Re: [Zope3-Users] public view on a private object

2007-12-20 Thread Marius Gedminas
On Wed, Dec 19, 2007 at 10:56:49PM +0200, Marius Gedminas wrote: > On Wed, Dec 19, 2007 at 08:32:02PM +0100, Lorenzo Gil Sanchez wrote: > > - Why do I have to define permissions for a view if I already > > configured the same permissions for the class? The view should always > > have more restricti

Re: [Zope3-Users] public view on a private object

2007-12-19 Thread Marius Gedminas
Hi, On Wed, Dec 19, 2007 at 08:32:02PM +0100, Lorenzo Gil Sanchez wrote: > permission="zope.ManageContent" > interface=".interfaces.IMyContent" > /> ... >for="mypackage.interfaces.IMyContent" > name="welcome.html" > class=".views.IndexView" > per

[Zope3-Users] public view on a private object

2007-12-19 Thread Lorenzo Gil Sanchez
Hi zopers, I got a security problem today and I finally fix it but I still wanted to share it with the rest of you to ask for advice and to help others to avoid my problem. My problem was that I have a content type whose class was configured with: And I have a default view for this class that