens Vagelpohl
On 11 Jul 2005, at 17:41, Andreas Pakulat wrote: add a security.declareProtected('comment_add_form', 'right that is granted to Authenticated users only') Where the second string would be one of the rights listed on the security tab with in the ZMI. If that right is granted to the authenticated

Re: [Zope] Security framework troubles

2005-05-07 Thread Dieter Maurer
Anders Bruun Olsen wrote at 2005-5-6 18:19 +0200: ... security = ClassSecurityInfo() security.setDefaultAccess(deny) security.declareProtected(View Bookbase, index_html) ... When the template tries to access container/title an access denied expection is raised. With VerboseSecurity I get

[Zope] Security framework troubles

2005-05-06 Thread Anders Bruun Olsen
Hi, I am attempting to make a zope product (a custom book-database for use by my employer) and of course want to secure it. I have added this code to my class: security = ClassSecurityInfo() security.setDefaultAccess(deny) security.declareProtected(View Bookbase, index_html)

Re: [Zope] Security framework troubles

2005-05-06 Thread Andreas Jung
--On Freitag, 6. Mai 2005 18:19 Uhr +0200 Anders Bruun Olsen [EMAIL PROTECTED] wrote: It works if I do setDefaultAccess(allow), but I don't want to allow access by default and then just deny for those I know I want to deny access to. I want it the other way around. Why don't you write an

[Zope] Security issues

2005-05-01 Thread cla
Hi! Im developing a portal using, zope and i had been some problems with the security of some template pages that I have created. Those pages are accesible just puting the correct path in the url, even if they are only for manager access. I have already try the security tabs that are associated

Re: [Zope] Security issues

2005-05-01 Thread Andreas Jung
--On Sonntag, 1. Mai 2005 13:02 Uhr +0100 cla [EMAIL PROTECTED] wrote: Hi! Im developing a portal using, zope and i had been some problems with the security of some template pages that I have created. Those pages are accesible just puting the correct path in the url, even if they are only for

Re: [Zope] Security issues

2005-05-01 Thread cla
thanks for your help! but is there any way to define this permission to the folder that contain the many pages templates that i want to restrict the use? afecting the parent(folder) we affect also the children(document) instead of defining for all template pages this rules. thanks a lot..

[Zope] Security on email.Message.Message

2005-04-12 Thread Tim Hicks
Hi, I'm trying to import and use the email.Message.Message class in a zope 'Script (Python)'. I have the following security assertions in my product code:: from AccessControl import allow_module, allow_class from AccessControl import ModuleSecurityInfo

Re: [Zope] Security on email.Message.Message

2005-04-12 Thread Andreas Jung
--On Dienstag, 12. April 2005 16:18 Uhr +0100 Tim Hicks [EMAIL PROTECTED] wrote: Hi, I'm trying to import and use the email.Message.Message class in a zope 'Script (Python)'. I have the following security assertions in my product code:: from AccessControl import allow_module, allow_class

Re: [Zope] Security on email.Message.Message

2005-04-12 Thread Tim Hicks
Andreas Jung said: Module RestrictedPython.Guards, line 96, in handler TypeError: object does not support item or slice assignment Does anyone have any idea what the problem is? Move your code into an external method which is less painful than dealing with module security issues. As

Re: [Zope] Security on email.Message.Message

2005-04-12 Thread Tim Hicks
Andreas Jung said: Module RestrictedPython.Guards, line 96, in handler TypeError: object does not support item or slice assignment Does anyone have any idea what the problem is? Digging further... I made the TypeError a little more revealing on line 96 of RestrictedPython/Guards.py so

Re: [Zope] Security on email.Message.Message

2005-04-12 Thread Tim Hicks
Tim Hicks said: Andreas Jung said: Module RestrictedPython.Guards, line 96, in handler TypeError: object does not support item or slice assignment Does anyone have any idea what the problem is? Digging further... I made the TypeError a little more revealing on line 96 of

