Commit graph

48 commits

Author SHA1 Message Date
Martin Wilke
b8cbb211eb - Update to 2.9.5
PR:		ports/104007
Submitted by:	HAYASHI Yasushi <yasi@yasi.to> (maintainer)
2006-10-06 19:12:07 +00:00
Renato Botelho
bd3acbc8df - Update to 2.9.4
PR:		ports/101236
Submitted by:	HAYASHI Yasushi <yasi at yasi.to> (maintainer)
2006-08-03 15:53:04 +00:00
Ion-Mihai Tetcu
2feda99d5f Corrects an information disclosure vulnerability in Zope2, due to Zope2's use
of the docutils module to parse and render "restructured text". Sites which
allow untrusted users to create restructured text as through-the-web
content should apply this hotfix.

PR:		ports/99952
Submitted by:	maintainer
Security:	http://www.zope.org/Products/Zope/Hotfix-2006-07-05/Hotfix-2006-07-05/
2006-07-09 12:35:56 +00:00
Renato Botelho
459f6251a5 - Update to 2.9.3
PR:		ports/97340
Submitted by:	maintainer
2006-05-16 18:01:44 +00:00
Marcus Alves Grando
ac72a7f269 - Update to 2.9.2
PR:		96804
Submitted by:	maintainer
2006-05-05 23:48:15 +00:00
Renato Botelho
2db166c935 - Update to 2.9.1
PR:		ports/94776
Submitted by:	maintainer
2006-03-21 16:54:03 +00:00
Pav Lucistnik
7c2c2661e4 - Add Zope 2.9.0 after repocopy
PR:		ports/91824
Submitted by:	HAYASHI Yasushi <yasi@yasi.to>
Repocopy by:	marcus
2006-01-28 10:07:29 +00:00
Pav Lucistnik
5eade7a03d - Update to 2.8.5
PR:		ports/91365
Submitted by:	Denis Shaposhnikov <dsh@vlink.ru> (maintainer)
2006-01-05 23:39:09 +00:00
Marcus Alves Grando
552e963a35 Update to 2.8.4
Changelog http://www.zope.org/Products/Zope/2.8.4/CHANGES.txt

PR:		88078
Submitted by:	Denis Shaposhnikov <dsh@vlink.ru> (maintainer)
2005-10-28 03:04:44 +00:00
Renato Botelho
f4453868d7 - Update to 2.8.3
2.8.3 release:
  http://www.zope.org/Products/Zope/2.8.3/CHANGES.txt

==========
    * ZSQLMethod.manage_main: Moved the error message that warns of a
      non-existing or closed database connection next to the
      Connection ID dropdown and present it using red to increase its
      visibility.
    * Update to Docutils 0.3.9 (forgotten in Zope 2.8.2)
==========

PR:		ports/87650
Submitted by:	maintainer
2005-10-19 12:27:51 +00:00
Marcus Alves Grando
037f39f0a1 Update to 2.8.2
PR:		87428
Submitted by:	Denis Shaposhnikov <dsh@vlink.ru> (maintainer)
2005-10-14 13:15:25 +00:00
Marcus Alves Grando
df76266e49 Hotfix 2005-10-09 Alert
This hotfix addresses an important security issue that affects users of Zope
versions 2.6 or higher.

PR:		87198
Submitted by:	Denis Shaposhnikov <dsh@vlink.ru> (maintainer)
Security:	http://www.vuxml.org/freebsd/d2b80c7c-3aae-11da-9484-00123ffe8333.html
2005-10-12 00:04:12 +00:00
Vsevolod Stakhov
6b2c94a1a2 Add zope28 - new stable branch of zope application server.
Here are some of the "headlines" mentioned in the features list.

Database Integration
	SQL and HTML in Harmony
	Multiple Data Sources
	Publish Databases
Application Development
	DTML Scripting
	External Methods
Content Management
        Builtin Objects
	Document Templates
Web to Objects
	Integrated Object Database
	Managed Through the Web
	Direct URL Access to Objects

