for completeness sake.
You can always fall back to functools.cmp_to_key() to use cmp-based sorting
in python 3:
http://docs.python.org/3/library/functools.html#functools.cmp_to_key
--
Martijn Pieters
--
Martijn Pieters
___
Zope-Dev maillist - Zope-Dev
act as a BlobStorage, NEO can not.
Anything else different? Did you make any performance comparisons
between RelStorage and NEO?
--
Martijn Pieters
___
Zope-Dev maillist - Zope-Dev@zope.org
https://mail.zope.org/mailman/listinfo/zope-dev
** No cross
with them before I
got to them. Mea Culpa!
--
Martijn Pieters
___
Zope-Dev maillist - Zope-Dev@zope.org
https://mail.zope.org/mailman/listinfo/zope-dev
** No cross posts or HTML encoding! **
(Related lists -
https://mail.zope.org/mailman/listinfo
On Tue, Jul 5, 2011 at 14:41, Hanno Schlichting ha...@hannosch.eu wrote:
Ok, seems 4.0 is the more popular choice.
I don't agree. Let's go with Fibonacci and call the next release Zope
8, as the logical extension of the series 1, 2, 3, and 5!
:-P
--
Martijn Pieters
the previous hotfix.
--
Martijn Pieters
___
Zope-Dev maillist - Zope-Dev@zope.org
https://mail.zope.org/mailman/listinfo/zope-dev
** No cross posts or HTML encoding! **
(Related lists -
https://mail.zope.org/mailman/listinfo/zope-announce
https
On Tue, Jun 28, 2011 at 15:40, Norbert Marrale norbertmarr...@yahoo.com wrote:
Why must PluggableAuthService (+ its dependencies) even be installed?
It is a dependency of Plone itself.
--
Martijn Pieters
___
Zope-Dev maillist - Zope-Dev@zope.org
On Wed, Jun 22, 2011 at 10:01, Lennart Regebro rege...@gmail.com wrote:
Whohoo! Amesome work all bugfixers!
Wohoo disabling the windows bots!
--
Martijn Pieters
___
Zope-Dev maillist - Zope-Dev@zope.org
https://mail.zope.org/mailman/listinfo/zope
of non-ASCII data. Also, it'd be almost impossible to
auto-detect when binary data will be handled by the form, unless you
start introspecting widget output, so the default looks entirely sane
to me.
--
Martijn Pieters
___
Zope-Dev maillist - Zope-Dev
SSH would make the sftp route the logical choice.
--
Martijn Pieters
___
Zope-Dev maillist - Zope-Dev@zope.org
https://mail.zope.org/mailman/listinfo/zope-dev
** No cross posts or HTML encoding! **
(Related lists -
https://mail.zope.org/mailman
options. I use jarn.mkrelease to make releases to private,
password protected folders on our dist.jarn.com 'egg server' (apache
directory indexes).
--
Martijn Pieters
___
Zope-Dev maillist - Zope-Dev@zope.org
https://mail.zope.org/mailman/listinfo/zope-dev
On Fri, Feb 18, 2011 at 22:19, Martijn Pieters m...@zopatista.com wrote:
We should at the very least convert PAS to use zope.password instead
of AccessControl.AuthEncoding.
There is a snag. The zope.password API doesn't provide any way to
detect what scheme was used for a given hash.
Say you
managers as well.
The only thing that could perhaps be removed are the SSHADigestScheme
and SHADigestSCheme classes, as these will be completely redundant
with zope.password support.
--
Martijn Pieters
___
Zope-Dev maillist - Zope-Dev@zope.org
https
On Sun, Feb 20, 2011 at 12:39, Martijn Pieters m...@zopatista.com wrote:
Yes, changing the existing interface would require a 4.0. If you'd add
a new interface extending the IPasswordManager one, we could do it in
a 3.x release.
A new zope.password 3.x release could go into both ZTK 1.1
is truly random! :-)
--
Martijn Pieters
___
Zope-Dev maillist - Zope-Dev@zope.org
https://mail.zope.org/mailman/listinfo/zope-dev
** No cross posts or HTML encoding! **
(Related lists -
https://mail.zope.org/mailman/listinfo/zope-announce
https
components.
