RE: [Zope] Re: [Zope-dev] possible security flaw? - and, request for a phone conference. conference.
8 Jun
2000
8 Jun
'00
1:48 p.m.
Basically, if a user with manager privileges to a folder changes their password to be empty, then anyone (from permitted domains) can access the management screen for that folder Without Logging On... Zope assumes that you are the user without the password and treats you as if you have those rights.
This is a feature, but I don't know if or where it is documented besides the source code (which is a bug if it isn't I guess).
You're right - it is a feature. You are also right that it isn't documented anywhere that I can find :( I would suggest adding this to the Collector (as a 'Documentation Request'). Brian Lloyd brian@digicool.com Software Engineer 540.371.6909 Digital Creations http://www.digicool.com
9434
Age (days ago)
9434
Last active (days ago)
0 comments
1 participants
participants (1)
-
Brian Lloyd