Commit Graph

62 Commits

Author SHA1 Message Date
Neil Blakey-Milner
0312b43bb0 Upgrade www/zope to version 2.6.2
PR:		59000
Submitted by:	Osma Suominen <ozone@sange.fi>
2003-11-21 18:11:38 +00:00
Neil Blakey-Milner
a7a67f9b3d Don't list Data.fs, as it's precious and should not be overwritten when
a package update is done.  Also, install zope.sh.sample, and copy it to
zope.sh if zope.sh doesn't already exist.
2003-08-28 18:55:15 +00:00
Neil Blakey-Milner
c212f6418b Port isn't broken, and claim maintainership. 2003-08-27 18:24:56 +00:00
Kris Kennaway
9ba21220e9 BROKEN: Does not build 2003-08-07 09:02:32 +00:00
Daichi GOTO
a03cb4094b update www/zope: allow zope to build with other python versions
PR:		54243
Submitted by:	Tim Middleton <x@vex.net>
2003-07-09 05:01:51 +00:00
Hye-Shik Chang
6083bd3d21 Change python dependency to 2.1 as the documentation recommends.
PR:		53313
Submitted by:	"Miguel Mendez" <flynn@energyhq.es.eu.org>
2003-06-16 08:59:10 +00:00
Hye-Shik Chang
62d30a76fb Upgrade to 2.6.1
PR:		52038
Submitted by:	Miguel Mendez <flynn@energyhq.es.eu.org>
2003-05-12 03:36:53 +00:00
Kris Kennaway
488b213183 BROKEN: Does not compile 2003-05-07 00:12:29 +00:00
Alan Eldridge
4616d09898 I just don't have the time to maintain this and all its issues. 2003-04-11 00:13:06 +00:00
Ade Lovett
7e52725f2a Clear moonlight beckons.
Requiem mors pacem pkg-comment,
And be calm ports tree.

E Nomini Patri, E Fili, E Spiritu Sancti.
2003-03-07 06:14:21 +00:00
Alan Eldridge
3575163451 restore python21 dependency that was lost in upgrade 2003-02-06 16:45:11 +00:00
Alan Eldridge
e741dc2b46 Updated to 2.6.0. Simon, you forgot to remove the temp files before making
the plist ;)

PR:		46168
Submitted by:	Simon 'corecode' Schubert <corecode@eikonww2.eikon.e-technik.tu-muenchen.de>
2003-01-12 17:48:19 +00:00
Alan Eldridge
df279c0135 Create the cgi-bin dir for Zope's cgi scripts if it doesn't exist, rather
than just bomb.
2002-11-03 13:17:17 +00:00
Alan Eldridge
61028157db Remove the StUdLyCaPs from maintainer name, 'cause some folks won't realize
mail's case insensitive and will try to type that. Sorry folks, purely a
cosmetic change here, nothing to see, move along, move along....
2002-11-01 13:09:32 +00:00
Alan Eldridge
7df6fabb8f Changed MAINTAINER to my FreeBSD address. 2002-11-01 04:17:51 +00:00
Alan Eldridge
76f7784982 1. Use the link /usr/local/www/cgi-bin for installing the cgi scripts.
2. Maintainer changed to ports@geeksrus.net (alane@freebsd.org) due to
   maintainer timeouts on this port.
3. PORTREVISION bumped due to change in pkg-plist and install dirs.

PR:		39687
Submitted by:	ports@geeksrus.net
Approved by:	will
2002-07-27 06:29:13 +00:00
Alan Eldridge
937d360042 1. Redirect stderr to /dev/null as well as stdout in rc.d/zope.sh, so that
boot time startup does not fail.
2. Bump PORTREVSION (not in PR).

PR:		ports/37878
Submitted by:	alane
Reviewed by:	will
Approved by:	will
2002-06-20 00:25:44 +00:00
Neil Blakey-Milner
f5dcd933c0 Upgrade to Zope 2.5.1
PR:		ports/37763
Submitted by:	HAYASHI Yasushi <yasi@yasi.to>
2002-05-08 18:50:07 +00:00
Neil Blakey-Milner
be5a1dcb66 Implement the HotFix described at
http://www.zope.org/Products/Zope/Hotfix_2002-03-01/README.txt which
says:

``The issue involves the checking of security for objects with proxy
  roles. The context of the owner user that created the object with
  proxy roles was not being taken into account when determining access
  to the object with proxy roles. This flaw could allow users defined
  in subfolders of a site with sufficient privileges to access objects
  at higher levels in the site that they would not normally be able to
  access.''