Any objections to reworking both AuthEncoding and PAS?
--
Martijn Pieters
[1] see http://codahale.com/how-to-safely-store-a-password/ and
http://stackoverflow.com/questions/1561174/sha512-vs-blowfish-and-bcrypt
___
Zope-Dev maillist - Zope
On Thu, Jul 1, 2010 at 3:10 PM, Godefroid Chapelle got...@bubblenet.be wrote:
http://packages.python.org/z3c.form
The index is empty and module index appears to be missing altogether:
http://packages.python.org/z3c.form/index.html#indices-and-tables
--
Martijn Pieters
2010/2/26 Tres Seaver tsea...@palladion.com:
Kettle to pot: Did you add a test?
I ran out of time; the current tests weren't easily molded to add a
case for this. I felt that at least the simple 'return' statement fix
should go in. I'll get the test case in this weekend, hopefully.
--
Martijn
suspect that
all open-ended slicing ops in Python C extensions are borken in python
2.4, because it doesn't have Py_ssize_t.
--
Martijn Pieters
___
Zope-Dev maillist - Zope-Dev@zope.org
https://mail.zope.org/mailman/listinfo/zope-dev
** No cross posts
these two back to 'i'
and int.
--
Martijn Pieters
___
Zope-Dev maillist - Zope-Dev@zope.org
http://mail.zope.org/mailman/listinfo/zope-dev
** No cross posts or HTML encoding! **
(Related lists -
http://mail.zope.org/mailman/listinfo/zope-announce
On Mon, Aug 3, 2009 at 08:04, Martijn Pieters m...@zopatista.com wrote:
AssertionError: Incorrect Content-Length is set! Expected 20425,
got 20426.
I don't grok the range support code at all: probably Martijn Pieters is
the only person in the world who does. The tests are quite
On Fri, Aug 7, 2009 at 14:55, Martijn Pieters m...@zopatista.com wrote:
Here is the simple test case:
from Acquisition import Implicit
class Root(Implicit):
pass
class Slicer(Implicit):
def __getslice__(self, start, end):
return [start, end]
root = Root()
slicer = Slicer
On Fri, Aug 7, 2009 at 14:55, Martijn Pieters m...@zopatista.com wrote:
The problem is caused by an acquisition wrapped object with a
__getslice__ method get the wrong indices passed in when the end
parameter is ommitted:
data[start:]
Image.Pdata classes have a __getslice__ method
don't grok the range support code at all: probably Martijn Pieters is
the only person in the world who does. The tests are quite obscure to
me, so I can't diagnose even whether the failure is a testing artifact
or a real bug.
Here's my response to Tres; for some reason my mail reader didn't
another 3k inactive).
--
Martijn Pieters
___
Zope-Dev maillist - Zope-Dev@zope.org
http://mail.zope.org/mailman/listinfo/zope-dev
** No cross posts or HTML encoding! **
(Related lists -
http://mail.zope.org/mailman/listinfo/zope-announce
http
is a dotted name and the Zope 2
permission name isn't, I think it's extremely unlikely that this would
actually happen in practice.
I'm sure we can do some performance comparisons on this one. I'd say
it's worth the cost, but hard numbers would help.
--
Martijn Pieters
-control.subversion.user/87346/focus=87525
It sucks for very specific cases, namely tight access control on
sub-paths. I don't see such cases, and I see speed improvements
instead.
Note that we are now up to svn 1.6.
--
Martijn Pieters
___
Zope-Dev maillist
errors' are not random but due to svn info being out-of-date after a
commit. svn up has always solved that for me. Yes, the latter is a
bug, but I suspect it is already solved in 1.6 (didn't test that yet
though).
--
Martijn Pieters
___
Zope-Dev maillist
not have any problems (and a
workaround for svn bug 3119) but that doesn't mean we can ask other
people that need access to more tightly ACL-ed repositories to put up
with subversion 1.5 and 1.6.
