It has occurred to me that some users use the grid for logged in users and 
set user_signature=False.
I cannot stress this enough. This is a major security issue. 
user_signature=True by default for a reason.

If you set user_signature=False any logged in user accessing any grid will 
be able to view, create and delated records in ANY table.



-- 

--- 
You received this message because you are subscribed to the Google Groups 
"web2py-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to web2py+unsubscr...@googlegroups.com.
For more options, visit https://groups.google.com/groups/opt_out.


Reply via email to