Re: [Zope] security - am I going crazy ?

2000-12-08 Thread Aleksander Salwa
On Fri, 8 Dec 2000, Shane Hathaway wrote: > You're right. It's because of a "legacy" issue. Here's a quick patch > that plugs the hole: > [...] > > This is not perfect, however. I'm working on a better solution. Thanks a lot ! It works for me. [EMAIL PROTECTED] /--

Re: [Zope] security - am I going crazy ?

2000-12-08 Thread Shane Hathaway
Aleksander Salwa wrote: > Few days ago I found that on site that I'm currently working on, > everybody can add DTMLMethods and Documents (and maybe do more, I haven't > checked yet, but I think it's bad enough !) by simply entering URL > http://www.mysite.com/manage_addDTMLMethod?id=q1&title=qq1&f

[Zope] security - am I going crazy ?

2000-12-08 Thread Aleksander Salwa
Few days ago I found that on site that I'm currently working on, everybody can add DTMLMethods and Documents (and maybe do more, I haven't checked yet, but I think it's bad enough !) by simply entering URL http://www.mysite.com/manage_addDTMLMethod?id=q1&title=qq1&file=qqq1 After that Zope sends