| Age | Commit message (Collapse) | Author | |
|---|---|---|---|
| 2013-11-07 | tests for custom query strings | Michael Merickel | |
| 2013-11-07 | support encoding arbitrary query strings | Michael Merickel | |
| 2013-11-07 | support query string and anchor on external static urls | Michael Merickel | |
| 2013-11-07 | document add_adapter | Michael Merickel | |
| 2013-10-30 | indicate default | Chris McDonough | |
| 2013-10-30 | indicate default | Chris McDonough | |
| 2013-10-30 | rendering | Chris McDonough | |
| 2013-10-30 | fix failing test (unrelated to security stuff) | Chris McDonough | |
| 2013-10-30 | new api | Chris McDonough | |
| 2013-10-30 | convert remember/forget to request-method-based | Chris McDonough | |
| 2013-10-30 | note deprecation | Chris McDonough | |
| 2013-10-30 | not methods, attrs | Chris McDonough | |
| 2013-10-30 | wording | Chris McDonough | |
| 2013-10-30 | rendering | Chris McDonough | |
| 2013-10-30 | fix wiki2 tutorial wrt request-method security APIs | Chris McDonough | |
| 2013-10-30 | copy forward views.py changes to tests step | Chris McDonough | |
| 2013-10-30 | fix zodb tutorial wrt request-based authentication and authorization apis | Chris McDonough | |
| 2013-10-28 | wording and specify return value | Chris McDonough | |
| 2013-10-28 | add NB notes about recursive add_response_callback policies, use req instead ↵ | Chris McDonough | |
| of self for normalization with exception getting | |||
| 2013-10-28 | avoid a deprecation warning during test runs | Chris McDonough | |
| 2013-10-28 | defer looking up headers until the response callback is called (FBO things ↵ | Chris McDonough | |
| like sessionauthenticationpolicy which does its own header-setting when its remember/forget methods are called) | |||
| 2013-10-28 | add on_exception flag to remember/forget, fix a bug in _remember_userid and ↵ | Chris McDonough | |
| _forget_userid (these should always return a sequence even if there is no authentication policy), defactorize tests | |||
| 2013-10-28 | Bring change log, API docs, and deprecations in line with normal ↵ | Chris McDonough | |
| policies/processes | |||
| 2013-10-28 | Merge branch 'security-apis-on-request' of github.com:mgrbyte/pyramid into ↵ | Chris McDonough | |
| mgrbyte-security-apis-on-request | |||
| 2013-10-28 | Merge branch 'master' of github.com:Pylons/pyramid | Chris McDonough | |
| 2013-10-27 | Security APIs on pyramid.request.Request | Matt Russell | |
| The pyramid.security Authorization API function has_permission is made available on the request. The pyramid.security Authentication API functions are now available as properties (unauthenticated_userid, authenticated_userid, effective_principals) and methods (remember_userid, forget_userid) on pyramid.request.Request. Backwards compatibility: For each of the APIs moved to request method or property, the original API in the pyramid.security module proxies to the request. Reworked tests to check module level b/c wrappers call through to mixins for each API. Tests that check no reg on request now do the right thing. Use a response callback to set the request headers for forget_userid and remember_userid. Update docs. Attempt to improve a documentation section referencing the pyramid.security.has_permission function in docs/narr/resources.rst Ensures backwards compatiblity for `pyramid.security.forget` and `pyramid.security.remember`. | |||
| 2013-10-26 | Merge pull request #1177 from bertjwregeer/fix/signed_serialize_deserialize | Michael Merickel | |
| digestmod() has to accept a parameter in certain cases | |||
| 2013-10-26 | Bring coverage back to 100% | Bert JW Regeer | |
| 2013-10-26 | digestmod() has to accept a parameter in certain cases | Bert JW Regeer | |
| Due to line 69 in hmac.py in the Python standard library (2.7) it expects to be able to call the digestmod function with the current key if the key passed in exceeds the block size in length. This fixes the code so that digestmod can accept string as an extra parameter, which is passed through to hashlib.new() [1]: http://hg.python.org/cpython/file/2.7/Lib/hmac.py#l69 | |||
| 2013-10-23 | Merge branch 'fix.view-defaults-on-notfound-and-forbidden-views' | Chris McDonough | |
| 2013-10-22 | update changelog | Michael Merickel | |
| 2013-10-20 | notfound and forbidden decorators were ignoring view_defaults | Michael Merickel | |
| This could be fixed in other ways but the basic problem is that because config.add_notfound_view and config.add_forbidden_view have actual signatures instead of *args, **kwargs, the arguments are squashing the view_defaults which are applied later on the call to config.add_view. Basically, by the time the args get to config.add_view, they look explicit when they are not. fix #1173 | |||
| 2013-10-20 | Merge branch 'fix.renderer-interfaces' | Chris McDonough | |
| 2013-10-20 | fix merge conflict and prevent warning from showing up during testing (dont ↵ | Chris McDonough | |
| import ITemplateRenderer) | |||
| 2013-10-20 | add a note so we can defend the choice later | Chris McDonough | |
| 2013-10-20 | Merge branch 'fix.basic-authentication-encodings' | Chris McDonough | |
| 2013-10-20 | Merge branch 'master' into fix.basic-authentication-encodings | Chris McDonough | |
| 2013-10-20 | Merge branch 'feature.bad-csrf-token-exception' | Chris McDonough | |
| 2013-10-20 | fix merge conflict | Chris McDonough | |
| 2013-10-20 | Merge branch 'feature.signed-cookie-session' | Chris McDonough | |
| 2013-10-20 | rewording about deprecation and cookie compatibility | Chris McDonough | |
| 2013-10-19 | remove unnecessary length check, slices are magic | Michael Merickel | |
| 2013-10-19 | moar typos | Michael Merickel | |
| 2013-10-19 | remove redundant "see" | Michael Merickel | |
| 2013-10-19 | mon | Chris McDonough | |
| 2013-10-19 | add admonishment against secret sharing | Chris McDonough | |
| 2013-10-19 | use zope.deprecation for warning about the ↵ | Chris McDonough | |
| UnencryptedCookieSessionFactoryConfig deprecation (it will happen at import time, rather than usage time, which is good for tests); add a few sphinx directives for deprecated and versionadded | |||
| 2013-10-19 | link to the public renderer interfaces | Michael Merickel | |
| 2013-10-19 | modify the docs for the renderer interfaces | Michael Merickel | |
| 2013-10-19 | fix tests on py3 | Michael Merickel | |
