pkgsrc/www/py-tornado
wiz 6eed0e8ce3 Update to 3.2.2:
Security fixes
~~~~~~~~~~~~~~

* The XSRF token is now encoded with a random mask on each request.
  This makes it safe to include in compressed pages without being
  vulnerable to the `BREACH attack <http://breachattack.com>`_.
  This applies to most applications that use both the ``xsrf_cookies``
  and ``gzip`` options (or have gzip applied by a proxy).

Backwards-compatibility notes
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

* If Tornado 3.2.2 is run at the same time as older versions on the same
  domain, there is some potential for issues with the differing cookie
  versions.  The `.Application` setting ``xsrf_cookie_version=1`` can
  be used for a transitional period to generate the older cookie format
  on newer servers.

Other changes
~~~~~~~~~~~~~

* ``tornado.platform.asyncio`` is now compatible with ``trollius`` version 0.3.
2014-06-09 12:33:43 +00:00
..
DESCR
distinfo Update to 3.2.2: 2014-06-09 12:33:43 +00:00
Makefile Update to 3.2.2: 2014-06-09 12:33:43 +00:00
PLIST Update to 3.2. 2014-01-27 19:58:33 +00:00