From: Luke Plant <L.Plant...@cantab.net>
Date: Fri, 25 Sep 2009 12:02:47 +0100
Local: Fri, Sep 25 2009 7:02 am
Subject: Re: Adding signing (and signed cookies) to Django core
On Thursday 24 September 2009 18:18:56 Simon Willison wrote:
> SECRET_KEY considerations Can I add some other things I've been worrying about while we're on > ========================= the topic? In other web apps (I think Wordpress?), there have been problems Suppose one part of an app signs an e-mail address for the purpose of However, suppose another part of the website allows a user to set There are many places in Django that use SECRET_KEY. I'm not So I propose: - we review all the Django code involving md5/sha1 The main difficulty is the way this could break compatibility with Luke -- Luke Plant || http://lukeplant.me.uk/ You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||