pkgsrc/security/py-mohawk/distinfo
adam 0bf4be5a6f py-mohawk: updated to 1.0.0
1.0.0:
Security related: Bewit MACs were not compared in constant time and were thus possibly circumventable by an attacker.
Breaking change: Escape characters in header values (such as a back slash) are no longer allowed, potentially breaking clients that depended on this behavior. See https://github.com/kumar303/mohawk/issues/34
A sender is allowed to omit the content hash as long as their request has no content. The mohawk.Receiver will skip the content hash check in this situation, regardless of the value of accept_untrusted_content. See Empty requests for more details.
Introduced max limit of 4096 characters in the Authorization header
Changed default values of content and content_type arguments to mohawk.base.EmptyValue in order to differentiate between misconfiguration and cases where these arguments are explicitly given as None (as with some web frameworks). See Skipping content checks for more details.
Failing to pass content and content_type arguments to mohawk.Receiver or mohawk.Sender.accept_response() without specifying accept_untrusted_content=True will now raise mohawk.exc.MissingContent instead of ValueError.
2019-01-17 13:22:00 +00:00

6 lines
399 B
Text

$NetBSD: distinfo,v 1.2 2019/01/17 13:22:00 adam Exp $
SHA1 (mohawk-1.0.0.tar.gz) = 31969339d4debbace957dd8a1e62c91fc1c319d7
RMD160 (mohawk-1.0.0.tar.gz) = d9a7d4528668a10d5f7092378bf9443a849b756d
SHA512 (mohawk-1.0.0.tar.gz) = 5bd360f26276181b1384d62e0929b2dc52e9cce39bf9293e85eef94bfc70b91954bc8ac1eb869fb7a8073cec17daf66c67e4c4af726c9f231792f2cb2f0bc7ac
Size (mohawk-1.0.0.tar.gz) = 17593 bytes