[Zope] (Security) Hotfix_20050405 Released

2005-04-05 Thread Tres Seaver
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Overview Zope Corporation has released a Zope hotfix product addressing a potential vulnerability discovered during a recent security audit of Zope 2.7 and 2.8. Affected Versions The hotfix affects versions 2.7.5 and earlier of Zope on the

[Zope] (Security) Hotfix_20050405 Released (URL correction)

2005-04-05 Thread Tres Seaver
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Overview Zope Corporation has released a Zope hotfix product addressing a potential vulnerability discovered during a recent security audit of Zope 2.7 and 2.8. Affected Versions The hotfix affects versions 2.7.5 and earlier of Zope on the

Re: [Zope-dev] About Zope Security

2004-01-24 Thread Dario Lopez-Kästen
Casey Duncan wrote: They are fixed in the latest releases of Zope 2.6 and 2.7 ...snip good info... Download a new version of Zope and test it out with a copy of your application. Let us know if anything breaks. Thank you. Sincerely, /dario - off to test new zope-versions -- --

[Zope-dev] About Zope Security (was: Zope - SecurityFocus Newsletter #232)

2004-01-23 Thread Dario Lopez-Kästen
Chris Withers wrote: Hi, Can anyone shed light on all of these? I know about some of them, but this is quite a disturbingly long list... What is the current status of these issues? I am running a rather larges site with sensitive personal data. The decision to use Python/Zope instead of

[Zope-dev] [Zope] Security and external methods

2002-06-03 Thread Thierry Florac
Hi... I have a question with a security related problem. I've written a script to produce PDF output from any HTML output, as described in http://www.zope.org/Members/mjablonski/howtoPDF My problem is that with this simple script, I can get access to protected pages without giving any

[Zope-dev] Re: [Zope] Security Assertions

2002-01-17 Thread Godefroid Chapelle
At 18:43 16/01/2002, you wrote: Sorry about cross-posting but I think the following info is worth reading for both zope-users and developers. Note that up until Zope 2.5.0b4 there is a bug in the way module security assertions are handled that makes it impossible to declare more than one

Re: [Zope-dev] Re: [Zope] Security Assertions

2002-01-17 Thread Chris McDonough
to do with Zope security, but it is not a vulnerability. (That's why I didn't want to use the term hotfix) You can make a monkey patch by creating code modeled after ZC hotfixes that does some specific set of steps. In this case, you'd probably want to replace the ModuleSecurityInfo class

Re: [Zope-dev] Re: [Zope] Security Assertions

2002-01-17 Thread Adrian Hungate
. - Sun Tzu - Original Message - From: Chris McDonough [EMAIL PROTECTED] To: Godefroid Chapelle [EMAIL PROTECTED] Cc: [EMAIL PROTECTED]; [EMAIL PROTECTED] Sent: Thursday, January 17, 2002 1:50 PM Subject: Re: [Zope-dev] Re: [Zope] Security Assertions I do not know what you mean

Re: [Zope-dev] Re: [Zope] Security Assertions

2002-01-17 Thread Chris McDonough
Just a quick note on this point, there are two points during startup when a product can get control: 1) When the __init__.py is imported 2) When the initialize function within that __init__.py is called. I think Godefroid's case it would definitely want to be in __init__.py *outside* of the

[Zope-dev] python methods zope - security hole ?

2001-01-30 Thread Joseph Wayne Norton
Evan - I believe I have found a situation while using python methods that exposes a security hole. A user that can create python methods can grant the Manager role to himself by simply writing and then calling the manage_users method. This issue might also apply to other scenarios. I created

Re: [Zope] Q's about Zope security model tweaking

2001-01-25 Thread Chris Withers
J B Bell wrote: I want to do authentication for a whole subset of the site (indeed, its entire public face really), but don't want a huge userfolder build from NIS. nisUserFolder doesn't seem like the right solution since I only want to use nis if they don't auth in the customary fashion.

