Re: [Zope-dev] Re: 2.7 management_page_charset cannot be callable

2004-01-15 Thread Alan Milligan
This indeed is a problem. Isn't this an issue because all of these quasi-private methods have a document string and are hence callable via an http request? If we were to remove the doc string from manage_form_title (ie via rewriting this as a python method which delegates to the underlying DTM

Re: [Zope-dev] Re: 2.7 management_page_charset cannot be callable

2004-01-15 Thread Shane Hathaway
On Fri, 16 Jan 2004, Alan Milligan wrote: > > Tres Seaver wrote: > > That change is one of a number which are designed to prevent > > cross-site scripting attacks; DTML is particularly vulnerable to such > > cracks, as it doesn't force the template writer to choose the source > > from which t

[Zope-dev] Re: 2.7 management_page_charset cannot be callable

2004-01-15 Thread Alan Milligan
Tres Seaver wrote: Alan Milligan wrote: In addition to this problem, someone has changed manage_form_title.dtml and caused me grief! The tag has been changed to <&dtml-title;> This causes an implicit html-quote to now be performed which means that my tag, inserted to display the product's i

[Zope-dev] Re: 2.7 management_page_charset cannot be callable

2004-01-15 Thread Tres Seaver
Alan Milligan wrote: In addition to this problem, someone has changed manage_form_title.dtml and caused me grief! The tag has been changed to <&dtml-title;> This causes an implicit html-quote to now be performed which means that my tag, inserted to display the product's icon to more strongly