--
Martijn Pieters
___
Zope-Dev maillist - Zope-Dev@zope.org
plugin, which includes a
link to the http:// or svn+ssh:// url for the currently viewed
location, for easy checking out.
--
Martijn Pieters
___
Zope-Dev maillist - Zope-Dev@zope.org
http://mail.zope.org/mailman/listinfo/zope-dev
** No cross posts or HTML
with any/all of the above.
My offer to set up Trac as a buildout still stands too.
Jens, have your concerns about dependencies been answered?
--
Martijn Pieters
___
Zope-Dev maillist - Zope-Dev@zope.org
http://mail.zope.org/mailman/listinfo/zope-dev
is
now stored encrypted, and subversion now supports KWallet, GNOME
Keyring, Mac OS Keychain, and Windows CryptoAPI for storage.
See:
http://subversion.tigris.org/svn_1.6_releasenotes.html#auth-related-improvements
--
Martijn Pieters
___
Zope-Dev maillist
. This means we'll have to fix
__parent__ and __name__ usage as well. This will be painful, me
thinks..
--
Martijn Pieters
___
Zope-Dev maillist - Zope-Dev@zope.org
http://mail.zope.org/mailman/listinfo/zope-dev
** No cross posts or HTML encoding
attribute of the function.
Note that even if the name *where* the same, attribute annotations
only work on classes and instances, while function annotations only
apply to functions, not?
--
Martijn Pieters
___
Zope-Dev maillist - Zope-Dev@zope.org
http
counter proposals if you have to, discuss things on their
merits, but if you cannot add more than a vague +1 and -1, please
refrain.
--
Martijn Pieters
___
Zope-Dev maillist - Zope-Dev@zope.org
http://mail.zope.org/mailman/listinfo/zope-dev
** No cross
. This is not about enforcing philosophical
choices, this is about being pragmatic. If the feature was truely
useful, more developers would be maintaining and fixing it. Obviously
the complexity of keeping it working is outweighing it's usefulness.
--
Martijn Pieters
the security implications of
undoing this work.
--
Martijn Pieters
___
Zope-Dev maillist - Zope-Dev@zope.org
http://mail.zope.org/mailman/listinfo/zope-dev
** No cross posts or HTML encoding! **
(Related lists -
http://mail.zope.org/mailman/listinfo/zope
am sceptical he'll be able to, and am not convinced
it'll be worth introducing risks.
--
Martijn Pieters
___
Zope-Dev maillist - Zope-Dev@zope.org
http://mail.zope.org/mailman/listinfo/zope-dev
** No cross posts or HTML encoding! **
(Related lists
be interesting to everybody, I think.
There is one already. However, it isn't immutable and thus a security risk.
--
Martijn Pieters
___
Zope-Dev maillist - Zope-Dev@zope.org
http://mail.zope.org/mailman/listinfo/zope-dev
** No cross posts or HTML
or something? Then everyone can make
their own choices instead of having them made for them.
--
Martijn Pieters
___
Zope-Dev maillist - Zope-Dev@zope.org
http://mail.zope.org/mailman/listinfo/zope-dev
** No cross posts or HTML encoding! **
(Related lists
._aliases = encoding.aliases.aliases
which does therefore not work in 2.3. So, now I am curious how your
Python 2.3 differs, and why you don't see the error locally :-)
The 1.1 version of the hotfix corrected this.
--
Martijn Pieters
___
Zope-Dev
not is defined by the schema of the
configuration which can be extended by any package. So adding this
information to the extractor would duplicate it. Not good.
But extracting that information may be prohibitively difficult and
expensive to do.
--
Martijn Pieters
be translatable.
Also, these days it is possible to register content views (such as the
default view for a folder) through ZCML, using a menu directive for
the title. Again these titles should be translatable.
--
Martijn Pieters
___
Zope-Dev maillist
trivial to extract that data without having to pull all of zope
in.
If you determine beforehand which strings are translatable (end up as
msgid objects) it should be trivial to extract these. You will have to
update i18ndude to add new zcml tags though.
