From: Christoph Z. <ci...@on...> - 2004-01-27 17:50:18
|
Hi Ian, > I think the reason (if there was one) for not including .pyc and .pyo > files is that it could be seen as a potential security hole, in that > removing the .py file would not be sufficient to delete the servlet if > the .pyc file had been created. By default, they are excluded in Application.config anyway. However, if you forget to exclude them, then you will have an even more severe security hole, since the content of the files will be delivered to the web browser, including private information like database passwords or something (they are treated as UnknownFileTypeServlets currently, which does not make much sense to me). > Though part of it was probably also the lack of cascading extensions As you wrote, this is not an argument any more. Anyway, I just want to say thank you for providing Webware in the first place. I really like it and appreciate the efforts of you and whoever might have added contributions. I just hope the project will be continued and one day we will see a 1.0 release ;-) Christoph |