*** Zopy_ has joined #zope | 00:06 | |
*** Wu has quit IRC | 00:08 | |
*** Wu has joined #zope | 00:08 | |
*** evilbungle has quit IRC | 00:08 | |
*** spanktar|afk is now known as Spanktar | 00:08 | |
*** Zopy_ has quit IRC | 00:13 | |
*** Zopy has joined #zope | 00:15 | |
*** russf_ has joined #zope | 00:23 | |
*** russf_ has quit IRC | 00:24 | |
*** russf_ has joined #zope | 00:24 | |
*** russf has quit IRC | 00:24 | |
*** russf_ is now known as russf | 00:24 | |
*** davisagli has quit IRC | 00:32 | |
*** Zopy has quit IRC | 00:32 | |
*** davisagli has joined #zope | 00:32 | |
*** ajmitch has quit IRC | 00:33 | |
*** ajmitch has joined #zope | 00:33 | |
*** ajmitch has joined #zope | 00:33 | |
*** rogererens has quit IRC | 00:43 | |
*** MrTango has quit IRC | 00:47 | |
*** rogererens has joined #zope | 00:50 | |
*** J1m has joined #zope | 00:54 | |
*** fairlite has joined #zope | 00:57 | |
*** fairlite has joined #zope | 00:57 | |
*** ccomb has joined #zope | 00:58 | |
*** fairlite has quit IRC | 01:02 | |
*** fairlite has joined #zope | 01:04 | |
*** fairlite has joined #zope | 01:04 | |
*** fairlite has quit IRC | 01:08 | |
*** fairlite has joined #zope | 01:08 | |
*** fairlite has joined #zope | 01:08 | |
*** davisagli has quit IRC | 01:09 | |
*** JT has quit IRC | 01:09 | |
*** JT has joined #zope | 01:10 | |
*** ajmitch has quit IRC | 01:10 | |
*** tiwula has quit IRC | 01:21 | |
*** JT has quit IRC | 01:28 | |
*** Wu has quit IRC | 01:44 | |
*** sp0cksbeard has quit IRC | 01:46 | |
*** JT has joined #zope | 01:50 | |
*** ccomb has quit IRC | 01:50 | |
*** JT has quit IRC | 01:56 | |
*** JT has joined #zope | 01:56 | |
*** JT has quit IRC | 02:00 | |
*** JT has joined #zope | 02:01 | |
*** Wu has joined #zope | 02:02 | |
*** rogererens has quit IRC | 02:04 | |
*** J1m has quit IRC | 02:05 | |
*** ajmitch has joined #zope | 02:15 | |
*** rogererens has joined #zope | 02:17 | |
*** hever has quit IRC | 02:18 | |
*** hever has joined #zope | 02:18 | |
*** ajmitch has quit IRC | 02:20 | |
*** davisagli has joined #zope | 02:20 | |
*** hever has quit IRC | 02:20 | |
*** hever has joined #zope | 02:20 | |
*** JT has quit IRC | 02:21 | |
*** JT has joined #zope | 02:21 | |
*** davisagli_ has joined #zope | 02:23 | |
*** davisagli has quit IRC | 02:25 | |
*** davisagli_ is now known as davisagli | 02:25 | |
*** rogererens has quit IRC | 02:30 | |
*** ajmitch has joined #zope | 02:30 | |
*** ajmitch has joined #zope | 02:30 | |
*** davisagli has quit IRC | 02:40 | |
*** davisagli has joined #zope | 02:43 | |
*** davisagli has quit IRC | 02:47 | |
*** davisagli has joined #zope | 02:50 | |
*** _mup_ has quit IRC | 03:00 | |
*** _mup_ has joined #zope | 03:00 | |
*** davisagli has quit IRC | 03:01 | |
*** davisagli has joined #zope | 03:04 | |
*** SpankyFromBRC has joined #zope | 03:19 | |
*** ajkaanbal1 has quit IRC | 03:22 | |
*** Spanktar has quit IRC | 03:24 | |
*** zenwryly has quit IRC | 03:27 | |
*** zenwryly has joined #zope | 03:28 | |
*** _srichter has quit IRC | 03:34 | |
*** _srichter has joined #zope | 03:35 | |
*** ajmitch has quit IRC | 03:42 | |
*** ajmitch has joined #zope | 03:44 | |
*** ajmitch has