[Zope] security risk in "many authors" situation

Kyler B. Laird laird@ecn.purdue.edu
Sun, 06 May 2001 09:59:30 -0500


On Sun, 6 May 2001 10:44:24 -0400 (EDT) you wrote:

>IIRC, this is *not* the case at all --

Ah!  I love being wrong about such things.

>you 'run' a script w/the
>intersection of your privileges and those of the creator.

I did something earlier that lead me to assume
that this was not the case, but I went back to
verify it and I see that what you say is correct.

My day is really looking up.  If I had been right
about that, I would have been in a world of hurt.

>(Hence, why the
>superuser can't own objects.)

Of course.  That makes perfect sense.

Thank you for the correction!

I'm sorry that I didn't check more today.  I'll
try to investigate my sleep-time conclusions a
bit before I panic next time.

--kyler