Skip to content.

Etria Lists

 

[quills-dev] Topic container security issue

Tim Hicks tim at sitefusion.co.uk
Sun Feb 24 13:51:17 UTC 2008


Tim Hicks wrote:
> Clayton Parker wrote:

>> I'm sending this email to see if there are any problems with what I've  
>> done.
>>
>> Here is the error I was receiving:
>> http://paste.plone.org/19698
>>
>> Here is the fix I checked in:
>> http://dev.plone.org/collective/changeset/59287
> 
> The change looks innocuous enough, but should we add a getId method that 
> returns the (now) private _id attribute?

Sorry, I just realised that we do have that method :).

> More generally, I don't really understand what the cause of the issue 
> was, or whether it was really Quills' fault.  I mean, I'm not aware of 
> 'rules' about not having 'id' attributes on objects in plone.  Are we 
> just side-stepping something more fundamental?

Still wondering about this, though.


Tim


More information about the quills-dev mailing list