joined #zope | 03:44 | |
*** daMaestro has quit IRC | 03:52 | |
*** tiwula has joined #zope | 03:53 | |
*** mitchell`off has quit IRC | 04:10 | |
*** supton has quit IRC | 04:10 | |
*** blueyed has quit IRC | 04:10 | |
*** kiorky_ has quit IRC | 04:10 | |
*** betabug has quit IRC | 04:10 | |
*** moo-_- has quit IRC | 04:10 | |
*** ajmitch has quit IRC | 04:10 | |
*** _srichter has quit IRC | 04:10 | |
*** BlueAidan has quit IRC | 04:10 | |
*** jham has quit IRC | 04:10 | |
*** Taggnostr has quit IRC | 04:10 | |
*** gawel has quit IRC | 04:10 | |
*** _mup_ has quit IRC | 04:10 | |
*** kosh has quit IRC | 04:10 | |
*** benji has quit IRC | 04:10 | |
*** zenwryly has quit IRC | 04:10 | |
*** davisagli has quit IRC | 04:10 | |
*** lewellyn has quit IRC | 04:10 | |
*** alga has quit IRC | 04:10 | |
*** yvl has quit IRC | 04:10 | |
*** alecm has quit IRC | 04:10 | |
*** CIA-33 has quit IRC | 04:10 | |
*** rodgort has quit IRC | 04:10 | |
*** [Arfrever] has quit IRC | 04:10 | |
*** raydeo has quit IRC | 04:10 | |
*** chaoflow has quit IRC | 04:10 | |
*** mcdonc has quit IRC | 04:11 | |
*** mcdonc has joined #zope | 04:13 | |
*** ajmitch has joined #zope | 04:13 | |
*** _srichter has joined #zope | 04:13 | |
*** zenwryly has joined #zope | 04:13 | |
*** davisagli has joined #zope | 04:13 | |
*** _mup_ has joined #zope | 04:13 | |
*** lewellyn has joined #zope | 04:13 | |
*** kosh has joined #zope | 04:13 | |
*** supton has joined #zope | 04:13 | |
*** alga has joined #zope | 04:13 | |
*** benji has joined #zope | 04:13 | |
*** chaoflow has joined #zope | 04:13 | |
*** yvl has joined #zope | 04:13 | |
*** BlueAidan has joined #zope | 04:13 | |
*** gawel has joined #zope | 04:13 | |
*** Taggnostr has joined #zope | 04:13 | |
*** jham has joined #zope | 04:13 | |
*** kiorky_ has joined #zope | 04:13 | |
*** betabug has joined #zope | 04:13 | |
*** moo-_- has joined #zope | 04:13 | |
*** blueyed has joined #zope | 04:13 | |
*** mitchell`off has joined #zope | 04:13 | |
*** alecm has joined #zope | 04:13 | |
*** CIA-33 has joined #zope | 04:13 | |
*** rodgort has joined #zope | 04:13 | |
*** [Arfrever] has joined #zope | 04:13 | |
*** raydeo has joined #zope | 04:13 | |
*** Spanktar has joined #zope | 04:28 | |
*** RaceCondition has quit IRC | 04:29 | |
*** russf_ has joined #zope | 04:57 | |
*** russf has quit IRC | 05:01 | |
*** russf_ is now known as russf | 05:01 | |
*** alga has quit IRC | 05:06 | |
*** hever has quit IRC | 05:13 | |
*** daver-sn has joined #zope | 05:17 | |
*** _srichter has quit IRC | 05:21 | |
daver-sn | This might have a painfully obvious answer - but I'm missing it. I have a project that is a custom customer portal/extranet built in Zope. Customers can login to download product keys, submit help requests, etc. Customer provides downloads of product updates via FTP from a separate FTP server. Customer wants to be able to control access to their ftp downloads via Zope. I.E. - Zope controls whether a customer has access to the FTP fil | 05:24 |
---|---|---|
*** Spanktar has quit IRC | 05:25 | |
*** nicksergeant has joined #zope | 05:26 | |
*** nicksergeant has left #zope | 05:26 | |
daver-sn | My explanation isn't terribly clear. When I say "customer" above - I mean my customer... When I say "customers" - I mean their customers. | 05:27 |