--
Martijn Pieters
is
at this point not scheduled yet, but is unlikely to get a release before
early 2009. This should give us plenty of time to test.
Opinions, votes?
+sys.maxint!
Thanks, Hanno, for carrying this to it's completion!
--
Martijn Pieters
___
Zope-Dev
a good idea.
--
Martijn Pieters
___
Zope-Dev maillist - Zope-Dev@zope.org
http://mail.zope.org/mailman/listinfo/zope-dev
** No cross posts or HTML encoding! **
(Related lists -
http://mail.zope.org/mailman/listinfo/zope-announce
http
hexadecimal represent
control characters; these must be encoded.
Now, Zope could well support UTF-8 ids, and translate URLs
appropriately, but in the meantime you could use the same scheme?
--
Martijn Pieters
___
Zope-Dev maillist - Zope-Dev@zope.org
http
-embedded-in-text-with-prefixes, as well.
--
Martijn Pieters
___
Zope-Dev maillist - Zope-Dev@zope.org
http://mail.zope.org/mailman/listinfo/zope-dev
** No cross posts or HTML encoding! **
(Related lists -
http://mail.zope.org/mailman/listinfo/zope
work to fix up the
loader; I'll probably create a branch to work on this some...
Has anyone looked at Babel (http://babel.edgewall.org/)? It includes a
python interface to CLDR, which if usable would let us off the hook of
maintaining such an interface ourselves.
--
Martijn Pieters
/112109
--
Martijn Pieters
___
Zope-Dev maillist - Zope-Dev@zope.org
http://mail.zope.org/mailman/listinfo/zope-dev
** No cross posts or HTML encoding! **
(Related lists -
http://mail.zope.org/mailman/listinfo/zope-announce
http://mail.zope.org/mailman
declaration. Should it be added there to lift this
attribute above implementation detail status?
It can then also be used in zope.component.interface where it could
replace the various usages of __module__ + '.' + __name__.
--
Martijn Pieters
___
Zope-Dev
in their emails though; today
Christian Thuene cleaned up the Z3 bugtracker and I couldn't tell from
any of the many bug emails if any related to bugs I cared about. I'll
have to file a LP feature-request, I guess.
--
Martijn Pieters
___
Zope-Dev maillist - Zope
On 3/12/07, Martijn Pieters [EMAIL PROTECTED] wrote:
- Create an ICatalogResult interface and use a five:implements
directive to configure ZCatalog.CatalogBrains.AbstractCatalogBrain as
implementing it.
[...]
I'd like to add this to Zope trunk, with Traversable a base class
with zopectl start.
--
Martijn Pieters
___
Zope-Dev maillist - Zope-Dev@zope.org
http://mail.zope.org/mailman/listinfo/zope-dev
** No cross posts or HTML encoding! **
(Related lists -
http://mail.zope.org/mailman/listinfo/zope-announce
http
On 3/26/07, Martijn Pieters [EMAIL PROTECTED] wrote:
Tres Seaver added the decorators to the Control_Panel and must've
missed the REQUEST parameter on manage_restart, which only comes into
effect when running the zope process with zopectl start.
Fixed on the trunk, and the 2.8, 2.9 and 2.10
On 3/26/07, Andreas Jung [EMAIL PROTECTED] wrote:
The penalty for this bug: two bottles of wine.
You know where to send the bill. ;)
The workaround is to add REQUEST as optional parameter to manage_restart()?
No, it's 'svn up' now, as I fixed it already. :)
--
Martijn Pieters
On 3/21/07, Stefan H. Holek [EMAIL PROTECTED] wrote:
Python 2.3 does not support the @decorator syntax.
My bad, I'll fix.
--
Martijn Pieters
___
Zope-Dev maillist - Zope-Dev@zope.org
http://mail.zope.org/mailman/listinfo/zope-dev
** No cross
-in
replacement for the doctest module (in fact, it's the one from Python
2.4). You probably want to use that instead of deleting the test case ;).
W00t! Didn't know about that one, thanks! Test re-instated.
