Skip to main content

This package allows to work around weaknesses in the web application server Zope’s security subsystem. Currently, it contains a single module proxy.

proxy

In principle, Zope makes a clear distinction between trusted code (which comes from the file system and cannot be modified through-the-web) and untrusted code (which might be tangled with through-the-web). Trusted code is unrestricted by Zope’s security subsystem, untrusted code has permission checks on each object and method access.

Unfortunately, occasionnally, trusted code performs its own security checks – and can raise Unauthorized exceptions even when called from other trusted code. The proxy module is destined to work around this behaviour. It uses Zope’s so called proxy roles to set up roles which should be used for internal security checks.

The module defines the context manager proxy_roles(*roles), typically used as follows:

>>> with proxy_roles(role1, role2, ...):
>>>   ... perform any operation[s] with internal security checks ...

This sets up proxy roles role1, role2, … to be used for the internal security checks.

Usually, the roles are 'Manager', 'Authenticated' but can be anything. Note that proxy roles override any currently active user roles.

History

2.0

Make Python 3/Zope 4 compatible; drop support for Python 2.6 (and below)

New “context manager” interface.

Metadata

Release files for dm.zopepatches.security 2.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for dm.zopepatches.security 2.0
File Size Uploaded
dm.zopepatches.security-2.0.tar.gz 3.2 kB Details

Release files / dm.zopepatches.security-2.0.tar.gz

Download URL dm.zopepatches.security-2.0.tar.gz
Size 3.2 kB
Tags Source
SHA-256 checksum
How to use checksums
7d4b47c2d2f416863ee4944dcb7881f17bd086dd32ee51fde7d5edd7635babaf
BLAKE2b-256 checksum
How to use checksums
3d737d43352365578afd85ee261d22eeaf4db4cbcc0ee751df7678fda0363fcd
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via Python-urllib/2.7

Release history Release notifications | RSS feed

This release

2.0 This release

1 release file

1.0

1 release file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page