PR:		85063
Submitted by:	Denis Shaposhnikov <dsh@vlink.ru>
2005-09-18 21:33:04 +00:00
Pav Lucistnik
1f984e07c6 - Update to 2.7.7
PR:		ports/83377
Submitted by:	HAYASHI Yasushi <yasi@yasi.to>
Approved by:	Gerhard Schmidt <estartu@augusta.de> (maintainer)
2005-07-13 13:09:01 +00:00
Jean-Yves Lefort
172b04b63c Update to 2.7.6
PR:		ports/80476
Submitted by:	HAYASHI Yasushi <yasi@yasi.to>
Approved by:	maintainer
2005-05-07 20:53:42 +00:00
Pav Lucistnik
195a06bff7 - Update to 2.7.5
PR:		ports/79812
Submitted by:	HAYASHI Yasushi <yasi@yasi.to>
Approved by:	Gerhard Schmidt <estartu@augusta.de> (maintainer)
2005-04-13 08:25:03 +00:00
Pav Lucistnik
e153f4d0be - Update to 2.7.4
PR:		ports/77633
Submitted by:	Gerhard Schmidt <estartu@augusta.de> (maintainer)
2005-02-18 16:52:17 +00:00
Pav Lucistnik
bf01faeea1 - Update to 2.7.3
PR:		ports/73969
Submitted by:	Gerhard Schmidt <estartu@augusta.de> (maintainer)
2004-11-16 00:02:25 +00:00
Pav Lucistnik
54b2489db2 - Update to 2.7.2
- Add special pkg-message to package to help with installation from package

PR:		ports/69476
Submitted by:	HAYASHI Yasushi <yasi@yasi.to>,
		Gerhard Schmidt <estartu@augusta.de> (maintainer)
2004-07-24 11:06:23 +00:00
Thierry Thomas
854938fdee Upgrade to 2.7.1.
PR:		ports/68408
Submitted by:	HAYASHI Yasushi
Approved by:	maintainer.
2004-07-02 20:41:00 +00:00
Pav Lucistnik
bc4cd30966 - Update to 2.7.0
PR:		ports/63265
Submitted by:	Gerhard Schmidt <estartu@augusta.de>
Approved by:	crowds on python@ via perky (in general)
2004-04-02 00:00:29 +00:00
Trevor Johnson
8232e82f85 SIZEify (maintainer timeout) 2004-03-31 03:12:58 +00:00
Neil Blakey-Milner
0312b43bb0 Upgrade www/zope to version 2.6.2
PR:		59000
Submitted by:	Osma Suominen <ozone@sange.fi>
2003-11-21 18:11:38 +00:00
Hye-Shik Chang
62d30a76fb Upgrade to 2.6.1
PR:		52038
Submitted by:	Miguel Mendez <flynn@energyhq.es.eu.org>
2003-05-12 03:36:53 +00:00
Alan Eldridge
e741dc2b46 Updated to 2.6.0. Simon, you forgot to remove the temp files before making
the plist ;)

PR:		46168
Submitted by:	Simon 'corecode' Schubert <corecode@eikonww2.eikon.e-technik.tu-muenchen.de>
2003-01-12 17:48:19 +00:00
Neil Blakey-Milner
f5dcd933c0 Upgrade to Zope 2.5.1
PR:		ports/37763
Submitted by:	HAYASHI Yasushi <yasi@yasi.to>
2002-05-08 18:50:07 +00:00
Neil Blakey-Milner
be5a1dcb66 Implement the HotFix described at
http://www.zope.org/Products/Zope/Hotfix_2002-03-01/README.txt which
says:

``The issue involves the checking of security for objects with proxy
  roles. The context of the owner user that created the object with
  proxy roles was not being taken into account when determining access
  to the object with proxy roles. This flaw could allow users defined
  in subfolders of a site with sufficient privileges to access objects
  at higher levels in the site that they would not normally be able to
  access.''

PR:		36103
Submitted by:	HAYASHI Yasushi <yasi@yasi.to>
2002-03-23 10:04:29 +00:00
Neil Blakey-Milner
1a17adebbf Upgrade to 2.5.0 plus the security fix.
PR:		ports/34430
Submitted by:	HAYASHI Yasushi <yasi@yasi.to>
2002-02-05 20:26:09 +00:00
Neil Blakey-Milner
8acebe2dac Upgrade to 2.4.2 2001-10-19 21:09:35 +00:00
Neil Blakey-Milner
f213143e00 Upgrade to Zope 2.4.1. 2001-09-10 08:52:19 +00:00
Neil Blakey-Milner
434868fb60 Acqusition context checking hotfix
``The issue involves an error in the '_check_context' method of the
AccessControl.User.BasicUser class. The bug made it possible to access
Zope objects via acquisition that a user would not otherwise have access
to. This issue could allow users with enough internal knowledge of Zope
to perform actions higher in the object hierarchy than they should be
able to.''
2001-08-04 17:29:00 +00:00
Vanilla I. Shu
6b0274afa1 Upgrade to 2.4.0.
Approved by:	nbm
2001-07-25 23:32:57 +00:00
Jimmy Olgeni
45bd8c5f79 Update port to version 2.3.3.
Approved by:	nbm
2001-07-04 20:52:41 +00:00
Neil Blakey-Milner
061280635c Update to Zope 2.3.2 + Hotfix 2001-05-01 2001-05-03 10:14:53 +00:00
Neil Blakey-Milner
73744dc786 Upgrade to Zope 2.3.1! 2001-03-31 12:12:26 +00:00
Jimmy Olgeni
32bd499f1c Apply Zope hotfix: Hotfix_2001-03-08
From the Zope site:

