[Mailman-Developers] small sec problem / or feuture (?)

Barry A. Warsaw bwarsaw@cnri.reston.va.us (Barry A. Warsaw)
Fri, 18 Dec 1998 23:38:44 -0500 (EST)


>>>>> "BB" == Bencsath Boldizsar <boldi@budapest.hu> writes:

    BB> Hi, I am not list member, but didn't find any bugreport
    BB> address in the docs of mailman ( please make one.. :) )

mailman-developers@python.org is fine.  I've added a note to the BUGS
file.
    
    BB> So, in 1.0b6 there is a small problem: Pendig messages can be
    BB> seen by anyone / i didn't checked the privacy options, but
    BB> it's more logical, that pending messages are only viewable by
    BB> the admin through the password.  check
    BB> http://www.anything.something/mailman/admindb/<listname> boldi

Good point.  I think doing the admin authentication upfront is better
for dealing with pending messages too.  I've got this working and will 
check it in for the next release.

Thanks,
-Barry