Re: Globally disabling sendto_form?

Matthew Vernon <mcv21-KWPb1pKIrIJaa/[email protected]>
Newsgroups gmane.comp.web.zope.plone.devel
Organization Speaking for myself
Message-ID <[email protected]>
Sean Upton <[email protected]> writes:

> On Tue, Feb 18, 2014 at 11:40 AM, Vincent Fretin
> <[email protected]> wrote:
>> I think you meant:
>> site.manage_permission('Allow sendto', roles=('Manager',))
>
> Ought an equivalent to this be an announced and publicly anticipated
> feature of the next scheduled PloneHotfix?  Can such
> site-configuration modifications be run at zope startup (since this
> would likely not be implemented gracefully as a monkey patch)?

I think it should definitely be included in the next hotfix - spammers
are abusing this bug already, and there are an awful lot of vulnerable
sites out there.

Regards,

Matthew

-- 
 `O'-----0     `O'---.       `O'---.       `O'---.
   \___| |       \___|0-/      \___|/        \___|
    |  | /\       |  |  \       |  |\         |  |
The Dangers of modern veterinary life


------------------------------------------------------------------------------
Managing the Performance of Cloud-Based Applications
Take advantage of what the Cloud has to offer - Avoid Common Pitfalls.
Read the Whitepaper.
http://pubads.g.doubleclick.net/gampad/clk?id=121054471&iu=/4140/ostg.clktrk
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.