The issue involves an error in the 'aq_inContextOf' method of objects that
support acquisition. A recent change to the access validation machinery
made this bug begin to affect security restrictions. The bug, with the
change to validation, made it possible to access Zope objects via
acquisition that a user would not otherwise have access to. This issue
could allow users with enough internal knowledge of Zope to perform actions
higher in the object hierarchy than they should be able to.
2001-03-10 12:22:15 +00:00
Neil Blakey-Milner
5aaf8bc98b Apply a Zope hotfix, fixing a potential security problem.
From the Zope hotfix:

	This hotfix addresses and important security issue that affects Zope
	versions up to and including Zope 2.3.1 b1.

	The issue is related to ZClasses in that a user with through-the-web
	scripting capabilities on a Zope site can view and assign class
	attributes to ZClasses, possibly allowing them to make inappropriate
	changes to ZClass instances.

	This patch also fixes problems in the ObjectManager, PropertyManager,
	and PropertySheet classes related to mutability of method return values
	which could be perceived as a security problem.

	We *highly* recommend that any Zope site running versions of Zope up to
	and including 2.3.1 b1 have this hotfix product installed to mitigate
	these issues if the site is accessible by untrusted users who have
	through-the-web scripting privileges.
2001-03-04 10:32:18 +00:00
Neil Blakey-Milner
b67c9642d5 Upgrade to Zope 2.3.0. It requires the recent change to python15 for
the 'new' module.
2001-01-29 14:52:23 +00:00
Neil Blakey-Milner
f582bfebfa Update to Zope 2.2.5 2001-01-18 13:35:17 +00:00
Neil Blakey-Milner
586286997d Upgrade to Zope 2.2.4, with 2000-12-08, 2000-12-15a, and 2000-12-18
security hotfixes.

All Zope users are encouraged to upgrade, or apply the hotfixes
themselves.
2000-12-20 11:54:42 +00:00
Neil Blakey-Milner
3cec3e2bf5 Fix up my silly mistake of adding DIST_SUBDIR=zope at the last second
after testing.

PR:		22050
Submitted by:	Taoka Fumiyoshi <fmysh@ga2.so-net.ne.jp>
2000-10-18 01:30:53 +00:00
Neil Blakey-Milner
f5150f6ce0 Add two security hotfixes for Zope - more complex Zope internals stuff
which allows people who may edit DTML to gain higher privilege, and
those who have higher privilege in some areas of the Zope tree to gain
it in other areas.
2000-10-14 23:33:12 +00:00
Neil Blakey-Milner
fe4ae0109d Upgrade to Zope 2.2.2
Also allow zope to be installed by non-root.
2000-09-19 14:25:24 +00:00
Neil Blakey-Milner
0389061469 Update to Zope 2.2.1.
Zope shutdown bug fixed.
Reported by:	Marc Rassbach <marc@milestonerdl.com>
Reported by:	Jimmy Olgeni <olgeni@uli.it>

Zope startup bug fixed (I think).
2000-09-06 22:12:35 +00:00
Neil Blakey-Milner
8070fd61c9 Update to 2.2.1b1, since there is a minor security problem in anything
beforehand.
2000-08-15 14:09:41 +00:00
Kris Kennaway
72ab3b9610 Update to zope 2.2.0 to fix security hole.
Submitted by:	James Howard <howardjp@wam.umd.edu>
PR:		20144
2000-08-05 05:02:53 +00:00
Steve Price
795f0af920 Update to version 2.1.6.
PR:		18444
Submitted by:	Thomas Hentschel <thomas@hentschel.net>
2000-05-29 02:49:55 +00:00
Steve Price
f73c0fc047 Initial import of zope version 2.0.0b5.
An object-based web application platform with database access.

PR:		13324
Submitted by:	Peter Cornelius <pcc@gmx.net>
1999-11-01 02:40:07 +00:00