Skip to main content

Zope Security Framework

Project description

The Security framework provides a generic mechanism to implement security policies on Python objects.

CHANGES

4.0.0a1 (2013-02-14)

  • Added support for Python 3.2 and 3.3.

  • 100% unit test coverage.

  • zope.security.untrustedpython moved to separate project: zope.untrustedpython

  • Converted use of assert in non-test code to apprpriate error types:

    • Non-dict’s passed to Checker.__init__.

  • Removed dprecattion of zope.security.adapter.TrustedAdapterFactory. Although it has been marked as deprectaed since before Zope3 3.2, current versions of zope.compoent still rely on it.

  • Converted doctests to Sphinx documentation in ‘docs’.

  • Added ‘setup.py docs’ alias (installs Sphinx and dependencies).

  • Added ‘setup.py dev’ alias (runs setup.py develop plus installs nose and coverage).

  • Made non-doctest tests fully independent of zope.testing.

    Two modules, zope.security.checker and zope.security.management, register cleanups with zope.testing IFF it is importable, but the tests no longer rely on it.

  • Enabled building extensions without the ‘svn:external’ of the zope.proxy headers into our ‘include’ dir.

  • Bumped zope.proxy dependency to “>= 4.1.0” to enable compilation on Py3k.

  • Replaced deprecated zope.component.adapts usage with equivalent zope.component.adapter decorator.

  • Replaced deprecated zope.interface.classProvides usage with equivalent zope.interface.provider decorator.

  • Replaced deprecated zope.interface.implements usage with equivalent zope.interface.implementer decorator.

  • Dropped support for Python 2.4 and 2.5.

  • Added test convenience helper create_interaction and with interaction().

3.8.3 (2011-09-24)

  • Fixed a regression introduced in 3.8.1: zope.location's LocationProxy did not get a security checker if zope.security.decorator was not imported manually. Now zope.security.decorator is imported in zope.security.proxy without re-introducing the circular import fixed in 3.8.1.

3.8.2 (2011-05-24)

  • Fix a test that failed on Python 2.7.

3.8.1 (2011-05-03)

  • Fixed circular import beween zope.security.decorator and zope.security.proxy which led to an ImportError when only importing zope.security.decorator.

3.8.0 (2010-12-14)

  • Added tests for our own configure.zcml.

  • Added zcml extra dependencies, run related tests only if zope.configuration is available.

  • Run tests related to the untrustedpython functionality only if RestrictedPython is available.

3.7.3 (2010-04-30)

  • Prefer the standard libraries doctest module to the one from zope.testing.

  • Fixed directlyProvides IVocabularyFactory for PermissionIdsVocabulary in Python code, even if it’s unnecessary because IVocabularyFactory is provided in zcml.

  • Removed the dependency on the zope.exceptions package: zope.security.checker now imports DuplicationError from zope.exceptions if available, otherwise it defines a package-specific DuplicationError class which inherits from Exception.

3.7.2 (2009-11-10)

  • Added compatibility with Python 2.6 abstract base classes.

3.7.1 (2009-08-13)

  • Fix for LP bug 181833 (from Gustavo Niemeyer). Before “visiting” a sub-object, a check should be made to ensure the object is still valid. Because garbage collection may involve loops, if you garbage collect an object, it is possible that the actions done on this object may modify the state of other objects. This may cause another round of garbage collection, eventually generating a segfault (see LP bug). The Py_VISIT macro does the necessary checks, so it is used instead of the previous code.

3.7.0 (2009-05-13)

  • Made pytz a soft dependency: the checker for pytz.UTC is created / tested only if the package is already present. Run bin/test_pytz to run the tests with pytz on the path.

3.6.3 (2009-03-23)

  • Ensure that simple zope.schema’s VocabularyRegistry is used for PermissionVocabulary tests, because it’s replaced implicitly in environments with zope.app.schema installed that makes that tests fail.

  • Fixed a bug in DecoratedSecurityCheckerDescriptor which made security-wrapping location proxied exception instances throw exceptions on Python 2.5. See https://bugs.launchpad.net/zope3/+bug/251848

3.6.2 (2009-03-14)

  • Add zope.i18nmessageid.Message to non-proxied basic types. It’s okay, because messages are immutable. It was done by zope.app.security before.

