[Zope] Re: access rule and authentication

Tres Seaver tseaver at palladion.com
Tue Oct 18 06:35:54 EDT 2005


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Chris Withers wrote:
> Tres Seaver wrote:
> 
>> AcceseRules run during path traversal, before any authentication is done
>> (Zope2 does "inside out" authentication starting at the "published"
>> objectd).  You might be able to force user validation to be attempted
>> earlier, e.g. by calling 'validate' directly on the user folder.
> 
> 
> Didn't someone add a post-authentication hook for this kind of thing?

Yes, but it runs too late to help for all the use cases AccessRules
address (like changing the publishing path).


Tres.
- --
===================================================================
Tres Seaver          +1 202-558-7113          tseaver at palladion.com
Palladion Software   "Excellence by Design"    http://palladion.com
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org

iD8DBQFDVNAK+gerLs4ltQ4RAp28AKDZyoLYz2UemJtj8Jt7NMMxyv0nIwCggoEr
pZf1i/CpHXoOI5geoWITcEI=
=9qHV
-----END PGP SIGNATURE-----



More information about the Zope mailing list