Re: AccessControl bug fixed
Hanno Schlichting <[email protected]>
| Newsgroups | gmane.comp.web.zope.devel |
|---|---|
| Message-ID | <CAJ5sox4abnVuar5boT7ZuhMN3QEL+bBHbfQnM1EAqSsySxzReQ@mail.gmail.com> |
On Thu, Aug 23, 2012 at 5:23 PM, <[email protected]> wrote: > does this have any security implications? In short: No. Long answer: Not unless you have very custom code similar to what's in the provided test (providing a custom rolesForPermissionOn callable on a class). And that code would have never worked as intended or at least it would have already been broken in Zope 2.12. Hanno _______________________________________________ Zope-Dev maillist - [email protected] https://mail.zope.org/mailman/listinfo/zope-dev ** No cross posts or HTML encoding! ** (Related lists - https://mail.zope.org/mailman/listinfo/zope-announce https://mail.zope.org/mailman/listinfo/zope )