Re: [Zope] Re: Every user should have the Anonymous role everywhere(was :Re: [Zope] Authentication, Anonymous and Public)
Stuart Bishop wrote: > or in BasicUserFolder. Either way it should go in the collector. Issue 1391, or in a slightly different phrasing, Issue 467 cheers, Chris ___ Zope maillist - [EMAIL PROTECTED] http://lists.zope.org/mailman/listinfo/zope ** No cross posts or HTML encoding! ** (Related lists - http://lists.zope.org/mailman/listinfo/zope-announce http://lists.zope.org/mailman/listinfo/zope-dev )
Re: [Zope] Re: Every user should have the Anonymous role everywhere(was :Re: [Zope] Authentication, Anonymous and Public)
On Sun, 2 Jul 2000, Dieter Maurer wrote: > Chris Withers writes: > > Dieter Maurer wrote: > > > In Zope, each user has a set of roles. > > > Any user has the "Anonymous" role. Log-in users may have > > > additional roles. > > > > I'm not convinced this is true... > The Content Manager Guide (Security, Authorization) states it > this way: > > The "Anonymous" role, which all users have implicitly, Ahh... I thought I saw this somewhere. Either a bug in the documentation, or in BasicUserFolder. Either way it should go in the collector. Since few (if any) of the user folders use this, it may be best handled in the Zope source if it is decided that it isn't a documentation error. -- Stuart Bishop Work: [EMAIL PROTECTED] Senior Systems Alchemist Play: [EMAIL PROTECTED] Computer Science, RMIT University ___ Zope maillist - [EMAIL PROTECTED] http://lists.zope.org/mailman/listinfo/zope ** No cross posts or HTML encoding! ** (Related lists - http://lists.zope.org/mailman/listinfo/zope-announce http://lists.zope.org/mailman/listinfo/zope-dev )
Re: [Zope] Re: Every user should have the Anonymous role everywhere (was :Re: [Zope] Authentication, Anonymous and Public)
Dieter Maurer wrote: > > > In Zope, each user has a set of roles. > > > Any user has the "Anonymous" role. Log-in users may have > > > additional roles. > > > > I'm not convinced this is true... > The Content Manager Guide (Security, Authorization) states it > this way: > > The "Anonymous" role, which all users have implicitly, ...and check out the last time the Content Manager's Guide was updated ;-) Seriously, though, I think this SHOULD be true, although I'm pretty sure it isn't. > This is natural, too. > Why should a registered user have > less authorization than an anonymous one. Or, to put it another way, just because an acl_users folder doesn't know anything about a user, why should that user not have the anonymous role? > Thus, two reasons to change the Zope authorization, such > that each user has implicitely the "Anonymous" role, > if this is not the case now. I totally agree :-) Chris ___ Zope maillist - [EMAIL PROTECTED] http://lists.zope.org/mailman/listinfo/zope ** No cross posts or HTML encoding! ** (Related lists - http://lists.zope.org/mailman/listinfo/zope-announce http://lists.zope.org/mailman/listinfo/zope-dev )
[Zope] Re: Every user should have the Anonymous role everywhere (was :Re: [Zope] Authentication, Anonymous and Public)
Chris Withers writes: > Dieter Maurer wrote: > > In Zope, each user has a set of roles. > > Any user has the "Anonymous" role. Log-in users may have > > additional roles. > > I'm not convinced this is true... The Content Manager Guide (Security, Authorization) states it this way: The "Anonymous" role, which all users have implicitly, This is natural, too. Why should a registered user have less authorization than an anonymous one. Thus, two reasons to change the Zope authorization, such that each user has implicitely the "Anonymous" role, if this is not the case now. Dieter ___ Zope maillist - [EMAIL PROTECTED] http://lists.zope.org/mailman/listinfo/zope ** No cross posts or HTML encoding! ** (Related lists - http://lists.zope.org/mailman/listinfo/zope-announce http://lists.zope.org/mailman/listinfo/zope-dev )