[Zope3-dev] Excessive long traceback info in TALES
Brian Lloyd
brian@zope.com
Wed Dec 10 18:18:33 EST 2003
> > Maybe this could be used to replace the current sub-optimal traceback
> > (with no source code) that gets displayed?
>
> The traceback includes the filename and position of errors in page
> templates, which is very valuable. I'm surprised you consider this
> sub-optimal.
>
> I'm not sure what you mean by "no source code". If you mean that it
> shows the module name rather than the filename, I'd hate to go back on
> that change. It made Zope 2.6 tracebacks far more readable!
FWIW, keeping filenames out of tracebacks was a fairly strong
goal of the traceback hackery we've done thus far. It was done in
response to numerous recurring "security-related bug reports", with
people feeling that any disclosure of filenames is bad. While one
can argue that point, we've had people in the past willing to post
this as a "security issue" on public security-related sites, and
it's really not a good use of time trying to fight that sort of
PR battle.
Brian Lloyd brian@zope.com
V.P. Engineering 540.361.1716
Zope Corporation http://www.zope.com
More information about the Zope3-dev
mailing list