[ZCM] [ZC] 338/ 4 Resolve "security.declareProtected misbehaviour"

Collector: Zope Bugs, Features, and Patches ... zope-coders-admin at zope.org
Tue Oct 21 09:44:02 EDT 2003


Issue #338 Update (Resolve) "security.declareProtected misbehaviour"
 Status Resolved, Zope/bug medium
To followup, visit:
  http://collector.zope.org/Zope/338

==============================================================
= Resolve - Entry #4 by Brian on Oct 21, 2003 9:44 am

 Status: Accepted => Resolved


________________________________________
= Assign - Entry #3 by Brian on Oct 21, 2003 9:42 am

 Status: Pending => Accepted

 Supporters added: Brian

Fixed on the head, 2.6 and 2.7 branches
________________________________________
= Comment - Entry #2 by leper on Jul 6, 2003 6:22 am

issue 761 proves this has bitten people

patch: http://audible.transient.net/zope/safersecapi.diff
________________________________________
= Request - Entry #1 by d.maurer on Apr 10, 2002 4:26 am

"AccessControl.ClassSecurityInfo.declareProtected(perm)" behaves like "AccessControl.ClassSecurityInfo.declareObjectProtected(perm)".

This unexpected behaviour can lead to hours of analysis of difficult security errors and
be a potential security hazzard.
==============================================================




More information about the Zope-Collector-Monitor mailing list