[Zope-CMF] CookieCrumbler

Shane Hathaway shane@digicool.com
Fri, 06 Apr 2001 10:26:56 -0400


Danny William Adair wrote:
> the CookieCrumbler product has been put into the standard CMF installation,
> but why did you take the product itself off your page:
> http://www.zope.org/Members/hathawsh/CookieCrumbler ?

Because the two versions there had a major security hole. 
CookieCrumbler effectively disabled security for the whole site.  I
fixed the hole in the version that's in the CMF.

> Its a very nice product, and I have built up my stuff with v2.0. Apart from
> some convenience forms (forgot passwd, join, change passwd etc., like in
> membership product - still this is just an addon) I don't see much that can
> be added to CookieCrumbler at this time (maybe you do). Will further
> development - if any - only take place as part of the CMF development?

For now, yes.  As long as it's part of the CMF, it's self-explanatory;
the user doesn't have to do anything to make it work.  As a standalone
product it would require documentation and even simple documentation
takes effort to write.  If someone wants to write the documentation then
I'll gladly re-release it standalone.

Shane