daver-sn | Have explored options of using a standard FTP server - like vsftp - and using PAM to authenticate - and using some method to then manipulate the PAM authentication with Zope. Seems like there might be a cleaner way though. | 05:29 |
*** Spanktar has joined #zope | 05:38 | |
*** _srichter has joined #zope | 05:39 | |
*** daver-sn has quit IRC | 05:49 | |
*** daver-sn has joined #zope | 05:51 | |
*** daver-sn has left #zope | 05:53 | |
*** _srichter has quit IRC | 05:56 | |
*** JT has quit IRC | 06:07 | |
*** JT has joined #zope | 06:24 | |
*** russf has quit IRC | 06:27 | |
*** Spanktar has quit IRC | 06:43 | |
*** Gautam has joined #zope | 07:40 | |
*** Gautam is now known as Guest19777 | 07:40 | |
*** Spanktar has joined #zope | 07:50 | |
*** Dikeshwar has joined #zope | 07:57 | |
*** mcdonc has quit IRC | 07:58 | |
*** mcdonc has joined #zope | 07:58 | |
*** __mac__ has joined #zope | 07:58 | |
*** Rakshith has joined #zope | 07:59 | |
*** ElDiabolo has joined #zope | 08:05 | |
*** Spanktar has quit IRC | 08:05 | |
ElDiabolo | Is there a set of test cases for the i18n namespace spec? | 08:05 |
*** tiwula has quit IRC | 08:09 | |
*** Dikeshwar has quit IRC | 08:12 | |
*** Rakshith has quit IRC | 08:13 | |
*** Guest19777 has quit IRC | 08:13 | |
*** tisto has joined #zope | 08:21 | |
*** Sada has joined #zope | 08:29 | |
*** Rakshith has joined #zope | 08:29 | |
*** Gautam has joined #zope | 08:29 | |
*** Gautam is now known as Guest95546 | 08:30 | |
*** Dikeshwar has joined #zope | 08:32 | |
*** d2m has joined #zope | 08:36 | |
*** dayne has joined #zope | 08:43 | |
*** dayne has quit IRC | 08:48 | |
*** __mac__ has quit IRC | 08:48 | |
*** Guest95546 has quit IRC | 08:54 | |
*** Gautam has joined #zope | 08:55 | |
*** Gautam is now known as Guest3999 | 08:55 | |
*** davisagli has quit IRC | 08:58 | |
*** davisagli has joined #zope | 08:59 | |
*** mcdonc has quit IRC | 09:07 | |
*** MrTango has joined #zope | 09:10 | |
*** zagy has joined #zope | 09:11 | |
*** Spanktar has joined #zope | 09:12 | |
*** Spanktar has quit IRC | 09:17 | |
*** Spanktar has joined #zope | 09:17 | |
*** SpankyFromBRC has joined #zope | 09:18 | |
*** davisagli has quit IRC | 09:18 | |
*** davisagli has joined #zope | 09:19 | |
*** Spanktar has quit IRC | 09:19 | |
*** SpankyFromBRC has quit IRC | 09:19 | |
*** Spanktar has joined #zope | 09:19 | |
*** ElDiabolo has quit IRC | 09:20 | |
*** Spanktar has quit IRC | 09:23 | |
*** agroszer has joined #zope | 09:29 | |
*** ccomb has joined #zope | 09:39 | |
*** planetzopebot has joined #zope | 10:08 | |
*** kosh has quit IRC | 10:15 | |
*** MrWu has joined #zope | 10:19 | |
*** __mac__ has joined #zope | 10:24 | |
*** rogererens has joined #zope | 10:31 | |
*** goschtl has joined #zope | 10:43 | |
*** avoinea has joined #zope | 10:56 | |
*** sunew has joined #zope | 10:57 | |
planetzopebot | I want your calendar data! (Lennart Regebro: Python, Plone, Web) http://regebro.wordpress.com/2011/10/04/i-want-your-calendar-data | 11:08 |
