[Zope-dev] Re: CoreSessionTracking proposal

2000-10-04 Thread gotcha
--- In [EMAIL PROTECTED], "Chris McDonough" [EMAIL PROTECTED] wrote: Without a client-checking scheme (such as encoding the IP address in the token), a token theft attack is very easy. As voiced by others in the thread, client-checking is not reliable, should not be a default, and maybe

[Zope-dev] Re: CoreSessionTracking proposal

2000-10-02 Thread gotcha
--- In [EMAIL PROTECTED], Chris McDonough [EMAIL PROTECTED] wrote: I suppose I could implement something like this (encode the IP address into the token) and provide a knob to turn it on and off on the id manager. I'm not going to do this for the first iteration, I need to get it working

[Zope] Pluggable brains

2000-09-14 Thread gotcha
Is there a place where pluggable brains mechanism is described ? I am beginning a Zope site project. With the few I have read about pluggable brains, I feel that more info could help me in deciding which part of data has to stay in ZODB and which should go inside RDBM. Thanks. Godefroid

[Zope] ZDOM and Zope release version number

2000-09-13 Thread gotcha
Hi all, two questions : I have read the ZDOM documentation on Zope.org but it is unclear if it is already implemented or if it is still a project. I could not use it on my Free Zope account by NIP. So I was wondering if NIP was running a previous release which does not support ZDOM. Then

[Zope] Re: list of users tied to database

2000-09-13 Thread gotcha
Quoting : on 13/9/00 2:47 pm, [EMAIL PROTECTED] at [EMAIL PROTECTED] wrote: I am still a newbie, but I wonder if you can use the sequence-item of a enclosing dtml-in inside the definition of a nested dtml-in yeah, I think I"ve done this before by using a dtml-let to set a