[Cosmo-dev] JSON-RPC considered harmful

Randy Letness randy at osafoundation.org
Tue Dec 5 22:50:50 PST 2006


Bobby Rullo wrote:
> That's not a problem with RPC now. Calendar paths are always resolved 
> relative to the current logged in user, so you can't specify a 
> collection that's outside your space - unless you can do something 
> like "../bcm/stuff" which I think we took care of already.       
> On Dec 5, 2006, at 10:27 PM, Brian Moseley wrote:
>

But isn't the path sent as part of the rpc request body?  So you could 
specify another users calendar right? 

-Randy


More information about the cosmo-dev mailing list