| Using Nautilus from Gnome 2.2, if you go to http://zope.org without any authentication, you still
| get a full listing of the site objects.
| Nautilus does a PROPFIND, controlled by "WebDAV access", and it appears that this is allowed for Anonymous on
| zope.org. I suggest removing the "WebDAV access" permission from Anonymous.
What makes you think thats a security issue? Its been there for more
than 2 years now, and its the default configuration for Zope (at least
until the 2.5 series, havent checked on 2.6). Theres nothing there
that cant be accessed by a browser. (BTW, the same happens with WinXP
if you use \\zope.org, and the same happens to zope.com, and any other
zope site that runs the default configuration)