[Zope] Q's about Zope security model tweaking

2001-01-24 Thread J B Bell
I'd like to make a 'fallback' authorization scheme for Zope. That is: If user does not exist in usual UserFolder, then authenticate against custom module (NIS, in this case) and give them Anonymous privileges. I want to do authentication for a whole subset of the site (indeed, its entire

[Zope] Security error when inserting object from my own Python product in objectmanager

2001-01-18 Thread Max M
I have made a Python product and when I add it to a folder there is no problem, but when I try to add it to a zClass that subclasses a objectManager i get a security error. Is there anything special I need to do to add products to an objectManager ??? I get a password box, but if I just clicks

Re: [Zope-dev] [ZPatterns] DataSkin and Zope Security

2001-01-03 Thread Chris Withers
"Phillip J. Eby" wrote: DataSkins stored in Racks do not participate in the Zope ownership mechanism, nor the creation of the 'Owner' role. This is because they are not being stored via the normal ObjectManager protocols. Hurm... to what extent do they participate in Zope's Security

[Zope] Re: [Zope-Annce] ANNOUNCE: Zope security alert and hotfix release

2000-12-18 Thread Gregor Hoffleit
On Fri, Dec 15, 2000 at 02:02:08PM -0500, Brian Lloyd wrote: A security issue has recently come to our attention (thanks to Erik Enge for identifying this) that affects Zope versions up to and including Zope 2.2.4. ... The hotfix will work for all versions of Zope 2.2.0 and higher.

[Zope] Re: ANNOUNCE: Zope security alert and hotfix release

2000-12-18 Thread Brian Lloyd
The hotfix will work for all versions of Zope 2.2.0 and higher. A future version of Zope will contain the fix for this issue, and you will be able to uninstall the hot fix after upgrading. This seems to imply that 2.1.6 is vulnerable as well, but that this Hotfix won't work, and

[Zope] Re: ANNOUNCE: Zope security alert and hotfix release

2000-12-18 Thread Gregor Hoffleit
On Mon, Dec 18, 2000 at 10:30:56AM -0500, Brian Lloyd wrote: The hotfix will work for all versions of Zope 2.2.0 and higher. A future version of Zope will contain the fix for this issue, and you will be able to uninstall the hot fix after upgrading. This seems to imply that

[Zope] ANNOUNCE: Zope security alert and hotfix release

2000-12-18 Thread Brian Lloyd
Hi all - Tis the season for hot - fix - es, fa la la la la, waa waa waa waa... Peter Kelly has brought another potential security issue to our attention that is important enough to make a Hotfix available for those who allow untrusted users to edit DTML on their sites. The issue

Re: [Zope] SECURITY alert and hotfix release

2000-12-09 Thread Andrew Kuchling
On Fri, Dec 08, 2000 at 05:40:13PM -0500, Shane Hathaway wrote: AFAICT 2.1.6 is not vulnerable. Verifying this on our server, this turns out to be quite correct; Zope 2.1.6 does not demonstrate the problem repaired by the hotfix. --amk ___ Zope

[Zope] security - am I going crazy ?

2000-12-08 Thread Aleksander Salwa
Few days ago I found that on site that I'm currently working on, everybody can add DTMLMethods and Documents (and maybe do more, I haven't checked yet, but I think it's bad enough !) by simply entering URL http://www.mysite.com/manage_addDTMLMethod?id=q1title=qq1file=qqq1 After that Zope sends

Re: [Zope] security - am I going crazy ?

2000-12-08 Thread Shane Hathaway
Aleksander Salwa wrote: Few days ago I found that on site that I'm currently working on, everybody can add DTMLMethods and Documents (and maybe do more, I haven't checked yet, but I think it's bad enough !) by simply entering URL

[Zope] SECURITY alert and hotfix release

2000-12-08 Thread Brian Lloyd
Hi all, Aleksander Salwa has brought a security issue to our attention that affects all Zope versions up to and including Zope 2.2.4. We have released a Hotfix product to address the issue that can be downloaded from zope.org. (Thanks to Aleksander for finding this and to Shane

Re: [Zope] Security problem?

