RE: [Zope] Folder and SQL security

2000-09-05 Thread Chris McDonough
way how to make sure that no one > unauthorised > gets to see any of the contents of 'wholesale' folder??? > > Regards, > > George > > > > -Original Message- > > From: Chris McDonough [mailto:[EMAIL PROTECTED]] > > Sent: Tuesday, 5 Sept

Re: [Zope] Folder and SQL security

2000-09-04 Thread R. David Murray
On Mon, 4 Sep 2000, George wrote: > asks for the password even for the viewing. Then I enable 'access the > content' and the site works as long as I do not try to use sql. When I > how ever enable 'use sql methods' permission they can access my > database, delete and add entries to it. What do I h

RE: [Zope] Folder and SQL security

2000-09-04 Thread Chris McDonough
On Tue, 5 Sep 2000, George Osvald wrote: > My sql works now and security is satisfactory so thank you. The only thing > that remains in question is that one subfolder. I created a user folder > inside, set all the security and it does not do what I want. I want to > restrict any access including

Re: [Zope] Folder and SQL security

2000-09-03 Thread Dimitris Andrakakis
Hi George ! Please check what Chris wrote too but I can answer this: > Security in ZOPE is very puzzling. If I have certain rules set for the > root folder, can I set something different for the sub folders? It's as simple as having a separate Acl_users in those folders that you need to have d

Re: [Zope] Folder and SQL security

2000-09-03 Thread Chris McDonough
George wrote: > > Security in ZOPE is very puzzling. If I have certain rules set for the > root folder, can I set something different for the sub folders? Sure... for general security information see both http://www.zope.org/Members/michel/ZB (the Zope book security chapter, mostly finished) and

[Zope] Folder and SQL security

2000-09-03 Thread George
Security in ZOPE is very puzzling. If I have certain rules set for the root folder, can I set something different for the sub folders? Any changes seem to have no effect at all. I am especially wandering about setting for anonymous user. I'd like to give them only 'viewing' privilege but that does