summaryrefslogtreecommitdiff
path: root/repoze
diff options
context:
space:
mode:
authorChris McDonough <chrism@agendaless.com>2008-11-01 19:26:08 +0000
committerChris McDonough <chrism@agendaless.com>2008-11-01 19:26:08 +0000
commit65e110304147fa4c19d9c6cc29e0f289e1465b4b (patch)
tree354e0972c49e364a4e606a64558e3ea22056a8d3 /repoze
parent4af9009e1765ea413465d477060b3d82f470562f (diff)
downloadpyramid-65e110304147fa4c19d9c6cc29e0f289e1465b4b.tar.gz
pyramid-65e110304147fa4c19d9c6cc29e0f289e1465b4b.tar.bz2
pyramid-65e110304147fa4c19d9c6cc29e0f289e1465b4b.zip
- Change default paster template generator to use ``Paste#http``
server rather than ``PasteScript#cherrpy`` server. The cherrypy server has a security risk in it when ``REMOTE_USER`` is trusted by the downstream application.
Diffstat (limited to 'repoze')
-rw-r--r--repoze/bfg/paster_template/+project+.ini_tmpl3
1 files changed, 1 insertions, 2 deletions
diff --git a/repoze/bfg/paster_template/+project+.ini_tmpl b/repoze/bfg/paster_template/+project+.ini_tmpl
index 2d6c4d0a2..311a2514a 100644
--- a/repoze/bfg/paster_template/+project+.ini_tmpl
+++ b/repoze/bfg/paster_template/+project+.ini_tmpl
@@ -6,7 +6,6 @@ use = egg:{{project}}#app
reload_templates = true
[server:main]
-use = egg:PasteScript#cherrypy
+use = egg:Paste#http
host = 0.0.0.0
port = 6543
-numthreads = 4