2000-12-07 Thread Chris Withers
Might be a security problem... Are you allowed to access that header from inside your index_html? cheers, Chris Andreas Jung wrote: Inside a product my index_html is set to "index_html=HTMLFile('index_html',globals())" The index_html.dtml calls dtml-var standard_html_header. This

Re: [Zope] security

2000-11-29 Thread seb bacon
* Dieter Maurer [EMAIL PROTECTED] [001128 00:12]: Bowyer, Alex writes: Can some one explain how the Define Permissions screen works. I really don't understand the concept behind it, what does it mean for a permission setting to own a permission? All I need to do is to make

Re: [Zope] security

2000-11-29 Thread Robin Becker
In article [EMAIL PROTECTED], seb bacon [EMAIL PROTECTED] writes * Dieter Maurer [EMAIL PROTECTED] [001128 00:12]: Bowyer, Alex writes: Can some one explain how the Define Permissions screen works. I really don't understand the concept behind it, what does it mean for a permission

Re: [Zope] security

2000-11-27 Thread Dieter Maurer
Bowyer, Alex writes: Can some one explain how the Define Permissions screen works. I really don't understand the concept behind it, what does it mean for a permission setting to own a permission? All I need to do is to make certain ZClass methods have a certain level of security and

[Zope] security

2000-11-26 Thread Bowyer, Alex
Can some one explain how the Define Permissions screen works. I really don't understand the concept behind it, what does it mean for a permission setting to own a permission? All I need to do is to make certain ZClass methods have a certain level of security and the other methods of the class

Re: [Zope] security problems .. should be fairly easy...

2000-11-21 Thread Dieter Maurer
Bowyer, Alex writes: I can't find any examples in any of the Zope documentation about how to manage permissions for class methods. Does anyone know where I could find such documentation or examples if there are any? Did you look at the upcoming Zope book? Dieter

[Zope] security problems .. should be fairly easy...

2000-11-20 Thread Bowyer, Alex
I know I am posting quite a lot of questions to the list lately, sorry about that, it's just that I can save myself hours of trial-and-error coding when I get quick answers from list, so I hope you don't mind. It seems to be the fastest way to learn. I have a news page ZClass and a news article

Re: [Zope] security problems

2000-11-17 Thread Aleksander Salwa
On Fri, 17 Nov 2000, Bowyer, Alex wrote: I have one method index_html which should be viewable by anonymous. All other methods should only be viewable when a username/password is entered for someone with the role I have called UAAdmin [...] I can only seem to get full access to all pages (if

[Zope] Security and Acquistition Problem

2000-11-09 Thread Charlie Wilkinson
Greetings, I had posted about this on Zope-dev because I'm running the CVS version, but no response there. Also more research has yielded more info. I first discovered this issue with LoginManager, but the same problem occurs with standard acl_users too. First, 'Figure 1:' / (Root Folder)

[Zope] Security and Acquisition

2000-11-09 Thread Charlie Wilkinson
Greetings, I know this a very busy list, but I'm hoping someone can take a moment to address this. I had posted about this on Zope-dev because I'm running the CVS version, but no response. Also more research has yielded more info. I first discovered this issue with LoginManager, but the same

Re: [Zope] Security and Acquistition Problem

2000-11-09 Thread Jeff Hoffman
On Thu, 9 Nov 2000, Charlie Wilkinson wrote: / (Root Folder) / acl_test (ACL Test Folder) acl_users (User Folder) index_html (Test Document) Now, referring to figure 1, changes to security settings for the acl_test folder are having no effect on access

Re: [Zope] Security and Acquisition

2000-11-09 Thread Morten W. Petersen
[Charlie Wilkinson] | Greetings, Hola! | Now, referring to figure 1 (above :-), changes to security settings | for the acl_test folder are having no effect on access to index_html. | Only when I change the security settings on index_html itself, can I | control access to it. Can it have

[Zope] security dilemma?

