Sidnei da Silva sidnei at awkly.org
Tue Dec 23 18:13:04 EST 2003

On Tue, Dec 23, 2003 at 05:39:01PM -0500, Tres Seaver wrote:
| I have a feeling that we are patching code here which would be better
| removed;  in particular, I can't see any reason to declare the
| 'editSynProperies' method public, and then turn around and do an
| unconditional permission check + raise Unauthorized as the first action
| of the method.
| I would prefer to check in the attached patch (for 1.3 / 1.4;  the head
| needs some light sanding after applying it), which just delcares the
| method protected by the same permission used in the '_checkPermission'
| call;  it then rips out all the other cruft.
| Any issues with that?

Well, your change would then require the user to have 'Manage
Properties' on the Syndication Tool, which may not be true on all
cases. Suppose a 'member' wants to allow syndication of his member
folder. This is possible now, but wouldn't with your change (at least
that's how I understand it).

