Re: [Zope-dev] Security Strangeness

2000-07-24 Thread Chris Withers
Johan Carlsson wrote: First, you can't delegate the permissionto add and delete user except by assigning the user the role "manager". IMHO this is to limiting. Second, if you give a user the permission to Change Persmissions, that user can change permissions that she doesn't have the right

[Zope-dev] Security Strangeness

2000-07-22 Thread Johan Carlsson
Hi all, I notised some strange behavior in the way Zope User Folders works. First, you can't delegate the permissionto add and delete user except by assigning the user the role "manager". IMHO this is to limiting. Second, if you give a user the permission to Change Persmissions, that user can