| Age | Commit message (Collapse) | Author | |
|---|---|---|---|
| 2016-04-24 | add sphinx doctests for hooks.rst | Steve Piercy | |
| 2016-04-24 | Allow Sphinx doctests to run and pass with `make doctest ↵ | Steve Piercy | |
| SPHINXBUILD=$VENV/bin/sphinx-build`. - TODO: two tests in `docs/narr/hooks.rst` | |||
| 2016-04-24 | update bad link | Steve Piercy | |
| 2016-04-23 | Fix all the stinky linkie rot via `make linkcheck ↵ | Steve Piercy | |
| SPHINXBUILD=$VENV/bin/sphinx-build`, but don't bother with HISTORY.txt or whatsnew-xx | |||
| 2016-04-19 | replace pyramid.require_default_csrf setting with ↵ | Michael Merickel | |
| config.set_default_csrf_options | |||
| 2016-04-17 | better explain view deriver options | Chris McDonough | |
| 2016-04-16 | Merge pull request #2507 from stevepiercy/master | Steve Piercy | |
| replace ps1con with doscon for lexer and syntax highlighting | |||
| 2016-04-16 | In addition to CSRF token, verify the origin too | Donald Stufft | |
| Add an additional layer of protection against CSRF by verifying the actual origin of the request in addition to the CSRF token. We only do this check on sites hosted behind HTTPS because only HTTPS sites have evidence to show that the Referrer header is not being spuriously removed by random middleware boxes. | |||
| 2016-04-15 | Have Automatic CSRF on all unsafe HTTP methods | Donald Stufft | |
| Instead of only protecting against unsafe POST requests, have the automatic CSRF protect on all methods which are not defined as "safe" by RFC2616. | |||
| 2016-04-15 | Only Accept CSRF Tokens in headers or POST bodies | Donald Stufft | |
| Previously `check_csrf_token` would allow passing in a CSRF token in through a the URL of a request. However this is a security issue because a CSRF token must not be allowed to leak, and URLs regularly get copy/pasted or otherwise end up leaking to the outside world. | |||
| 2016-04-12 | Merge branch 'master' into feature/require-csrf | Michael Merickel | |
| 2016-04-12 | Merge branch 'master' into feature/BeforeTraversal | Bert JW Regeer | |
| 2016-04-12 | Remove note about -Wd flag | Bert JW Regeer | |
| Since we no longer support Python 2.6, it becomes a requirement for all our supported Python versions, and thus the note is no longer required. | |||
| 2016-04-12 | Update introduction to testing | Bert JW Regeer | |
| It mentions that we use Jenkins, but our Travis is more open, and used for all commits, so add a reference to Travis as well. Also, remove Python 2.6 reference here. | |||
| 2016-04-12 | Replace Python 2.6 with 2.7 | Bert JW Regeer | |
| 2016-04-12 | - zap easy_install straggler | Steve Piercy | |
| 2016-04-12 | one does not simply "create a virtualenv". one should "create a virtual ↵ | Steve Piercy | |
| environment". - Fixes #2483 | |||
| 2016-04-12 | update testing.rst | Steve Piercy | |
| - replace nose with py.test - use pip - use literalinclude of MyProject/setup.py instead of copy-pasta | |||
| 2016-04-12 | - use an environment variable and venv. See ↵ | Steve Piercy | |
| https://github.com/Pylons/pyramid/pull/2468#discussion_r59311019 - rename stanza from `testing_extras` to `tests_require` - switch from nose to pytest | |||
| 2016-04-12 | - replace `python -m` with `python3 -m` | Steve Piercy | |
| 2016-04-12 | - replace `pyvenv` with `python3 -m venv` | Steve Piercy | |
| 2016-04-12 | - removed "now" per ↵ | Steve Piercy | |
| https://github.com/Pylons/pyramid/pull/2468#discussion_r59310317 | |||
| 2016-04-12 | - fix readme in narr/MyProject (used in project.rst and testing.rst) | Steve Piercy | |
| 2016-04-11 | Merge branch 'master' into docs/easy-install-to-pip.2104 | Michael Merickel | |
| 2016-04-11 | remove theme.min.css, it serves no purpose | Michael Merickel | |
| 2016-04-11 | - upgrade `BeforeTraversal` event in router.rst | Steve Piercy | |
| 2016-04-11 | - add trailing line ending | Steve Piercy | |
| 2016-04-11 | - update narr/project.rst to use pip instead of setup.py | Steve Piercy | |
| - update starter scaffold tests and setup.py (used in `narr/project.rst` and `narr/testing.rst`) - update links to documentation | |||
| 2016-04-10 | Update router documentation | Bert JW Regeer | |
| 2016-04-10 | cleanup some references in the docs | Michael Merickel | |
| 2016-04-10 | deprecate the check_csrf predicate | Michael Merickel | |
| 2016-04-10 | rewrite csrf checks to support a global setting to turn it on | Michael Merickel | |
| - only check csrf on POST - support "pyramid.require_default_csrf" setting - support "require_csrf=True" to fallback to the global setting to determine the token name | |||
| 2016-04-10 | add a csrf_view to the view pipeline supporting a require_csrf option | Michael Merickel | |
| 2016-04-10 | - update installation.rst to use pip, pyvenv, Python 3.4 | Steve Piercy | |
| - simplify installation.rst by removing not-Pyramid things (installing Python and requirements for installing packages) while providing official external references - update cross-reference in quick_tutorial requirements.rst - add glossary entry for pyvenv | |||
| 2016-04-10 | Merge pull request #2021 from Pylons/feature/configurable-view-deriver | Michael Merickel | |
| configurable view deriver | |||
| 2016-04-10 | - update extending.rst to use pip | Steve Piercy | |
| 2016-04-10 | - update commandline.rst to use pip | Steve Piercy | |
| 2016-04-08 | Add pyramid_jinja2 example to i18n docs. Fixes #2437. | Steve Piercy | |
| 2016-04-08 | update constraints for derivers as well as docs | Michael Merickel | |
| 2016-04-07 | separate the viewderiver module and allow overriding the mapper | Michael Merickel | |
| 2016-04-03 | - replace easy_install with pip | Steve Piercy | |
| - bump Python version to 3.5 or generalize to Python 3 - rewrite seealso's - use ps1con lexer for windows powershell console - add hyperlink targets | |||
| 2016-03-21 | polish view derivers docs, minor grammar | Steve Piercy | |
| 2016-03-17 | fix deriver docs to explain ordering issues | Michael Merickel | |
| 2016-03-14 | add a docstring for add_view_deriver and expose the method to the api docs | Michael Merickel | |
| 2016-03-14 | do not guess at the name of the view deriver without further discussion | Michael Merickel | |
| 2016-03-14 | use the implicit name in the doc examples | Michael Merickel | |
| 2016-03-14 | first cut at documenting view derivers | Michael Merickel | |
| 2016-03-14 | polish Invoking an Exception View docs | Steve Piercy | |
| - add index entry - minor grammar, syntax | |||
| 2016-03-14 | move comment closer to relevant logic | Michael Merickel | |
| 2016-03-14 | fix broken ref | Michael Merickel | |