*** yvl has quit IRC | 11:13 | |
*** yvl has joined #zope | 11:15 | |
*** eperez has joined #zope | 11:24 | |
*** goschtl has quit IRC | 11:25 | |
*** mr_jolly has joined #zope | 11:33 | |
*** mr_jolly has left #zope | 11:34 | |
*** menesis has joined #zope | 11:35 | |
*** f10w has quit IRC | 11:37 | |
*** menesis has quit IRC | 11:40 | |
*** eperez has quit IRC | 11:41 | |
*** f10w has joined #zope | 11:42 | |
*** hever has joined #zope | 11:45 | |
*** evilbungle has joined #zope | 12:02 | |
*** TomBlockley has joined #zope | 12:04 | |
*** mitchell`off is now known as mitchell` | 12:07 | |
*** menesis has joined #zope | 12:11 | |
*** mcdonc has joined #zope | 12:14 | |
*** rogererens has quit IRC | 12:16 | |
*** menesis has quit IRC | 12:31 | |
*** sunew has quit IRC | 12:36 | |
*** teix has joined #zope | 12:44 | |
*** thetet has joined #zope | 12:52 | |
*** tisto has quit IRC | 12:56 | |
*** Guest3999 has quit IRC | 13:03 | |
*** Dikeshwar has quit IRC | 13:04 | |
*** Rakshith has quit IRC | 13:04 | |
*** Sada has quit IRC | 13:04 | |
*** Dikeshwar has joined #zope | 13:05 | |
*** Rakshith has joined #zope | 13:05 | |
*** Sada has joined #zope | 13:06 | |
*** eperez has joined #zope | 13:07 | |
*** Gautam has joined #zope | 13:17 | |
*** Gautam is now known as Guest6880 | 13:17 | |
*** Allmity has joined #zope | 13:20 | |
*** sunew has joined #zope | 13:42 | |
*** fRiSi has joined #zope | 13:42 | |
*** menesis has joined #zope | 13:48 | |
*** __mac__ has quit IRC | 13:51 | |
*** regebro has left #zope | 14:02 | |
*** rogererens has joined #zope | 14:13 | |
*** Sada has quit IRC | 14:15 | |
*** alga has joined #zope | 14:15 | |
*** dayne has joined #zope | 14:18 | |
*** yvl has quit IRC | 14:27 | |
*** mcdonc_ has joined #zope | 14:29 | |
*** mcdonc has quit IRC | 14:30 | |
*** __mac__ has joined #zope | 14:37 | |
*** sunew has quit IRC | 14:44 | |
*** mr_jolly has joined #zope | 14:48 | |
*** MrWu has quit IRC | 14:57 | |
*** Sada has joined #zope | 15:01 | |
*** sp0cksbeard has joined #zope | 15:25 | |
*** kosh has joined #zope | 15:25 | |
*** rogererens has quit IRC | 15:27 | |
*** rogererens has joined #zope | 15:27 | |
*** hannosch has joined #zope | 15:34 | |
*** _mup_ has quit IRC | 15:41 | |
*** _mup_ has joined #zope | 15:43 | |
*** mr_jolly_ has joined #zope | 15:53 | |
*** mr_jolly has quit IRC | 15:55 | |
*** mr_jolly_ is now known as mr_jolly | 15:55 | |
*** chrisw_ has joined #zope | 15:55 | |
chrisw_ | so, when's this announcement? | 15:56 |
hannosch | 15:00 UTC - in three hours | 15:57 |
hannosch | eh, no two hours | 15:57 |
kosh | and then I have to get everything patched | 15:57 |
kosh | it sure is strange we went for so long with almost no major security issues but recent versions have picked up 2 | 15:58 |
kosh | which is still vastly better then any other framework I have heard of | 15:58 |
hannosch | we just happen to have some people in the community who try to find them now | 15:59 |
kosh | ah well that is good | 15:59 |
kosh | so do these bugs effect older zope versions then also? | 15:59 |
hannosch | it depends. todays doesn't | 16:00 |
