[Zope3-Users] RFC: Should Zope grant view access to everybody?

Garrett Smith garrett at mojave-corp.com
Mon Feb 7 13:51:33 EST 2005


Jim Fulton wrote:
> By default, Zope 2 grants view access to the anonymous role.
> 
> Should Zope 3 do the equivalent?  Ot should sites be private
> unless they are explicitly made public?

+1 for private until told otherwise. It's a policy assumption either
way, but more secure is a better assumption than less secure.

 -- Garrett


More information about the Zope3-users mailing list