2000-11-09 Thread Zhen Zhou
please bear with my ignorance, because this is the first couple of day I ever try Zope. It is super cool, but I should say that the documentation is far from satisfaction. Here is my problem: The only API I can find to alter the properties of some object is "manage_changeProperties". However, in

Re: [Zope] Security and Acquisition

2000-11-09 Thread Charlie Wilkinson
[Charlie Wilkinson] | Greetings, Hola! | Now, referring to figure 1 (above :-), changes to security settings | for the acl_test folder are having no effect on access to index_html. | Only when I change the security settings on index_html itself, can I | control access to it. Can

Re: [Zope] security dilemma?

2000-11-09 Thread Jason C. Leach
hi, do you have these two: http://www.zope.org/Members/michel/ZB/ http://zdp.zope.org/projects/zqr j. .. . Jason C. Leach ... University College of the Cariboo. .. ___ Zope maillist - [EMAIL PROTECTED]

Re: [Zope] security quickie

2000-10-16 Thread Manuel Amador (Rudd-O)
cument or method, i should be able to acquire anything specified into it, from its parent hierarchy. Please help or tip. Thanks =) Seb Bacon wrote: Does Zope security provide a way of restricting what objects are listed to an authenticated user inside the Zope 'manage' interface? I'm getting my head all t

[Zope] Non-existing Zope-Security!!!

2000-10-13 Thread Stephan Goeldi
OK let me state that I don't think so (subject line). I had to choose this subject, because it seems to me, that nobody was interested in my previous attempts to get information about my problem. So here is my newbie (?) question again: I have the folders: /www/folder1 /www/folder2 Apache

Re: [Zope] Non-existing Zope-Security!!!

2000-10-13 Thread Tim Cook
Stephan Goeldi wrote: OK let me state that I don't think so (subject line). I had to choose this subject, because it seems to me, that nobody was interested in my previous attempts to get information about my problem. So here is my newbie (?) question again: I have the folders:

Re: [Zope] Non-existing Zope-Security!!!

2000-10-13 Thread Joachim Werner
r's "Access contents information" rights for Anonymous and the sub-tree managers. I think Zope security is really a bit weak here because the standard settings are NOT blocking "Access contents information" and blocking it makes programming a bit harder ... BUT: You CAN configu

Re: [Zope] Non-existing Zope-Security!!!

2000-10-13 Thread knight
Also, consider adding an accessrule. This won't stop them from using __no_before_traverse__ or _SUPPRESS_ACCESSRULE but it will make it 'appear' there is nothing more than the current level. knight [EMAIL PROTECTED] On Fri, 13 Oct 2000, Tim Cook wrote: Stephan Goeldi wrote: OK let me

[Zope] security quickie

2000-10-09 Thread Seb Bacon
Does Zope security provide a way of restricting what objects are listed to an authenticated user inside the Zope 'manage' interface? I'm getting my head all twisted up over this security / proxy roles /local roles lark. Thanks, seb ___ Zope maillist

Re: [Zope] Import Zope Security

2000-09-11 Thread Chris Withers
Martijn Pieters wrote: No it isn't. Web access to class instances is handled by permissions. Unpickling will cause class instantiation in the python process, where you have no control over what get's created. Surely you could pipe this process through the Zope security process? You can

[Zope-dev] RFC: Zope Security for Developers

2000-09-08 Thread Brian Lloyd
Hi all - There was quite a bit of discussion on the "security assertion spelling proposal" on dev.zope.org recently - it has since turned into an active project and I have a draft of the first deliverable (user documentation) ready for review and comment:

[Zope] Security Problems upgrading to Zope 2.2.0

2000-08-21 Thread Stefan Bambach
Hello zope-users, I upgraded my Zope application from version 2.1.3 to 2.2.0 . Now I have problems with the new security system. e.g. 'test.py' in Extensions directory: class test: def __init__(self): pass def sayhello(self): return "hello" def initialize(self): return test()

Re: [Zope] Security Problems upgrading to Zope 2.2.0

2000-08-21 Thread Aleksander Salwa
On Mon, 21 Aug 2000, Stefan Bambach wrote: class test: def __init__(self): pass def sayhello(self): return "hello" def initialize(self): return test() What's wrong with this code ? Try to add this attribute to your class 'test':

[Zope-dev] Re: Zope security alert and hotfix product...

