[ZCM] [ZC] 78/ 5 Unrestrict ""mange_pasteObjects" does not look for proxy roles"

Collector: Zope Bugs, Features, and Patches ... zope-coders@zope.org
Mon, 16 Dec 2002 14:22:35 -0500


Issue #78 Update (Unrestrict) ""mange_pasteObjects" does not look for proxy roles"
 Status Pending, Zope/bug medium
To followup, visit:
  http://collector.zope.org/Zope/78

==============================================================
= Unrestrict_pending - Entry #5 by mcdonc on Dec 16, 2002 2:22 pm

 Triggered by security_related toggle.
________________________________________
= Edit - Entry #4 by mcdonc on Dec 16, 2002 2:22 pm

 Changes: submitter email, security_related unset, new comment

This bug is not really a security "hole" so it's not necessary to make it confidential.
________________________________________
= Restrict_pending - Entry #3 by klm on Dec 7, 2001 12:58 pm

 Triggered by security_related toggle.
________________________________________
= Edit - Entry #2 by klm on Dec 7, 2001 12:58 pm

 Changes: security_related set, new comment

Chris originally meant for this to be marked as security-related, so i'm doing so (and exercising the edit transition with security-related setting).
________________________________________
= Request - Entry #1 by chrisdeckard on Dec 7, 2001 12:31 pm

Issue better defined at the following link.  In short, when
manage_pasteObjects() is called from a proxied script in a context
where the logged in user doesn't have ownership, manage_pasteObjects
raises and Unauthorized exception.

http://lists.zope.org/pipermail/zope/2001-December/105141.html

-Chris
==============================================================