Would it be sufficient to disallow the PROPFIND for non-authenticated
----- Original Message -----
From: "Barry Pederson" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Wednesday, March 06, 2002 11:39
Subject: Re: [Zope-dev] WebDAV quibble -- fix in 2.6?
> Casey Duncan wrote:
> > This maybe more 2.6 (or even 2.5.1 final) fodder:
> > I notice that in a vanilla Zope install, Anonymous users are allowed
> > through WebDAV. This is bad for two reasons:
> > 1. From a security perspective this discloses way too much information
> > your site to the outside world.
> > 2. Due to vagarities of WebDAV authentication, it makes it impossible to
> > anything, because I guess the WebDAV implementation is too stupid to
> > login when you try to lock something as anonymous (instead is returns a
> > server error). To get around this you have to create or copy an object
> > force a login. This problem disappears if everyone must login to access
> > WebDAV at all.
> > So the question is: Is there a good reason why WebDAV access is granted
> > anonymous by default? If not I vote we change it.
> Agreed, the way it is now is just wrong, and I was shocked to see it
> wide-open like that.
> Zope-Dev maillist - [EMAIL PROTECTED]
> ** No cross posts or HTML encoding! **
> (Related lists -
> http://lists.zope.org/mailman/listinfo/zope )
Zope-Dev maillist - [EMAIL PROTECTED]
** No cross posts or HTML encoding! **
(Related lists -