  • Add “__name__” and “__parent__” attributes to list of available by default. This was also done by zope.app.security package before.

  • Added PermissionsVocabulary and PermissionIdsVocabulary vocabularies to the zope.security.permission module. They were moved from the zope.app.security package.

  • Add zcml permission definitions for most common and useful permissions, like “zope.View” and “zope.ManageContent”, as well as for the special “zope.Public” permission. They are placed in a separate “permissions.zcml” file, so it can be easily excluded/redefined. They are selected part of permissions moved from zope.app.security and used by many zope.* packages.

  • Add addCheckerPublic helper function in zope.security.testing module that registers the “zope.Public” permission as an IPermission utility.

  • Add security declarations for the zope.security.permisson.Permission class.

  • Improve test coverage.

3.6.1 (2009-03-10)

  • Use from imports instead of zope.deferred to avoid circular import problems, thus drop dependency on zope.deferredimport.

  • Raise NoInteraction when zope.security.checkPermission is called without interaction being active (LP #301565).

  • Don’t define security checkers for deprecated set types from the “sets” module on Python 2.6. It’s discouraged to use them and set and frozenset built-in types should be used instead.

  • Change package’s mailng list address to zope-dev at zope.org as zope3-dev at zope.org is now retired.

  • Remove old zpkg-related files.

3.6.0 (2009-01-31)

  • Install decorated security checker support on LocationProxy from the outside.

  • Added support to bootstrap on Jython.

  • Moved the protectclass module from zope.app.security to this package to reduce the number of dependencies on zope.app.security.

  • Moved the <module> directive implementation from zope.app.security to this package.

  • Moved the <class> directive implementation from zope.app.component to this package.

3.5.2 (2008-07-27)

  • Made C code compatible with Python 2.5 on 64bit architectures.

3.5.1 (2008-06-04)

  • Add frozenset, set, reversed, and sorted to the list of safe builtins.

3.5.0 (2008-03-05)

  • Changed title for zope.security.management.system_user to be more presentable.

3.4.3 - (2009/11/26)

  • Backported a fix made by Gary Poster to the 3.4 branch: Fix for LP bug 181833 (from Gustavo Niemeyer). Before “visiting” a sub-object, a check should be made to ensure the object is still valid. Because garbage collection may involve loops, if you garbage collect an object, it is possible that the actions done on this object may modify the state of other objects. This may cause another round of garbage collection, eventually generating a segfault (see LP bug). The Py_VISIT macro does the necessary checks, so it is used instead of the previous code.

3.4.2 - (2009/03/23)

  • Added dependency ‘zope.thread’ to setup.py, without the tests were failing.

  • Backported a fix made by Albertas Agejevas to the 3.4 branch. He fixed a bug in DecoratedSecurityCheckerDescriptor which made security-wrapping location proxied exception instances throw exceptions on Python 2.5. See https://bugs.launchpad.net/zope3/+bug/251848

3.4.1 - 2008/07/27

  • Made C code compatible with Python 2.5 on 64bit architectures.

3.4.0 (2007-10-02)

  • Updated meta-data.

3.4.0b5 (2007-08-15)

  • Bug: Fixed a circular import in the C implementation.

3.4.0b4 (2007-08-14)

  • Bug: zope.security.management.system_user had an ugly/brittle id.

3.4.0b3 (2007-08-14)

  • zope.security now works on Python 2.5

  • Bug: zope.security.management.system_user wasn’t a valid principal (didn’t provide IPrincipal).

  • Bug: Fixed inclusion of doctest to use the doctest module from zope.testing. Now tests can be run multiple times without breaking. (#98250)

3.4.0b2 (2007-06-15)

  • Bug: Removed stack extraction in newInteraction. When using eggs this is an extremly expensive function. The publisher is now more than 10 times faster when using eggs and about twice as fast with a zope trunk checkout.

3.4.0b1

  • Temporarily fixed the hidden (and accidental) dependency on zope.testing to become optional.