--
Martijn Pieters
___
Zope-Dev maillist - Zope-Dev
'
--
Martijn Pieters
___
Zope-Dev maillist - Zope-Dev@zope.org
http://mail.zope.org/mailman/listinfo/zope-dev
** No cross posts or HTML encoding! **
(Related lists -
http://mail.zope.org/mailman/listinfo/zope-announce
http://mail.zope.org/mailman
.
--
Martijn Pieters
___
Zope-Dev maillist - Zope-Dev@zope.org
http://mail.zope.org/mailman/listinfo/zope-dev
** No cross posts or HTML encoding! **
(Related lists -
http://mail.zope.org/mailman/listinfo/zope-announce
http://mail.zope.org/mailman/listinfo
this one also useful:
http://primates.ximian.com/~federico/docs/summer-of-code-mentoring-howto/index.html
That's the correct link! Corrected on the Wiki. :) Thanks!
--
Martijn Pieters
___
Zope-Dev maillist - Zope-Dev@zope.org
http://mail.zope.org
How-To:
http://plone.org/products/plone/releases/SoC-2007
I added it to the Wiki page. It should be mandatory reading for any
potential mentor!
--
Martijn Pieters
___
Zope-Dev maillist - Zope-Dev@zope.org
http://mail.zope.org/mailman/listinfo/zope
guards (no meaningful context to look
up on) and guard expressions need to be written taking into account
that the context is either a real content object or a catalog result.
These limitations were not a problem for the workflows involved.
--
Martijn Pieters
On 3/5/07, Martijn Pieters [EMAIL PROTECTED] wrote:
On 3/5/07, Philipp von Weitershausen [EMAIL PROTECTED] wrote:
Great. I've added you to http://wiki.zope.org/zope3/SummerOfCode2007. If
you happen to have any project suggestions, feel free to add them to the
list.
I've added myself
On 3/5/07, Philipp von Weitershausen [EMAIL PROTECTED] wrote:
Great. I've added you to http://wiki.zope.org/zope3/SummerOfCode2007. If
you happen to have any project suggestions, feel free to add them to the
list.
I've added myself to the mentors list as well.
--
Martijn Pieters
On 11/25/06, Christian Steinhauer [EMAIL PROTECTED] wrote:
As i see you fixed it. Can you give me a description how to fix it or have
you done a thread into an bugtracker?
http://svn.zope.org/Zope/branches/2.10/inst/Makefile.win.in?rev=71283view=rev
--
Martijn Pieters
is a clear candidate to be kicked...
objections?
No objections. With it you could package ZClass-based Products up for
redistribution; the redstributed version could then be installed like
a regular product, complete with locked code...
--
Martijn Pieters
passphrase into the .subversion/servers config file, and you are back
to square one.
--
Martijn Pieters
___
Zope-Dev maillist - Zope-Dev@zope.org
http://mail.zope.org/mailman/listinfo/zope-dev
** No cross posts or HTML encoding! **
(Related lists
instead of querying the database. Another value for 'bar' in
between those calls will not kill the cache.
Martijn Pieters
___
Zope-Dev maillist - Zope-Dev@zope.org
http://mail.zope.org/mailman/listinfo/zope-dev
** No cross posts or HTML encoding
Lennart Regebro wrote:
How about: http://public-bertha.in.nuxeo.com/~ben/funkload/
Is this site ment to be public? The name doesn't resolve for me. Is the
head from http://svn.nuxeo.org/trac/pub/browser/funkload/ sufficient?
Martijn Pieters
___
Zope
Martijn Pieters wrote:
Is this site ment to be public? The name doesn't resolve for me. Is the
head from http://svn.nuxeo.org/trac/pub/browser/funkload/ sufficient?
Reply to self: in the zope3 list the answer to the above question has
been found; it was Yes.
Martijn Pieters
I
responded to this afternoon still shows up in it's originally filed
state on the default URL (ending in the issue number)
Martijn Pieters
___
Zope-Dev maillist - Zope-Dev@zope.org
http://mail.zope.org/mailman/listinfo/zope-dev
** No cross posts
(the BTrees tests are
kinda very dense), I am not too keen to go touch this, but I think this
should read:
def _p_resolveConflict(self, old, s1, s2):
s1['value'] += s2['value'] - old['value']
return s1
Martijn Pieters, up to his armpits in conflict resolution code
Tim Peters wrote:
You haven't seen this fail, you're _deducing_ that it must fail, right?
