Re: [Zope-dev] Unauthorized users can writelock helpfiles in /Control_Panel/Products

2002-03-10 Thread Chris McDonough
> Chris McDonough writes: > > ... HelpSystem problems ... > > It then proceeds to do writes to the database when it > > appears that all you're doing is reading a > pre-existing page. > What does it write to the database? > I do not see a reason for this behaviour... I don't know. IMHO, ther

Re: [Zope-dev] Unauthorized users can writelock helpfiles in /Control_Panel/Products

2002-03-10 Thread Dieter Maurer
Chris McDonough writes: > ... HelpSystem problems ... > It then proceeds to do writes to the database when it > appears that all you're doing is reading a pre-existing page. What does it write to the database? I do not see a reason for this behaviour... Dieter __

Re: [Zope-dev] Unauthorized users can writelock helpfiles in /Control_Panel/Products

2002-03-09 Thread Chris McDonough
Note that I volunteered to rewrite the help system in the Zope 2.6 plan. Chris McDonough wrote: >> There is no way to fix this? What other problems are there with the >> help system? > > > Not that I can think of. Other problems with the help system are > presentation, mostly. > >> Would it

Re: [Zope-dev] Unauthorized users can writelock helpfiles in /Control_Panel/Products

2002-03-09 Thread Chris McDonough
> There is no way to fix this? What other problems are there with the > help system? Not that I can think of. Other problems with the help system are presentation, mostly. > Would it somehow be possible to make the helpsystem ignore versions? No, unfortunately. It uses the Catalog, which is

Re: [Zope-dev] Unauthorized users can writelock helpfiles in /Control_Panel/Products

2002-03-08 Thread Ivo van der Wijk
On Fri, Mar 08, 2002 at 09:24:05AM -0500, Chris McDonough wrote: > Bummer. :-( It really seems like the help system should just be > rewritten. The fact that it applies the dreaded "write on read" > pattern, uses persistent objects and the catalog to provide help has > been a thorn in our sid

Re: [Zope-dev] Unauthorized users can writelock helpfiles in /Control_Panel/Products

2002-03-08 Thread Chris McDonough
Bummer. :-( It really seems like the help system should just be rewritten. The fact that it applies the dreaded "write on read" pattern, uses persistent objects and the catalog to provide help has been a thorn in our side for a while. I think we should just come up with a much simpler help

[Zope-dev] Unauthorized users can writelock helpfiles in /Control_Panel/Products

2002-03-08 Thread Ivo van der Wijk
Hi, I'm sorry to repost my question here, but noone seems to be able to give me any information on the standard Zope mailinlist. I still do, however, find the problem described below annoying, and it could be even considered a security bug (somewhat), or at least a Help page DOS :) -- Hi all,