…mplates Rationale: Mako template renderers can be specified using an absolute asset spec. An entire application can be written with such asset specs, requiring no ordered lookup path.
Avoid timing attacks in AuthTktAutenticationPolicy
This factors out the timing-invariant string comparison code from session.py and re-uses it for signature checking in AuthTkt code.
fix static_url docstring about absolute path
since pyramid 1.2, the path can be absolute and no ValueError is raised anymore (see commit b8c7977 )
fix typo in docstring: s/current_static_url/static_url/
Edited docs/narr/urldispatch.rst via GitHub
This was resulting in unicode cookie values (and thus headers) on Python 2 causing mod_wsgi to complain: TypeError: expected string object for header value PEP 3333 also says: "Native" strings (which are always implemented using the type named str) that are used for request/response headers and metadata So mod_wsgi is right to complain about unicode headers and Pyramid is wrong to send them.