Deducing indeed...
Don't overlook this other Length method:
def __getstate__(self):
return self.value
That is, when a Length instance is asked for its state, it returns an
integer.
/ as was required before.
Should I file a collector item on this?
/RPC2/ was never requered before; that URI is a convention used by Frontier
(the first server to implement XML-RPC) and possibly other XML-RPC
implementations, but never by Zope.
--
Martijn Pieters
| Software Engineer mailto:[EMAIL
all
lists this morning.
--
Martijn Pieters
| Software Engineer mailto:[EMAIL PROTECTED]
| Zope Corporation http://www.zope.com/
| Creators of Zope http://www.zope.org/
-
___
Zope-Dev maillist - [EMAIL
lists still uses the old mailman version (see my
reply to the original message). This will be switched over in due time
showing the full list again. Sorry about the inconvenience.
--
Martijn Pieters
| Software Engineer mailto:[EMAIL PROTECTED]
| Zope Corporation http://www.zope.com/
| Creators
mailman version. These lists will be migrated as well, and the page will be
switched to show the new mailman version lists list (try saying that 20
times fast).
--
Martijn Pieters
| Software Engineer mailto:[EMAIL PROTECTED]
| Zope Corporation http://www.zope.com/
| Creators of Zope http
PROTECTED]
(forwarded to [EMAIL PROTECTED]). I have seen numerous 'increase website traffic'
spams explicitly mentioning /Examples URLs around the net.
--
Martijn Pieters
| Software Engineer mailto:[EMAIL PROTECTED]
| Zope Corporation http://www.zope.com/
| Creators of Zope http://www.zope.org
of the directly-HTML-generating
python code to be shot without trial.
--
Martijn Pieters
| Software Engineer mailto:[EMAIL PROTECTED]
| Zope Corporation http://www.zope.com/
| Creators of Zope http://www.zope.org
available.
--
Martijn Pieters
| Software Engineer mailto:[EMAIL PROTECTED]
| Zope Corporation http://www.zope.com/
| Creators of Zope http://www.zope.org/
-
___
Zope-Dev maillist - [EMAIL PROTECTED]
http
at night of course.
Mea Culpa!
--
Martijn Pieters
| Software Engineer mailto:[EMAIL PROTECTED]
| Zope Corporation http://www.zope.com/
| Creators of Zope http://www.zope.org/
-
___
Zope-Dev maillist
cvs.zope.org now runs on ViewCVS 0.9.2, and I enabled CVSGraph (watch out,
big images!) and database query support. Head on over and play around with
the new look and features!
--
Martijn Pieters
| Software Engineer mailto:[EMAIL PROTECTED]
| Zope Corporation http://www.zope.com/
| Creators
Sorry for the spam that snuck through; we had memory problems on the mail
server and the spam handling facilities were temporarily off-line.
--
Martijn Pieters
| Software Engineer mailto:mj;zope.com
| Zope Corporation http://www.zope.com/
| Creators of Zope http://www.zope.org
directory should not be configurable through the web. Rather, use
an environment variable. Only one directory is needed, as files that need to
be accessible can be copied or symlinked.
--
Martijn Pieters
| Software Engineer mailto:mj;zope.com
| Zope Corporation http://www.zope.com/
| Creators
on
large files, I would need considerable justification for not using sorted
ranges. If you use Zope 2.4, then you are probably experiencing one of the
above mentioned bugs.
--
Martijn Pieters
| Software Engineer mailto:[EMAIL PROTECTED]
| Zope Corporation http://www.zope.com/
| Creators of Zope
recommended!
--
Martijn Pieters
| Software Engineer mailto:[EMAIL PROTECTED]
| Zope Corporation http://www.zope.com/
| Creators of Zope http://www.zope.org/
-
___
Zope-Dev maillist - [EMAIL PROTECTED
as 'not a bug'?
