- 10 May, 2017 1 commit
-
-
Maurits van Rees authored
If you use experimental.publishtraverse and try to call manage_pack, it warns that the object (the manage_pack function) has no roles. In strict mode it will fail. This is an indication that the function *might* be available for anonymous users. That is not the case here, but being strict seems good.
-
- 20 Feb, 2017 3 commits
-
-
Hanno Schlichting authored
-
Hanno Schlichting authored
-
Hanno Schlichting authored
-
- 15 Feb, 2017 1 commit
-
-
Maurits van Rees authored
* Test that `str.format` checks the security for attributes that are accessed. Part of PloneHotfix20170117. This needs https://github.com/zopefoundation/AccessControl/pull/23 This was merged, but not released yet, so we add AccessControl to auto-checkout for now. * AccessControl has a release, no need for auto-checkout anymore.
-
- 18 Jan, 2017 2 commits
-
-
Maurits van Rees authored
In functional doc tests you can apparently have a test case that has no runTest method. Until now the Testing package added a dummy runTest method in that case, and set it to None. But when this dummy runTest method gets called, you get an error: Error in test runTest (Testing.ZopeTestCase.ZopeTestCase.FunctionalTestCase) Traceback (most recent call last): File ".../lib/python2.7/unittest/case.py", line 329, in run testMethod() TypeError: 'NoneType' object is not callable Simply importing Testing.ZopeTestCase.FunctionalTestCase in a new test file may be enough to trigger this. So this has something to do with the order in which tests are found. I fixed it by making the dummy runTest method callable.
-
Tres Seaver authored
Apply plonehotfix 20170717 [2.13]
-
- 17 Jan, 2017 2 commits
-
-
Maurits van Rees authored
This applies PloneHotfix20170117.
-
Maurits van Rees authored
-
- 13 Jan, 2017 7 commits
-
-
Hanno Schlichting authored
-
Hanno Schlichting authored
-
Hanno Schlichting authored
-
Hanno Schlichting authored
-
Hanno Schlichting authored
-
Hanno Schlichting authored
-
Hanno Schlichting authored
-
- 27 Dec, 2016 2 commits
-
-
Maurits van Rees authored
Patch zope.interface to remove docstrings and avoid publishing.
-
Maurits van Rees authored
From Products.PloneHotfix20161129. Signed-off-by: Maurits van Rees <maurits@vanrees.org>
-
- 21 Dec, 2016 3 commits
-
-
Tres Seaver authored
Don't copy items the user is not allowed to view. [2.13]
-
Maurits van Rees authored
-
Maurits van Rees authored
-
- 08 Dec, 2016 1 commit
-
-
Maurits van Rees authored
From Products.PloneHotfix20161129.
-
- 15 Sep, 2016 2 commits
-
-
Tres Seaver authored
Add support for optional 'SameSite' cookie attribute
-
Cédric Le Ninivin authored
-
- 14 Sep, 2016 1 commit
-
-
Cédric Le Ninivin authored
As described in the definition document by the ietf: https://tools.ietf.org/html/draft-west-first-party-cookies-07 "The 'SameSite' attribute allows servers to assert that a cookie ought not to be sent along with cross-site requests. This assertion allows user agents to mitigate the risk of cross-origin information leakage, and provides some protection against cross-site request forgery attacks."
-
- 09 Sep, 2016 1 commit
-
-
Hanno Schlichting authored
Revert "Optimize 'OFS.ObjectManager.__contains__' method"
-
- 08 Sep, 2016 1 commit
-
-
Maurits van Rees authored
It causes problems with ZCatalog indexes. See https://github.com/zopefoundation/Zope/issues/69 This reverts commit 753683e3.
-
- 07 Sep, 2016 3 commits
-
-
Hanno Schlichting authored
Quote variables in manage_tabs and manage_container to avoid XSS [2.13]
-
Maurits van Rees authored
From Products.PloneHotfix20160830.
-
Maurits van Rees authored
-
- 02 Aug, 2016 1 commit
-
-
Hanno Schlichting authored
-
- 01 Aug, 2016 1 commit
-
-
Hanno Schlichting authored
The 3.0 release of the project contains no code. It allows projects to declare a dependency on it for forward compatibility with Zope 4.
-
- 17 Jul, 2016 3 commits
-
-
Hanno Schlichting authored
Apply hotfix 20160419 rebased
-
Maurits van Rees authored
-
Maurits van Rees authored
From Products.PloneHotfix20160419.
-
- 29 Jun, 2016 2 commits
-
-
Tres Seaver authored
Optimize "OFS.ObjectManager.__contains__" method (backport)
-
Malthe Borch authored
Backported from master.
-
- 04 Mar, 2016 2 commits
-
-
Maurits van Rees authored
fix ReST rendering problem in changelog
-
Jens W. Klein authored
-
- 29 Feb, 2016 1 commit
-
-
Tres Seaver authored
[ci skip]
-