PR:		36103
Submitted by:	HAYASHI Yasushi <yasi@yasi.to>
2002-03-23 10:04:29 +00:00
Neil Blakey-Milner
d716ba9430 Add install and deinstall scripts I forgot to commit last time.
Submitted by:	HAYASHI Yasushi <yasi@yasi.to>
2002-02-08 21:25:10 +00:00
Neil Blakey-Milner
1a17adebbf Upgrade to 2.5.0 plus the security fix.
PR:		ports/34430
Submitted by:	HAYASHI Yasushi <yasi@yasi.to>
2002-02-05 20:26:09 +00:00
Akinori MUSHA
4adc5a8a71 Use ${ECHO_CMD} instead of ${ECHO} where you mean the echo command;
the ECHO macro is set to "echo" by default, but it is set to "true" if
make(1) is invoked with the -s option while ECHO_CMD is always set to
the echo command.
2002-01-29 12:08:37 +00:00
Neil Blakey-Milner
8acebe2dac Upgrade to 2.4.2 2001-10-19 21:09:35 +00:00
Neil Blakey-Milner
f213143e00 Upgrade to Zope 2.4.1. 2001-09-10 08:52:19 +00:00
Neil Blakey-Milner
434868fb60 Acqusition context checking hotfix
``The issue involves an error in the '_check_context' method of the
AccessControl.User.BasicUser class. The bug made it possible to access
Zope objects via acquisition that a user would not otherwise have access
to. This issue could allow users with enough internal knowledge of Zope
to perform actions higher in the object hierarchy than they should be
able to.''
2001-08-04 17:29:00 +00:00
Vanilla I. Shu
6b0274afa1 Upgrade to 2.4.0.
Approved by:	nbm
2001-07-25 23:32:57 +00:00
Jimmy Olgeni
45bd8c5f79 Update port to version 2.3.3.
Approved by:	nbm
2001-07-04 20:52:41 +00:00
Jimmy Olgeni
6b2aa0a1a9 Add missing @dirrm for Hotfix_2001_05_01. 2001-05-27 21:59:33 +00:00
Neil Blakey-Milner
c4f736719a Actually install the 2001-05-01 Hotfix. 2001-05-03 10:23:54 +00:00
Neil Blakey-Milner
061280635c Update to Zope 2.3.2 + Hotfix 2001-05-01 2001-05-03 10:14:53 +00:00
Neil Blakey-Milner
73744dc786 Upgrade to Zope 2.3.1! 2001-03-31 12:12:26 +00:00
Jimmy Olgeni
32bd499f1c Apply Zope hotfix: Hotfix_2001-03-08
From the Zope site:

The issue involves an error in the 'aq_inContextOf' method of objects that
support acquisition. A recent change to the access validation machinery
made this bug begin to affect security restrictions. The bug, with the
change to validation, made it possible to access Zope objects via
acquisition that a user would not otherwise have access to. This issue
could allow users with enough internal knowledge of Zope to perform actions
higher in the object hierarchy than they should be able to.
2001-03-10 12:22:15 +00:00
Jimmy Olgeni
68fda8686d More plist and Makefile fixes.
* Removed "access" from pkg-plist, it contains password data that
  should be preserved (I forgot this last time!).

* In the "do-install" target, leave the "access" file unchanged if it
  already exists.

* Remove the pre-deinstall comment: Data.fs is already preserved by
  pkg_delete anyway.

* In the "install" target, use temporary file Data.fs.preserve to avoid
  overwriting Data.fs. "make deinstall/install" can now be safely used to
  perform upgrades.

* Don't leave .o files around anymore.

Approved by:	maintainer
2001-03-08 11:55:18 +00:00
Jimmy Olgeni
8c85eb2734 Miscellaneous fixes.
* Changed the python15 dependency to USE_PYTHON=yes
* Replaced PYTHON15 with PYTHON_CMD from bsd.python.mk
* Added SAPACHE_CONFDIR, like the other Sxxx variables, to be used in the
  PLIST. APACHE_CONFDIR now depends on SAPACHE_CONFDIR
* Added APACHE_CONFDIR and WEBBASEDIR to PLIST_SUB
* Removed temporary file Zope.cgi.orig
* Removed .cvsignore from var/
* Added/removed some files to the PLIST
* Used @unexec rmdir to remove shared directories from PLIST
* Removed the line with "grep". I didn't understand how it was supposed to
  work, I guess it should have been something like "cmp -s ...", but
  Data.fs cannot be equal to Data.fs.in anyway, because Zope adds some
  things to it the first time it's started (automatically imported
  packages from filesystem).
* Removed temporary files from var/ at deinstall time (*.tmp, *.lock, *.soc,
  *.pid)
* Sometimes the inituser file did not exist at deinstall time, so I
  deleted it with @unexec. It won't be included by "make package".
* Added the Hotfix_2001-02-23 directory (@dirrm)
* Used variables from PLIST_SUB instead of www and etc/apache (@dirrm)

Approved by:		maintainer
2001-03-06 22:30:21 +00:00
Neil Blakey-Milner
5aaf8bc98b Apply a Zope hotfix, fixing a potential security problem.
From the Zope hotfix:

	This hotfix addresses and important security issue that affects Zope
	versions up to and including Zope 2.3.1 b1.