Together with the autoquoting changes, I tightened Exception messages; data
from REQUEST is quoted where I could reasonably suspect REQUEST data was
used.
--
Martijn Pieters
| Software Engineer mailto:[EMAIL PROTECTED]
| Zope Corporation http://www.zope.com/
| Creators of Zope
sounding 'hacker alert' alarm bells suggests to me that you dont really
believe that ;-)
Again, the wide scope of DTML use would make such bells warble prematurely
all too often. The normal, recommended fix for the general weakness is to
always use HTML quote.
--
Martijn Pieters
| Software Engineer
to exploit the weakness,
not in normal operation of the site.
I'll leave any decisions on wether or not this stays in the current release
cycles or moves to 2.7 to Jim Fulton. He is unfortunately on cvacation until
next week.
--
Martijn Pieters
| Software Engineer mailto:[EMAIL PROTECTED]
| Zope
that is more generaly
configurable and useable.
--
Martijn Pieters
| Software Engineer mailto:[EMAIL PROTECTED]
| Zope Corporation http://www.zope.com/
| Creators of Zope http://www.zope.org/
-
___
Zope-Dev
through other ways than
string methods.
Because of size of the change and the impact on existing DTML code, well
release betas of Zope 2.5 and 2.6 soon to facilitate wider testing. For
those following CVS, please test the changes rigorously and let me know what
you find.
--
Martijn Pieters
On Thu, Aug 01, 2002 at 10:46:44AM -0400, Martijn Pieters wrote:
I am about to land some big changes in the way DTML deals with data taken
from the REQUEST object when accessed implicitly, in both the Zope Trunk
and the Zope 2.5 branch. These changes could potentially break existing
Zope
that breakage only occurs when REQUEST data actually contains
possibly dangerous markup, and your site was vulnerable in those areas that
now break. Disabeling the tainting will leave you vulnerable.
--
Martijn Pieters
| Software Engineer mailto:[EMAIL PROTECTED]
| Zope Corporation http
can test for a specific list method.
--
Martijn Pieters
| Software Engineer mailto:[EMAIL PROTECTED]
| Zope Corporation http://www.zope.com/
| Creators of Zope http://www.zope.org/
-
___
Zope-Dev
On Thu, Jul 11, 2002 at 04:10:33PM -0400, Shane Hathaway wrote:
Python scripts provide a special function, same_type(), for this
purpose. Example:
if same_type(s, ''):
s = [s]
Much better than my hacked-up solution. :p
--
Martijn Pieters
| Software Engineer mailto:[EMAIL PROTECTED
On Thu, Apr 25, 2002 at 06:02:19PM +0200, Lennart Regebro wrote:
I want a *good* mail program. :-/
I can recommend Mutt. ;)
--
Martijn Pieters
| Software Engineer mailto:[EMAIL PROTECTED]
| Zope Corporation http://www.zope.com/
| Creators of Zope http://www.zope.org
. With the flexibility and dynamic runtime nature of Python, i wonder
how hard it would be to update a running server.
Head over to [EMAIL PROTECTED] and help out then; the effort to build a new
zope.org is already well under way.
--
Martijn Pieters
| Software Engineer mailto:[EMAIL PROTECTED
, doesn't it ? Or will there be
another way ?
No, the validation methods take into account that class members of an
implementation will have a self-referential first argument. Detecting if an
implementation is a class is trivial.
--
Martijn Pieters
| Software Engineer mailto:[EMAIL PROTECTED
as the windows problem is resolved.
--
Martijn Pieters
| Software Engineer mailto:[EMAIL PROTECTED]
| Zope Corporation http://www.zope.com/
| Creators of Zope http://www.zope.org/
-
___
Zope-Dev maillist
, the changes are in 2.5.0b3 as well (check the CHANGES.txt file when in
doubt :)).
--
Martijn Pieters
| Software Engineer mailto:[EMAIL PROTECTED]
| Zope Corporation http://www.zope.com/
| Creators of Zope http://www.zope.org
1 - 100 of 169 matches
Mail list logo