Re: Globally disabling sendto_form?
"David Glick (Plone)" <david.glick-z4DKO/[email protected]>
| Newsgroups | gmane.comp.web.zope.plone.devel |
|---|---|
| Message-ID | <[email protected]> |
Go to /manage_access and remove the Allow sendto permission from the Anonymous role (or the programmatic equivalent via a bin/instance run script) On 2/18/14, 10:12 AM, Matthew Vernon wrote: > Hi, > > We have discovered that sendto_form is being used by spammers on a > number of our Plone sites - while we don't link to it directly from > anywhere, they've clearly learned how to reach the form from the URL of > a normal Plone page. We're running 4.2.6 > > How can I bulk-disable this feature rapidly? We have around 200 sites, > so it needs to be something we can do from the command-line... > > I could presumably go into our eggs directory and remove > sendto_form.cpt, but then the next CMFPlone upgrade will end up putting > it back. > > Thanks, > > Matthew > ------------------------------------------------------------------------------ Managing the Performance of Cloud-Based Applications Take advantage of what the Cloud has to offer - Avoid Common Pitfalls. Read the Whitepaper. http://pubads.g.doubleclick.net/gampad/clk?id=121054471&iu=/4140/ostg.clktrk