summaryrefslogtreecommitdiff
path: root/docs/quick_tutorial/authentication/tutorial
AgeCommit message (Collapse)Author
2024-06-09docs: remove 'came_from' from login viewTres Seaver
- The narrative doesn't discuss this (mis-)feature. - Without any authorization, there is no meaninful reason to remember the 'previous' page. - As a general rule, we want to avoid trusting user-supplied data (i.e., from the query string or form params) when constructing redirect URLs.
2020-10-13Rename `ISecurityPolicy.authenticated_identity` to `identity`Theron Luhn
2019-12-31change hashalg on AuthTktCookieHelper to sha512.Michael Merickel
2019-12-30rename identify(request) to authenticated_identity(request)Michael Merickel
2019-12-29update authentication and authorization chapters of the quick_tutorial to ↵Michael Merickel
use the new ISecurityPolicy
2017-11-03views.py: prevent exception on unknown user loginsilum
Attempting authentication without specifying a login, or when the login is not known, causes an unhandled exception to be raised in `security.py` because `None` is passed to `check_password()` as the hashed password to check against.
2016-07-21Add one-way password hash to security example in Quick Tutorial.Keith Yang
2015-05-23correct title tag; punctuationSteve Piercy
2013-11-09undeprecate remember/forget functions and remove ↵Chris McDonough
remember_userid/forget_userid methods from request
2013-10-30convert remember/forget to request-method-basedChris McDonough
2013-09-25Get pyramid_chameleon added to the quick tutorial, plus some other fixes for ↵Paul Everitt
Python 3.
2013-09-13First cut at import of quick tutorial.Paul Everitt