[Zope] CMF1.3 private showing to anonymous

Kelley, Sean SKelley@ci.santa-rosa.ca.us
Wed, 25 Sep 2002 16:29:07 -0700


I have been having some trouble with security lately.  I took folder out of
the workflow process after some people suggested this due to strange
behavior.  I guess it sneaks if you did an upgrade from a earlier version of
CMF.  It seems that all was working fine and I don't recall making changes
to the site, but must have in some way.  Anyway, now when someone adds an
item to the site and leaves it private, it shows for "anonymous" users
anyway.  If I look at the document created, anonymous has view rights.  

What happens when something gets created then published by default?  I had
it in my head that I wanted everyone to see all published items.  To do this
I thought that anonymous should have VIEW starting at the root of the CMF.
Is this right?  If so, how them is the PRIVATE item hidden...no VIEW rights
or by being marked "Private"

-Confused