Note: The releases between 3.2.0 and 3.4.0b1 where not tracked as an individual package and have been documented in the Zope 3 changelog.

3.2.0 (2006-01-05)

  • Corresponds to the verison of the zope.security package shipped as part of the Zope 3.2.0 release.

  • Removed deprecated helper functions, ‘proxy.trustedRemoveSecurityProxy’ and ‘proxy.getProxiedObject’.

  • Made handling of ‘management.{end,restore}Interaction’ more careful w.r.t. edge cases.

  • Made behavior of ‘canWrite’ consistent with ‘canAccess’: if ‘canAccess’ does not raise ‘ForbiddenAttribute’, then neither will ‘canWrite’. See: http://www.zope.org/Collectors/Zope3-dev/506

  • Code style / documentation / test fixes.

3.1.0 (2005-10-03)

  • Added support for use of the new Python 2.4 datatypes, ‘set’ and ‘frozenset’, within checked code.

  • C security proxy acquired a dependency on the ‘proxy.h’ header from the ‘zope.proxy’ package.

  • XXX: the spelling of the ‘#include’ is bizarre! It seems to be related to ‘zpkg’-based builds, and should likely be revisited. For the moment, I have linked in the ‘zope.proxy’ package into our own ‘include’ directory. See the subversion checkin: http://svn.zope.org/Zope3/?rev=37882&view=rev

  • Updated checker to avoid re-proxying objects which have and explicit ‘__Security_checker__’ assigned.

  • Corresponds to the verison of the zope.security package shipped as part of the Zope 3.1.0 release.

  • Clarified contract of ‘IChecker’ to indicate that its ‘check*’ methods may raise only ‘Forbidden’ or ‘Unauthorized’ exceptions.

  • Added interfaces, (‘IPrincipal’, ‘IGroupAwarePrincipal’, ‘IGroup’, and ‘IPermission’) specifying contracts of components in the security framework.

  • Code style / documentation / test fixes.

3.0.0 (2004-11-07)

  • Corresponds to the version of the zope.security package shipped as part of the Zope X3.0.0 release.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

zope.security-4.0.0a1.tar.gz (700.1 kB view details)

Uploaded Source

Built Distributions

If you're not sure about the file name format, learn more about wheel file names.

zope.security-4.0.0a1.win-amd64-py2.7.exe (344.4 kB view details)

Uploaded Source

zope.security-4.0.0a1.win-amd64-py2.6.exe (344.3 kB view details)

Uploaded Source

zope.security-4.0.0a1.win32-py2.7.exe (316.6 kB view details)

Uploaded Source

zope.security-4.0.0a1.win32-py2.6.exe (316.5 kB view details)

Uploaded Source

zope.security-4.0.0a1-py2.7-win-amd64.egg (212.7 kB view details)

Uploaded Egg

zope.security-4.0.0a1-py2.7-win32.egg (212.4 kB view details)

Uploaded Egg

zope.security-4.0.0a1-py2.6-win-amd64.egg (213.2 kB view details)

Uploaded Egg

zope.security-4.0.0a1-py2.6-win32.egg (212.8 kB view details)

Uploaded Egg

File details

Details for the file zope.security-4.0.0a1.tar.gz.

File metadata

File hashes

Hashes for zope.security-4.0.0a1.tar.gz
Algorithm Hash digest
SHA256 4e5677a9d976d384a4d8c9f6135e818509beed84f93ff2edd2b605f419881035
MD5 68a6c61a3744248393413f62ead144eb
BLAKE2b-256 4c93c73d8167d778bf5d0b150bd6c6420901128beb22ba1bc0154e9637b0e855

See more details on using hashes here.

File details

Details for the file zope.security-4.0.0a1.win-amd64-py2.7.exe.

File metadata

File hashes

Hashes for zope.security-4.0.0a1.win-amd64-py2.7.exe
Algorithm Hash digest
SHA256 a83497de2a64636a32387b76ca2ac79dcd00a46708947eb6ea38aee7e18bb4fd
MD5 34eeddea9bfe7914a21333da85c061c9
BLAKE2b-256 8d203879ebb240e169c54307334af1ac767c63962931731132e49b46e5e69805

See more details on using hashes here.

