Re: [Zope] Nasty subtle security bug - Me Too

2000-09-26 Thread Martijn Faassen
Shane Hathaway wrote: Martijn Faassen wrote: General problem description: For a ZClass instance/external methods that is only viewable by users with a particular role, the view operation fails if that role is only added to a user in a place deeper in the folder tree than the

Re: [Zope] Nasty subtle security bug - Me Too

2000-09-25 Thread Brad Clements
On 25 Sep 2000, at 21:01, Martijn Faassen wrote: In Zope 2.2.2, the user cannot execute the external method E either. Instead, the calling DTML code raises a NameError, basically saying our external method does not exist. I'll also dump this description into the collector, but posted to the

[Zope] Nasty subtle security bug

2000-09-25 Thread Martijn Faassen
Hi there, I'm about to describe a very nasty bug that appears to exist in different guises in at least Zope 2.1.6 and Zope 2.2.2. The bug is nasty because it occurs under rather restricted circumstances, so nobody else noticed it yet, but it keeps biting _me_. The circumstances: * we have

Re: [Zope] Nasty subtle security bug - Me Too

2000-09-25 Thread Martijn Faassen
Brad Clements wrote: On 25 Sep 2000, at 21:01, Martijn Faassen wrote: In Zope 2.2.2, the user cannot execute the external method E either. Instead, the calling DTML code raises a NameError, basically saying our external method does not exist. I'll also dump this description into the