In article <[EMAIL PROTECTED]> you write: > > Note that you'll also want to change validate() if you go that route. > > It has a short-circuited version of getRolesInContext in it. > > are you sure it's not BasicUser.allowed() that you mean? > there's a comment in there about checking roles manaully > rather than with getRolesInContext...
Yeah I'm sorry, I meant allowed(). You could also check what NuxUserGroups does, it has to patch this same area to provide a notion of groups to the security machinery. Note that I don't remember your exact use cases, but NuxUserGroups could be useful to you. Florent -- Florent Guillaume, Nuxeo (Paris, France) +33 1 40 33 79 87 http://nuxeo.com mailto:[EMAIL PROTECTED] _______________________________________________ Zope-Dev maillist - [EMAIL PROTECTED] http://mail.zope.org/mailman/listinfo/zope-dev ** No cross posts or HTML encoding! ** (Related lists - http://mail.zope.org/mailman/listinfo/zope-announce http://mail.zope.org/mailman/listinfo/zope )