2000-08-14 Thread Brian Lloyd
The issue involves the fact that the getRoles method of user objects contained in the default UserFolder implementation returns a mutable Python type. Because the mutable object is still associated with the persistent User object, users with the ability to edit DTML could

Re: [Zope-dev] Re: Zope security alert and hotfix product...

2000-08-14 Thread Andrew Wilcox
Now - should methods of mutable types be off-limits in the future? [...] I don't think it would be acceptable for 'append' to be off-limits in this case, so the alternative is that the security machinery would somehow have to be able to distinguish mutables created by the user from those

[Zope] SECURITY: Zope security alert and hotfix product...

2000-08-10 Thread Brian Lloyd
Hi all - We have recently become aware of an important security issue that affects all released Zope versions prior to 2.2.1 beta 1. The issue involves the fact that the getRoles method of user objects contained in the default UserFolder implementation returns a mutable Python

[Zope] security settings go blank on change!

2000-08-09 Thread Paul Abrams
Yikes! Every time I try to change my security settings all of the checkboxes become unset when I save the form! 1. Open up any "Security" tab 2. Change a checkbox 3. Save the form 4. Click 'Ok' 5. ALL of the checkboxes are empty! Has anbody else seen this problem? I have a workaround, but I'd

Re: [Zope] security settings go blank on change!

2000-08-09 Thread Martijn Pieters
On Wed, Aug 09, 2000 at 10:08:20AM -0700, Paul Abrams wrote: Yikes! Every time I try to change my security settings all of the checkboxes become unset when I save the form! 1. Open up any "Security" tab 2. Change a checkbox 3. Save the form 4. Click 'Ok' 5. ALL of the checkboxes are

[Zope] Security Problem

2000-08-03 Thread Sven Hohage
Hi, I've got two questions. 1.Is Zope 2.2.0 masking the length of the passwords? 2. the more important- I'm using a method to change properties by form. The user i.e. Tim has the role manager in the highest user_folder and acquisition is kept but Zope tells me that the user is not authorized.

[Zope] Security (proxy role??)

2000-08-03 Thread Sven Hohage
Hi, I've got two questions. 1.Is Zope 2.2.0 masking the length of the passwords? 2. the more important- I'm using a method to change properties by form. The user i.e. Tim has the role manager in the highest user_folder and acquisition is kept but Zope tells me that the user is not authorized.

[Zope] security model

2000-07-28 Thread Olivier Tanguy
authentification request bug and fail when running an sql method through an external method (python 1.5.42+) in a dtml-tree tag zope(2.2dev) asks me to login again, what i do without success. Indeed, all separate components work fine. Any idea ? Thanks

[Zope] Security problem i 2.2 final - Bug?

2000-07-19 Thread Peter Arvidsson
I have a very anoying problem... I have created a news-product and have several news-objects. Now I want to change the properties of a news-object. This is my code for that: dtml-with "newsEntries" dtml-call "_[objId].propertysheets[1].manage_editProperties(

Re: [Zope] Security problem i 2.2 final - Bug?

2000-07-19 Thread Pierre Rougier
Hi :) I may say something idiot, but... Did u try to change the proxy roles of the method which call the fonction manage_editProperties? (in case of: to do it, edit your method and choose proxy at the top of the window), u can edit the role of your method. Piotr. Peter Arvidsson wrote: I

  1   2   >