Permalink
Commits on Mar 16, 2017
  1. Merge pull request #80 from davidism/sha2

    change default intermediate hash from SHA-1 to SHA-512
    davidism committed on GitHub Mar 16, 2017
  2. change default intermediate hash from SHA-1 to SHA-512

    Note that HMAC is still secure even with MD5. This is mostly a change
    for aesthetics so people will stop asking, although it doesn't hurt to
    be preemtive in this case.
    
    Skipping SHA-256 for SHA-512 since it's more efficient on 64-bit.
    
    See https://mail.python.org/pipermail/cryptography-dev/2017-March/000737.html for discussion.
    davidism committed Mar 16, 2017
Commits on Jan 6, 2017
  1. HTTPS links

    untitaker committed Jan 6, 2017
  2. Make `load_payload()` signature consistent between types (#75)

    Fixes #74.
    
    The `JSONWebSignatureSerializer.load_payload` signature change is potentially breaking if anybody passed `return_header` as a second non-keyword argument to the method in the past. `itsdangerous.py` itself is using kwargs correctly everywhere so this shouldn't be an issue.
    
    For the mixin, the change ensures it will pass additional arguments correctly.
    ambv committed with untitaker Jan 6, 2017
Commits on Nov 1, 2016
  1. Add license_file to setup.cfg metadata (#70)

    Without this, the LICENSE file is never included in the built wheels: this makes it harder for users to comply with the license.
    With this addition a file LICENSE.txt will be created in the `xxx.dist-info` directory with the content of the `license_file` file, e.g. the top level LICENSE.
    pombredanne committed with davidism Nov 1, 2016
Commits on Aug 21, 2016
  1. Forbid unsafe separators

    Fix #62
    untitaker committed Aug 21, 2016
  2. Fix test setup

    untitaker committed Aug 21, 2016
  3. Fix test setup

    untitaker committed Aug 21, 2016
  4. Revamp test setup

    untitaker committed Aug 21, 2016
  5. Fix frontpage example

    Fix #29
    untitaker committed Aug 21, 2016
Commits on Jul 23, 2016
  1. Fix typo (wheather ~> whether) (#65)

    Christian Rotzoll committed with davidism Jul 23, 2016
Commits on Jul 7, 2016
  1. Fix misleading EPOCH comment. (#64)

    #46
    
    1/1/2011 cutoff was removed, but comment was not updated.
    stereosteve committed with davidism Jul 7, 2016
Commits on May 2, 2016
  1. Add PyPy 3 to travis build matrix (#60)

    'pypy3' on Travis passes all tests without modification.
    Travis uses the following PyPy 3k version currently:
    
    Python 3.2.5 (b2091e973da6, Oct 19 2014, 18:29:55)
    [PyPy 2.4.0 with GCC 4.6.3]
    jayvdb committed with untitaker May 2, 2016
Commits on Apr 13, 2016
  1. Revert "JWT Serializer sets default media type header"

    This reverts commit f513b48.
    davidism committed Apr 13, 2016
Commits on Apr 12, 2016
  1. More compact JSON dumps for unicode strings (#38)

    Pass `ensure_ascii=False` to `json.dumps`, this will produce shorter json dumps.
    tahajahangir committed with davidism Apr 12, 2016
  2. fix docs theme logo height

    davidism committed Apr 12, 2016
  3. use themes submodule

    davidism committed Apr 12, 2016
  4. docs show copyright range to current year

    use first year of copyright
    davidism committed Apr 12, 2016
Commits on Apr 11, 2016
  1. tag dev builds

    add version string
    add license for setup, closes #52
    davidism committed Apr 11, 2016
  2. use struct to convert int to/from bytes

    directly alias constant_time_compare to compare_digest if possible
    davidism committed Apr 11, 2016
Commits on Apr 10, 2016
Commits on Apr 3, 2016
  1. Change to Pallets project

    quobit committed with davidism Apr 3, 2016
Commits on Apr 2, 2016
  1. Support universal wheels

    graingert committed with davidism Apr 2, 2016
  2. Use rstrip instead of strip

    Because padding is only ever going to be added to the end.
    eugene-eeo committed with davidism Apr 2, 2016