[Zope-dev] 2.7.3 beta attribute permission problems
Richard Jones
richard at commonground.com.au
Tue Oct 19 02:44:42 EDT 2004
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
On 19/10/2004, at 4:33 PM, Santi Camps wrote:
> Yes, meta_type is an attribute of type string, but I don't understand
> your reasons. Acquisition, obviously, is not implemented in strings,
> but if the object containing meta_type attribute inherits from
> Acquisition.Implicit it should work. In fact, it works for Zope 2.7.0
> to 2.7.2. The problem appears in Zope 2.7.3, and I think that the
> problem is the change I mentioned in AccessControl/cAccessControl.c
> and AccessControl/ImplPython.py. I suppose this change is for some
> reasonable reason, but if it breaks security validations throught
> implicit acqusition I think the change should be considered.
AFAIK Tres is working on this. I was unable to produce a simple example
case, but more recently Stefan Holek (I think) was. The last I saw was
Tres saying "Aargh!" on the 13th, then on the 14th saying he's unable
to produce good test cases.
And that's the problem. Tres' patch removed "DWIM" code. I'm not sure
what that meant (I know what DWIM stands for ;) ... and I'm unable to
state exactly (in a test case) what it is that my code does that
invokes the DWIM'y code.
Richard
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (Darwin)
iD8DBQFBdLffrGisBEHG6TARAlEZAJ46betsryQklXpFxPFK1EuxozGZxwCghtGG
+XdZTjWsgdahMh6qqGrwPL4=
=v/LZ
-----END PGP SIGNATURE-----
More information about the Zope-Dev
mailing list