	The issue is related to ZClasses in that a user with through-the-web
	scripting capabilities on a Zope site can view and assign class
	attributes to ZClasses, possibly allowing them to make inappropriate
	changes to ZClass instances.

	This patch also fixes problems in the ObjectManager, PropertyManager,
	and PropertySheet classes related to mutability of method return values
	which could be perceived as a security problem.

	We *highly* recommend that any Zope site running versions of Zope up to
	and including 2.3.1 b1 have this hotfix product installed to mitigate
	these issues if the site is accessible by untrusted users who have
	through-the-web scripting privileges.
2001-03-04 10:32:18 +00:00
Neil Blakey-Milner
b67c9642d5 Upgrade to Zope 2.3.0. It requires the recent change to python15 for
the 'new' module.
2001-01-29 14:52:23 +00:00
Neil Blakey-Milner
f582bfebfa Update to Zope 2.2.5 2001-01-18 13:35:17 +00:00
Neil Blakey-Milner
586286997d Upgrade to Zope 2.2.4, with 2000-12-08, 2000-12-15a, and 2000-12-18
security hotfixes.

All Zope users are encouraged to upgrade, or apply the hotfixes
themselves.
2000-12-20 11:54:42 +00:00
Neil Blakey-Milner
0b7a8bcbda Add __init__.pyc's for the Hotfixes, since they seem to be created.
Since this doesn't affect any functionality for port or packages users,
I'll try avoid the PORTREVISION bump.

Noticed by:	bento
2000-11-03 23:56:16 +00:00
Neil Blakey-Milner
3cec3e2bf5 Fix up my silly mistake of adding DIST_SUBDIR=zope at the last second
after testing.

PR:		22050
Submitted by:	Taoka Fumiyoshi <fmysh@ga2.so-net.ne.jp>
2000-10-18 01:30:53 +00:00
Neil Blakey-Milner
f5150f6ce0 Add two security hotfixes for Zope - more complex Zope internals stuff
which allows people who may edit DTML to gain higher privilege, and
those who have higher privilege in some areas of the Zope tree to gain
it in other areas.
2000-10-14 23:33:12 +00:00
Neil Blakey-Milner
fe4ae0109d Upgrade to Zope 2.2.2
Also allow zope to be installed by non-root.
2000-09-19 14:25:24 +00:00
Neil Blakey-Milner
689945f93e Make Zope management work with non-SSL connections, but give an example
of how to turn it on.  Conditionalize the SSL usage on <IfDefine SSL>,
since that's been a problem.

Also make the rewrite use cgi-bin.default/Zope.cgi, but give an example
of what to change if you move it to cgi-bin/Zope.cgi.
2000-09-19 09:49:04 +00:00
Neil Blakey-Milner
ae04bbe006 Zope depends on python 1.5.2, and that is installed from lang/python15
now.
2000-09-15 14:19:36 +00:00
Neil Blakey-Milner
b4f42b6692 Remove the zope data file if it is the same as installed. 2000-09-07 11:48:56 +00:00
Neil Blakey-Milner
a0ec029ac0 Fix numerous bugs in my upgrading to 2.2.1.
It may even work out the box now.
2000-09-07 11:04:44 +00:00
Neil Blakey-Milner
0389061469 Update to Zope 2.2.1.
Zope shutdown bug fixed.
Reported by:	Marc Rassbach <marc@milestonerdl.com>
Reported by:	Jimmy Olgeni <olgeni@uli.it>

Zope startup bug fixed (I think).
2000-09-06 22:12:35 +00:00
Neil Blakey-Milner
8070fd61c9 Update to 2.2.1b1, since there is a minor security problem in anything
beforehand.
2000-08-15 14:09:41 +00:00
Neil Blakey-Milner
f1bd7a1c08 Take over maintainership from Thomas for a while.
Approved by:	thomas@hentschel.net (previous maintainer)
2000-08-08 20:01:47 +00:00
Neil Blakey-Milner
556f521955 Fix a type in the installation target
PR:		ports/20486
Submitted by:	thomas@hentschel.net
2000-08-08 18:10:52 +00:00