summaryrefslogtreecommitdiff
path: root/CHANGES.rst
diff options
context:
space:
mode:
authorMichael Merickel <michael@merickel.org>2024-01-28 23:36:46 -0700
committerMichael Merickel <michael@merickel.org>2024-01-28 23:36:46 -0700
commitb2457bba372aead8d66444c233e4d0c48be191a2 (patch)
tree0c6407fdca19e3387382b132b0d7ad43b4984234 /CHANGES.rst
parentef8b250d20a4223fb7ae2af7cbc9b320da150ecc (diff)
downloadpyramid-b2457bba372aead8d66444c233e4d0c48be191a2.tar.gz
pyramid-b2457bba372aead8d66444c233e4d0c48be191a2.tar.bz2
pyramid-b2457bba372aead8d66444c233e4d0c48be191a2.zip
remove changes from changelog that have been released in 2.0.x
Diffstat (limited to 'CHANGES.rst')
-rw-r--r--CHANGES.rst16
1 files changed, 1 insertions, 15 deletions
diff --git a/CHANGES.rst b/CHANGES.rst
index 480ebe83c..c05bc66fa 100644
--- a/CHANGES.rst
+++ b/CHANGES.rst
@@ -4,7 +4,7 @@ unreleased
Features
--------
-- Add support for Python 3.11 and 3.12.
+- Add support for Python 3.12.
- Added HTTP 418 error code via `pyramid.httpexceptions.HTTPImATeapot`.
See https://github.com/Pylons/pyramid/pull/3667
@@ -31,17 +31,6 @@ Features
Bug Fixes
---------
-- Removed support for null-bytes in the path when making a request for a file
- against a static_view. Whille null-bytes are allowed by the HTTP
- specification, due to the handling of null-bytes potentially leading to
- security vulnerabilities it is no longer supported.
-
- This fixes a security vulnerability that is present due to a bug in Python
- 3.11.0 through 3.11.4, thereby allowing the unintended disclosure of an
- ``index.html`` one directory up from the static views path.
-
- Thanks to Masashi Yamane of LAC Co., Ltd for reporting this issue.
-
- Fix issues where permissions may be checked on exception views. This is not
supposed to happen in normal circumstances.
@@ -62,9 +51,6 @@ Backward Incompatibilities
- Drop support for Python 3.6 and 3.7.
-- Requests to a static_view are no longer allowed to contain a null-byte in any
- part of the path segment.
-
- Drop support for l*gettext() methods in the i18n module.
These have been deprecated in Python's gettext module since 3.8, and
removed in Python 3.11.