[Zope3-dev] Excessive long traceback info in TALES
Florent Guillaume
fg@nuxeo.com
Thu, 12 Dec 2002 18:23:00 +0100
> Really? Jim says this too. But I and everyone who sits near me prefers
> module names over filenames. This is as strange as the XML style
> discussion we had a while back. To me it's absolutely incredible that
> anyone would prefer filenames over module names, and bulky XML
> attributes over elements.
Full filenames tracebacks should never be enabled for the casual user
otherwise you'll see many a BUGTRAQ post complaining of a "file path
disclosure" hole in Zope. The ZOPE_PATH prefix could be truncated from
it before display though.
Florent
--
Florent Guillaume, Nuxeo (Paris, France)
+33 1 40 33 79 87 http://nuxeo.com mailto:fg@nuxeo.com