[Zope-dev] ZCatalog madness. (Must log in as emergencyuser.)

Steve Alexander steve@cat-box.net
Thu, 22 Feb 2001 17:38:22 +0000


Chris McDonough wrote:

> I'm not sure why this isn't in 2.3.1b1, but yes, the code in getobject was
> changed to use unrestrictedTraverse for this very reason.

Does that open up a security hole?

Can I get to an object via the getobject method of ZCatalog that I can't get to otherwise?

I thought that was the reason it was changed to restrictedTraverse in the first place.


--
Steve Alexander
Software Engineer
Cat-Box limited
http://www.cat-box.net