Re: [Zope-dev] Possible security problem with DTML

2003-03-24 Thread Shane Hathaway
On 03/24/2003 12:28 PM, kosh wrote: On Monday 24 March 2003 09:05 am, Leonardo Rochael Almeida wrote: On Fri, 2003-03-21 at 20:08, kosh wrote: I am having a problem where DTML is allowing access to an attribute of an object that restrictedTraverse and regular . notation denies from a python scrip

Re: [Zope-dev] Possible security problem with DTML

2003-03-24 Thread kosh
On Monday 24 March 2003 09:05 am, Leonardo Rochael Almeida wrote: > On Fri, 2003-03-21 at 20:08, kosh wrote: > > I am having a problem where DTML is allowing access to an attribute of an > > object that restrictedTraverse and regular . notation denies from a > > python script. > > This is pretty se

Re: [Zope-dev] Possible security problem with DTML

2003-03-24 Thread Leonardo Rochael Almeida
On Fri, 2003-03-21 at 20:08, kosh wrote: > I am having a problem where DTML is allowing access to an attribute of an > object that restrictedTraverse and regular . notation denies from a python > script. This is pretty serious. You should post this as a bug in the collector. Cheers, Leo

[Zope-dev] Possible security problem with DTML

2003-03-21 Thread kosh
I am having a problem where DTML is allowing access to an attribute of an object that restrictedTraverse and regular . notation denies from a python script. I have a python product and I have the securit.setDefaultAccess('deny') so that items inside there without security declarations can't be