[Zope] VirtualHostMonster: access to all content in instance

Martijn Pieters mj at zopatista.com
Fri Jul 4 10:31:51 EDT 2008


On Fri, Jul 4, 2008 at 3:03 PM, Jonas Meurer <jonas at freesources.org> wrote:
> But both project1 and project3 are also accessible through project2.com
> over the URLs "http://www.project2.com/project1" and
> "http://www.project3.com/project3".
>
> Is this a known issue? I consider that as a quite serious bug, as both
> project1 and project3 might be private and should not be published over
> the globally available apache rewriterule.

This is expected behaviour, you are seeing Acquisition at work. Do not
rely on VirtualHostMonster to provide security, it only provides URL
rewriting services.

-- 
Martijn Pieters


More information about the Zope mailing list