[Checkins] SVN: z3c.layer.pagelet/trunk/CHANGES.txt added missing backport bugfix release notes
Roger Ineichen
roger at projekt01.ch
Tue Sep 14 04:17:13 EDT 2010
Log message for revision 116344:
added missing backport bugfix release notes
Changed:
U z3c.layer.pagelet/trunk/CHANGES.txt
-=-
Modified: z3c.layer.pagelet/trunk/CHANGES.txt
===================================================================
--- z3c.layer.pagelet/trunk/CHANGES.txt 2010-09-13 20:15:10 UTC (rev 116343)
+++ z3c.layer.pagelet/trunk/CHANGES.txt 2010-09-14 08:17:12 UTC (rev 116344)
@@ -103,6 +103,23 @@
- Cleaned up dependencies.
+1.0.2 (2009-04-03)
+------------------
+
+- backport release, see release date
+
+- **Security issue:** The traverser defined for
+ ``IPageletBrowserLayer`` was a trusted adapter, so the security
+ proxy got removed from each traversed object. Thus all sub-objects
+ were publically accessable, too.
+
+ Making this change might BREAK your application!
+ That means if security is not well declared.
+
+- Bugfix: use IContentTemplate instead of IPageTemplate which avoids to get the
+ layout template if no IPageTemplate is registered
+
+
1.0.1 (2008-01-24)
------------------
More information about the checkins
mailing list