hannosch | one basic problem is, that Zope's security concept is so magical that almost nobody actually understands it - it just happens to protect you in most cases | 16:01 |
hannosch | but once you are trying to be a bit clever, you can shoot yourself | 16:01 |
kosh | I do like access controls and default to no access though that zope has | 16:01 |
kosh | it is vastly easier to shoot yourself in the foot with other frameworks though that don't have a security model | 16:01 |
kosh | I love fail closed design as opposed to fail open which 99% of other frameworks are | 16:02 |
kosh | at least pyramid can be set to fail closed with a 1 line change | 16:02 |
*** __mac__ has quit IRC | 16:03 | |
*** J1m has joined #zope | 16:05 | |
*** __mac__ has joined #zope | 16:09 | |
*** ajkaanbal has joined #zope | 16:10 | |
*** fRiSi has quit IRC | 16:11 | |
*** regebro has joined #zope | 16:17 | |
*** sylvain has joined #zope | 16:21 | |
*** Rakshith has quit IRC | 16:24 | |
*** dayne has quit IRC | 16:25 | |
*** regebro has quit IRC | 16:28 | |
*** regebro has joined #zope | 16:46 | |
*** __mac__ has quit IRC | 16:46 | |
*** d2m has quit IRC | 16:47 | |
*** sp0cksbeard has quit IRC | 16:55 | |
*** Allmity has quit IRC | 16:55 | |
*** __mac__ has joined #zope | 16:57 | |
*** Sada has quit IRC | 16:58 | |
*** d2m has joined #zope | 17:26 | |
chrisw_ | zone 2 is not closed by design | 17:33 |
chrisw_ | it defaults to allow a lot of things, for historical reasons... | 17:33 |
hannosch | SimpleItem.Item __allow_access_to_unprotected_subobjects__ = 1 … gargh | 17:34 |
kosh | yeah that one is bad | 17:37 |
kosh | but for most things zope is closed by default especially compared to other systems | 17:37 |
*** do3cc has joined #zope | 17:40 | |
*** tiwula has joined #zope | 17:40 | |
chrisw_ | yeah, just like a sieve mostly stops big things going through it ;-) | 17:41 |
*** Dikeshwar has quit IRC | 17:43 | |
*** rogererens has quit IRC | 17:44 | |
kosh | most frameworks stop absolutely nothing which is a major source of problems | 17:45 |
kosh | in actual practical usage I would still put up zope against django, rails, php etc security | 17:45 |
lewellyn | kosh: frameworks shouldn't. they're just a frame. it's up to you to close it up. | 17:45 |
kosh | I don't agree at all | 17:46 |
kosh | people make mistakes and they don't close things up | 17:46 |
kosh | that is shown over and over and over again | 17:46 |
lewellyn | that still doesn't make it the framework's jobe to figure out wtf you're going to not do. | 17:47 |
kosh | even major banks end up with huge gaping security holes because something was forgotten in the code | 17:47 |
lewellyn | or what you WILL for that matter | 17:47 |
kosh | it is the frameworks job to allow you to declare security permissions seperate from code implementation | 17:47 |
kosh | and nothing should be allowed by default | 17:47 |
kosh | we use fail closed in firewalls and most other security systems because that is the only thing that actually works | 17:48 |
lewellyn | some would argue that it's not the framework's job to worry about security either ;) | 17:48 |
kosh | the web is not any different, people just believe they can get security right | 17:48 |
