[Zope] acl_user and parent directory

Stephan Goeldi stephan.goeldi@datacomm.ch
Wed, 11 Oct 2000 14:15:22 GMT


When I create a user in a subfolder, he can view the files in the parent 
folders:

/www/folder1
/www/folder2

The manager of folder1 can not only view the content of /www but the content 
and the files of /www/folder2 too.

This is BAD security IMHO.

I don't want the user of folder1 let to know, that there exists a folder2!
_________________________________________________________________________
Get Your Private, Free E-mail from MSN Hotmail at http://www.hotmail.com.

Share information about yourself, create your own public profile at 
http://profiles.msn.com.