.hgignore
author Laurent Peuch <cortex@worlddomination.be>
Fri, 12 Apr 2019 12:31:14 +0200
changeset 12584 6eba53763482
parent 12371 923f9c9f56c5
permissions -rw-r--r--
Use secure hash algorithm in WebConfiguration.sign_text Fix: PendingDeprecationWarning: HMAC() without an explicit digestmod argument is deprecated. The default hash algorithm used by hmac.new is md5. As of today, md5 is so weak that it's the equivalent of plaintext and can't be considered to be secured at all. Therefor, we switch to a secure hash algorithm. The rational for choosing sha3_512 is: * the recommended algorithm is at least sha_256 * the stronger, the more secured and sha3_512 is the stronger available * thinking about the future this should keep this part of the code safe long enough before people think about checking it again You can read more about choosing a secure hash algorithm in the NIST recommendations https://csrc.nist.gov/Projects/Hash-Functions/NIST-Policy-on-Hash-Functions This code modification should normally be transparent since check_text_sign is exactly this code 'self.sign_text(text) == signature' and that sign_text is only used in combination with it. The only impact is that the hash is going to move from 32 char to 128 which might make html page a bit bigger and that sha3_512 is slow to compute (which is a good thing for security)
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
3116
8bf500eb01d6 two convenience files
Aurélien Campéas
parents:
diff changeset
     1
^build$
8bf500eb01d6 two convenience files
Aurélien Campéas
parents:
diff changeset
     2
^dist$
10512
99bdd4bddd77 Add tox.ini file
Denis Laxalde <denis.laxalde@logilab.fr>
parents: 10491
diff changeset
     3
\.egg-info$
99bdd4bddd77 Add tox.ini file
Denis Laxalde <denis.laxalde@logilab.fr>
parents: 10491
diff changeset
     4
^.tox$
11272
53fbd5644bff Let hg Ignore py.test's .cache directory
Denis Laxalde <denis.laxalde@logilab.fr>
parents: 11029
diff changeset
     5
^.cache$
3116
8bf500eb01d6 two convenience files
Aurélien Campéas
parents:
diff changeset
     6
\.pyc$
8bf500eb01d6 two convenience files
Aurélien Campéas
parents:
diff changeset
     7
\.pyo$
8bf500eb01d6 two convenience files
Aurélien Campéas
parents:
diff changeset
     8
\.bak$
8bf500eb01d6 two convenience files
Aurélien Campéas
parents:
diff changeset
     9
\.old$
8bf500eb01d6 two convenience files
Aurélien Campéas
parents:
diff changeset
    10
\~$
8bf500eb01d6 two convenience files
Aurélien Campéas
parents:
diff changeset
    11
\#.*?\#$
8bf500eb01d6 two convenience files
Aurélien Campéas
parents:
diff changeset
    12
\.swp$
3990
14e14fef4460 hide en apidoc in .hgignore
Pierre-Yves David <pierre-yves.david@logilab.fr>
parents: 3116
diff changeset
    13
^doc/book/en/apidoc$
7078
bad26a22fe29 [test] New Handling of database for test.
Aurelien Campeas <aurelien.campeas@logilab.fr>
parents: 3990
diff changeset
    14
\.old$
11829
17078e20088f add debian buildpackage-generated files to hgignore
David Douard <david.douard@logilab.fr>
parents: 11475
diff changeset
    15
\.pybuild
12122
92aef8c6e7c8 [hg] Add generated slapd.conf to hgignore
Sylvain Thénault <sylvain.thenault@logilab.fr>
parents: 11829
diff changeset
    16
cubicweb/server/test/data/slapd.conf
11829
17078e20088f add debian buildpackage-generated files to hgignore
David Douard <david.douard@logilab.fr>
parents: 11475
diff changeset
    17
debian/python-cubicweb
17078e20088f add debian buildpackage-generated files to hgignore
David Douard <david.douard@logilab.fr>
parents: 11475
diff changeset
    18
debian/*.log
17078e20088f add debian buildpackage-generated files to hgignore
David Douard <david.douard@logilab.fr>
parents: 11475
diff changeset
    19
debian/*.substvars
17078e20088f add debian buildpackage-generated files to hgignore
David Douard <david.douard@logilab.fr>
parents: 11475
diff changeset
    20
debian/cubicweb-doc
17078e20088f add debian buildpackage-generated files to hgignore
David Douard <david.douard@logilab.fr>
parents: 11475
diff changeset
    21
debian/cubicweb
17078e20088f add debian buildpackage-generated files to hgignore
David Douard <david.douard@logilab.fr>
parents: 11475
diff changeset
    22
debian/files
17078e20088f add debian buildpackage-generated files to hgignore
David Douard <david.douard@logilab.fr>
parents: 11475
diff changeset
    23
7078
bad26a22fe29 [test] New Handling of database for test.
Aurelien Campeas <aurelien.campeas@logilab.fr>
parents: 3990
diff changeset
    24
syntax: regexp
11029
c9d12d1d3081 [testlib] put postgres test database in test/data/database directory
Sylvain Thénault <sylvain.thenault@logilab.fr>
parents: 10524
diff changeset
    25
.*/data.*/database/.*
8252
3e769d21f67a [hg] ignore ldap database
Sylvain Thénault <sylvain.thenault@logilab.fr>
parents: 7972
diff changeset
    26
.*/data/ldapdb/.*
10524
5392f100c0e3 Update hgignore
Rémi Cardona <remi.cardona@logilab.fr>
parents: 10512
diff changeset
    27
.*/data/uicache/
11460
5be729810695 [devtools] Handle i18ncube command for "cubes as packages"
Denis Laxalde <denis.laxalde@logilab.fr>
parents: 11272
diff changeset
    28
.*/data/libpython/cubicweb_.*/i18n/.*\.po
7972
99210c8b63b0 Add generated documentation to .hgignore.
Pierre-Yves David <pierre-yves.david@logilab.fr>
parents: 7078
diff changeset
    29
^doc/html/
99210c8b63b0 Add generated documentation to .hgignore.
Pierre-Yves David <pierre-yves.david@logilab.fr>
parents: 7078
diff changeset
    30
^doc/doctrees/
99210c8b63b0 Add generated documentation to .hgignore.
Pierre-Yves David <pierre-yves.david@logilab.fr>
parents: 7078
diff changeset
    31
^doc/book/en/devweb/js_api/
10491
c67bcee93248 [doc] Restructure the documentation
Christophe de Vienne <christophe@unlish.com>
parents: 10466
diff changeset
    32
^doc/_build
c67bcee93248 [doc] Restructure the documentation
Christophe de Vienne <christophe@unlish.com>
parents: 10466
diff changeset
    33
^doc/js_api/
11475
d2fcd81b7ca9 [tox] Add a dummy test-results.xml file in check-manifest and flake8 environments
Denis Laxalde <denis.laxalde@logilab.fr>
parents: 11460
diff changeset
    34
test-results.xml
12371
923f9c9f56c5 [pyramid] improve pyramid warning with link to doc on how to write pyramid.ini file
Laurent Peuch <cortex@worlddomination.be>
parents: 12122
diff changeset
    35
ve