Re: [Zope-dev] Re: Suggestion for small(?) change in BaseRequest.py. Security effects?

2004-09-03 Thread Dieter Maurer
Tres Seaver wrote at 2004-9-3 08:56 -0400: > ... >I am worried that there may be third-party application code which relies >on 'validate' to raise an exception. Returning the login form directly >is not really a big win over a redirect; among other things, it messes >up cacheability, because t

[Zope-dev] Re: Suggestion for small(?) change in BaseRequest.py. Security effects?

2004-09-03 Thread Tres Seaver
Lennart Regebro wrote: Dieter Maurer wrote: Lennart Regebro wrote at 2004-9-2 12:38 +0200: ... Are there any other problems with NOT raising an exception in unathorized(). Becuase if there is, we probably limit the possible challenge responses to a redirect, and then this change makes no differe