Re: [Zope-dev] security problem in an monkey-patch

2007-09-19 Thread Dieter Maurer
Joachim Schmitz wrote at 2007-9-19 11:54 +0200: >and > >../portal_catalog/getBypassQueue >displays a 1 This looks like a security bug. You should not be able to "call" something via the ZPublisher what you cannot call in a script. Maybe, you file a bug report? -- Dieter _

[Zope-dev] security problem in an monkey-patch

2007-09-19 Thread Joachim Schmitz
Hi, I have monkey-patched the QueueCatalog to adopt it to our needs, which works fine. I now wanted to introduce a new feature: The QueueCatalog should be bypassed during mass-import of data. So I introduced a new variable "_bypass", and new getBypassQueue() and setBypassQueue methods in the