[Zope3-dev] Protecting class methods

Brad Bollenbach brad@bbnet.ca
Mon, 14 Jul 2003 16:55:53 -0400


On Mon, Jul 14, 2003 at 11:41:46PM +0300, Steve Alexander wrote:
> 
> >Although it's worth noting in this particular instance (no pun intended)
> >that you (Sidnei, that is) will probably want to protect instance access
> >to the .new method as well.
> 
> Why?

Because if he only protects it when called as an attribute of a class
then the permission checks can be subverted by calling .new as an
instance method.

--
Brad Bollenbach
BBnet.ca