[ZPatterns] LoginManager roles problem

Itai Tavor itai@optusnet.com.au
Thu, 11 Oct 2001 09:50:44 +1000


Tim,

I'd like to get a copy myself, if I can! I wanted to this myself but 
wasn't sure if there were any hidden tricks involved.

Itai

Tim McLaughlin wrote:

>Joachim,
>This can be fixed by eliminating the BetterLocalRolesMixin and
>BetterSimpleUser from LoginManager.py and UserSources.py.  I can send
>you my *hacked* copy if you want.
>
>Cheers,
>Tim
>
>Joachim Schmitz wrote:
>>
>>  Hi,
>>
>>  my site structure is like this:
>>
>>  root:
>>   acl_users (standard)
>>   mysitefolder: viewable by Anonymous
>>     index_html
>>      acl_users (login-manager with a custumized login form)
>>      otherfolder: viewable only by Authenticated
>>        test dtml document
>>
>>  When I now call the /mysite/otherfolder/test
>>
>>  not my customized loginform pops up, but the standard httpauthorization =
from
>>  the root acl_users folder.
>>  When I cancel the authentication box, I get that Anonymous User has no
>>  access to the "test" document, which is contained in otherfolder
>>
>>  When I copy the index_html into the otherfolder, it works correctly.
>>
>>  Apparently LoginManager checks for the permissions in the parent, which =
is
>>  index_html. Is this a bug or a feature ?
>>
>>  Mit freundlichen Gr=FC=DFen
>>
>  > Joachim Schmitz

-- 
--
Itai Tavor                      -- "Je sautille, donc je suis."    --
itai@optusnet.com.au            --               - Kermit the Frog --
--                                                                 --
-- "If you haven't got your health, you haven't got anything"      --