File details

Details for the file zope.security-4.0.0a1.win-amd64-py2.6.exe.

File metadata

File hashes

Hashes for zope.security-4.0.0a1.win-amd64-py2.6.exe
Algorithm Hash digest
SHA256 265032b593b38f231c6d8d812d4c3aab58176032b93d91cf788dee4b5680bdea
MD5 c7237fb4528cdc5b7da6003b98b661f3
BLAKE2b-256 3904f9d1459370ef06c3e672553b9865ee58e41afdfb962f38bc953603ecef80

See more details on using hashes here.

File details

Details for the file zope.security-4.0.0a1.win32-py2.7.exe.

File metadata

File hashes

Hashes for zope.security-4.0.0a1.win32-py2.7.exe
Algorithm Hash digest
SHA256 d0f1126367975c1fafa27f2102b35976a95f382bd2059b895cdf212fd78cf8fd
MD5 e880e146fd8b1fa4d7b8403a7067c04a
BLAKE2b-256 1328f235f97ee2822f3ddc588ae5de9a3520082cb4faff2c23d1175af0109a3c

See more details on using hashes here.

File details

Details for the file zope.security-4.0.0a1.win32-py2.6.exe.

File metadata

File hashes

Hashes for zope.security-4.0.0a1.win32-py2.6.exe
Algorithm Hash digest
SHA256 0a8dddf9a0f940a6afd4b0be4d29d0179c4508fa75699e6df9cfd1b78d09c4ac
MD5 0f3062f1e90c1589cc2fe4d63345485c
BLAKE2b-256 f5ed3e1026948a4b6fd7d52afef5bebc30ae74ed6263d7f161b54b75e01b2cfa

See more details on using hashes here.

File details

Details for the file zope.security-4.0.0a1-py2.7-win-amd64.egg.

File metadata

File hashes

Hashes for zope.security-4.0.0a1-py2.7-win-amd64.egg
Algorithm Hash digest
SHA256 504fbea9f543d79e478e3d6d94c7ad265af2d5f3d33c7172a0378906991d30dd
MD5 060b76dca0be83e2be12853dd64cfcb7
BLAKE2b-256 41e13bfcfb1821c2f49e5c71ad37bd0051d6160c0831aa8272b655834c7642a9

See more details on using hashes here.

File details

Details for the file zope.security-4.0.0a1-py2.7-win32.egg.

File metadata

File hashes

Hashes for zope.security-4.0.0a1-py2.7-win32.egg
Algorithm Hash digest
SHA256 4eb28fd28c056a17e934030f54812d1d45fd79208840634449d29bad97519cc4
MD5 471bfe91383b06d5fd5778df5b823322
BLAKE2b-256 309003517a90f877aecda280a034f2417ec893890d85ce88d124909670e515c5

See more details on using hashes here.

File details

Details for the file zope.security-4.0.0a1-py2.6-win-amd64.egg.

File metadata

File hashes

Hashes for zope.security-4.0.0a1-py2.6-win-amd64.egg
Algorithm Hash digest
SHA256 9e18f2d390af276aeaaa00ba73a406fcf44b8a97a1cde75f9b86cda9a9cdb0ac
MD5 e8160cf7d2c3d654c1f41155e8304f07
BLAKE2b-256 5b4eb52d73dcd9304e87566041b0536feefffdaabbf63d21bd51d26b91ef9813

See more details on using hashes here.

File details

Details for the file zope.security-4.0.0a1-py2.6-win32.egg.

File metadata

File hashes

Hashes for zope.security-4.0.0a1-py2.6-win32.egg
Algorithm Hash digest
SHA256 42000d71818acf22d5b9eb095a4da3ff53d35a836321fc71aed63483988855c6
MD5 2c292107049657dc1234869b4adbb682
BLAKE2b-256 5902a476a0286cf53b6c7813c0d71614e3d06a18d27d67da7b8a6c59fba8f058

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page