weberror: Fix CSRF validation when token is unicode

27 views
Skip to first unread message

Jan Heylen

unread,
Feb 7, 2016, 2:57:20 PM2/7/16
to pylons-devel, Mads Kiilerich, T De Schampheleire, Andrew Shadura, Mathias De Maré, Søren Løvborg
Hi,

as user of the pylons web framework, I very much like the interactive debugger, however, since some time, this is a broken feature.

However, the fix (in weberror) is very trivial and already proposed as pull request by Patrick Valsecchi on github since November last year:

I know Pylons is no longer actively maintained, but the website does still states: "The Pylons web framework 1.x line will continue to be maintained alongside Pyramid" :-)

Will this pull request be taken in and will weberror be updated in pypi? Currently, this is still a version without this fix. (https://pypi.python.org/pypi/WebError)

Thanks,

Jan Heylen




Bert JW Regeer

unread,
Feb 8, 2016, 7:11:41 PM2/8/16
to pylons...@googlegroups.com
I’ve just received push access to PyPi from Ben Bangert, will pull in that PR and get a new release out that fixes the issue in the next day or so.

Thanks,
Bert
> --
> You received this message because you are subscribed to the Google Groups "pylons-devel" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to pylons-devel...@googlegroups.com.
> To post to this group, send email to pylons...@googlegroups.com.
> Visit this group at https://groups.google.com/group/pylons-devel.
> For more options, visit https://groups.google.com/d/optout.

Jan Heylen

unread,
Feb 9, 2016, 12:50:39 AM2/9/16
to pylons...@googlegroups.com
Great, thanks!

Bert JW Regeer

unread,
Feb 9, 2016, 12:52:40 AM2/9/16
to pylons...@googlegroups.com
WebError 0.12 is out on PyPi.

Pulled in that CSRF fix :-)

Cheers,
Bert

Steve Piercy

unread,
Feb 9, 2016, 3:02:23 AM2/9/16
to pylons...@googlegroups.com
I've also merged a PR to change the wording on this page to reflect reality.
http://www.pylonsproject.org/projects/pylons-framework/about

Soon it will be deployed.

--steve


On 2/9/16 at 6:50 AM, hey...@gmail.com (Jan Heylen) pronounced:
------------------------
Steve Piercy, Soquel, CA

Jonathan Vanasco

unread,
Feb 9, 2016, 11:20:50 AM2/9/16
to pylons-devel
@Steve-

Would it make sense to just explicitly state "Pylons was put into maintenance-only status in 2012."  
Reply all
Reply to author
Forward
0 new messages