Index: openacs-4/packages/acs-tcl/tcl/apm-install-procs.tcl =================================================================== RCS file: /usr/local/cvsroot/openacs-4/packages/acs-tcl/tcl/apm-install-procs.tcl,v diff -u -N -r1.126.2.24 -r1.126.2.25 --- openacs-4/packages/acs-tcl/tcl/apm-install-procs.tcl 27 Oct 2022 10:57:57 -0000 1.126.2.24 +++ openacs-4/packages/acs-tcl/tcl/apm-install-procs.tcl 24 Nov 2022 12:44:18 -0000 1.126.2.25 @@ -1856,7 +1856,10 @@ # to /api-doc. This is probably OK, when one assumes that the # registered users are developers. However, providing source code # access to all registered users can pose a security thread, - # especially on large sites. + # especially on large sites. By deactivating the following line, + # just "Main Site Administrators" will have rights on the + # /api-doc, which is probably the right thing to do on most sites. + # With the new permissions interface, providing more liberal rights via is # if {0} { # Only registered users should have permission to access the