diff options
| author | cce <devnull@localhost> | 2005-12-17 17:17:56 +0000 |
|---|---|---|
| committer | cce <devnull@localhost> | 2005-12-17 17:17:56 +0000 |
| commit | c3133de6522c02cb538ce9100ac5e20aaea7f02e (patch) | |
| tree | e111b62a574f6b9d1b3653b5cdc479bb61f5eefa /paste | |
| parent | 7ed47ed3d30ecba9bd77d5534ae7d7b5d076b307 (diff) | |
| download | paste-c3133de6522c02cb538ce9100ac5e20aaea7f02e.tar.gz | |
- removed super() usage in httpserver and just copied the code
- replaced plain sha with hmac in cookie.py
Diffstat (limited to 'paste')
| -rw-r--r-- | paste/auth/cookie.py | 8 | ||||
| -rwxr-xr-x | paste/util/httpserver.py | 3 |
2 files changed, 6 insertions, 5 deletions
diff --git a/paste/auth/cookie.py b/paste/auth/cookie.py index 3dcbd09..9661077 100644 --- a/paste/auth/cookie.py +++ b/paste/auth/cookie.py @@ -22,13 +22,13 @@ should allow each domain at least 20 cookies; each one with a content size of at least 4k (4096 bytes). This is rather small; so one should be parsimonious in your cookie name/sizes. """ -import sha, base64, random, time, string, warnings +import sha, hmac, base64, random, time, string, warnings from paste.request import get_cookies def make_time(value): """ return a human readable timestmp """ return time.strftime("%Y%m%d%H%M",time.gmtime(value)) -_signature_size = len(sha.sha("").digest()) +_signature_size = len(hmac.new('x','x',sha).digest()) _header_size = _signature_size + len(make_time(time.time())) # build encode/decode functions to safely pack away values @@ -72,7 +72,7 @@ class CookieSigner: cookie is handled server-side in the auth() function. """ cookie = base64.b64encode( - sha.sha(content+self.secret).digest() + + hmac.new(self.secret,content,sha).digest() + make_time(time.time()+60*self.timeout) + content).replace("/","_").replace("=","~") if len(cookie) > self.maxlen: @@ -89,7 +89,7 @@ class CookieSigner: signature = decode[:_signature_size] expires = decode[_signature_size:_header_size] content = decode[_header_size:] - if signature == sha.sha(content+self.secret).digest(): + if signature == hmac.new(self.secret,content,sha).digest(): if int(expires) > int(make_time(time.time())): return content else: diff --git a/paste/util/httpserver.py b/paste/util/httpserver.py index 8d05270..969356a 100755 --- a/paste/util/httpserver.py +++ b/paste/util/httpserver.py @@ -34,7 +34,8 @@ class WSGIHandlerMixin: """ behavior that BaseHTTPServer should have had """ if not self.sys_version: return self.server_version - return super(WSGIHandlerMixin,self).version_string(self) + else: + return self.server_version + ' ' + self.sys_version def wsgi_write_chunk(self, chunk): """ |