kosh | yeah some argue that the frameworks job is not security but what you get in practice is no security | 17:48 |
* lewellyn is speaking in generalizations here, btw | 17:48 | |
kosh | you might as well argue that we all write in c and manually check all buffers since if we did that the code would run faster and everyone should check all buffers all the time anyways | 17:49 |
kosh | what we got in practice is massive buffer overflows because people did not check every single one | 17:49 |
*** fRiSi has joined #zope | 17:55 | |
*** fRiSi has quit IRC | 17:56 | |
*** Guest6880 has quit IRC | 17:58 | |
*** supton_ has joined #zope | 18:01 | |
*** Taggnostr2 has joined #zope | 18:01 | |
*** Taggnostr has quit IRC | 18:02 | |
*** Taggnostr2 has quit IRC | 18:02 | |
*** Taggnostr has joined #zope | 18:02 | |
*** do3cc has quit IRC | 18:15 | |
*** chrisw_ has quit IRC | 18:18 | |
*** daMaestro has joined #zope | 18:18 | |
*** do3cc has joined #zope | 18:20 | |
*** zagy has quit IRC | 18:24 | |
*** do3cc has quit IRC | 18:27 | |
*** supton_ has quit IRC | 18:34 | |
*** ccomb has quit IRC | 18:38 | |
*** hannosch has quit IRC | 18:49 | |
*** d2m has quit IRC | 18:53 | |
*** avoinea has quit IRC | 18:56 | |
*** avoinea has joined #zope | 18:56 | |
*** thetet has quit IRC | 18:59 | |
*** thetet has joined #zope | 19:06 | |
*** agroszer has quit IRC | 19:10 | |
*** __mac__ has quit IRC | 19:11 | |
*** menesis has quit IRC | 19:15 | |
*** thetet has quit IRC | 19:23 | |
*** teix has quit IRC | 19:44 | |
*** runyaga has joined #zope | 19:44 | |
*** runyaga has quit IRC | 19:45 | |
*** runyaga has joined #zope | 19:45 | |
*** teix has joined #zope | 19:46 | |
*** mitchell` is now known as mitchell`off | 19:54 | |
*** chrisw_ has joined #zope | 20:00 | |
*** zagy has joined #zope | 20:02 | |
*** agroszer has joined #zope | 20:06 | |
*** Spanktar has joined #zope | 20:12 | |
*** sylvain has quit IRC | 20:12 | |
*** eperez has quit IRC | 20:15 | |
*** agroszer has quit IRC | 20:21 | |
*** __mac__ has joined #zope | 20:23 | |
*** d2m has joined #zope | 20:28 | |
*** chrisw_ has quit IRC | 20:30 | |
*** evilbungle has quit IRC | 20:32 | |
*** __mac__ has quit IRC | 20:38 | |
*** rogererens has joined #zope | 20:51 | |
*** TomBlockley has quit IRC | 20:55 | |
*** Spanktar is now known as spanktar|afk | 21:50 | |
*** avoinea has quit IRC | 22:02 | |
*** alexpilz1 has joined #zope | 22:16 | |
*** alexpilz has quit IRC | 22:17 | |
*** menesis has joined #zope | 22:18 | |
*** TomBlockley has joined #zope | 22:25 | |
*** TomBlockley has quit IRC | 22:41 | |
*** teix has quit IRC | 22:48 | |
*** ajsmith has joined #zope | 22:51 | |
*** m8 has joined #zope | 22:55 | |
*** Arfrever has joined #zope | 22:56 | |
*** ajsmith has quit IRC | 22:57 | |
*** ajsmith has joined #zope | 22:57 | |
*** avoinea has joined #zope | 23:09 | |
*** zagy has quit IRC | 23:10 | |
*** menesis has quit IRC | 23:28 | |
*** ccomb has joined #zope | 23:30 | |
*** d2m has left #zope | 23:32 | |
*** MrTango has quit IRC | 23:32 | |
*** menesis has joined #zope | 23:41 | |
*** mr_jolly has left #zope | 23:49 |
Generated by irclog2html.py 2.15.1 by Marius Gedminas - find it at mg.pov.lt!