Re: [Zope-dev] Methods with no __roles__ defined no always protected?

2000-08-21 Thread Chris Withers
Toby Dickenson wrote: > Firstly, I assume your management page is a dtml file on disk, not a > dtml object stored in the ZODB. dtml files bypass *all* security > checks. That's nice :( > Secondly, all objects that inherit from OFS.Item.SimpleItem (that is, > almost all high level objects) have t

Re: [Zope-dev] Methods with no __roles__ defined no always protected?

2000-08-21 Thread Toby Dickenson
On Mon, 21 Aug 2000 12:15:24 +0100, Chris Withers <[EMAIL PROTECTED]> wrote: >The SquishSite class has a method called item_count() which is used on >one of the management pages. It currently isn't protected by any >permissions or __roles__ and yet it still works fine on the management >screen con

[Zope-dev] Methods with no __roles__ defined no always protected?

2000-08-21 Thread Chris Withers
Hi, Just doing Squishdot for 2.2 when I noticed the following: The SquishSite class has a method called item_count() which is used on one of the management pages. It currently isn't protected by any permissions or __roles__ and yet it still works fine on the management screen concerned. I thoug