[Zope] Zope and security.

Christopher Petrilli petrilli@digicool.com
Thu, 11 Nov 1999 14:11:21 -0500


On 11/11/99 11:57 AM, Otto Hammersmith at otto@ipass.net wrote:

> If I take away "Create ZSQL Methods" from his home folder but don't take
> away the security tab, he can put it right back.  If I'm using UserDB to
> authenticate he can just create a Z SQL Method that queries the db for
> userid's and passwords.

How about using security in the database?  I'd never consider using the same
login/password for UserDB that I used for application data, ever.

Chris
-- 
| Christopher Petrilli        Python Powered        Digital Creations, Inc.
| petrilli@digicool.com                             http://www.digicool.com