[Twisted-Python] Potential PB Security Problem (And Solution)

Glyph Lefkowitz glyph at twistedmatrix.com
Sat Feb 16 13:02:34 EST 2002


On Sat, 2002-02-16 at 11:55, Allen Short wrote:
> On Sat, 2002-02-16 at 05:47, Glyph Lefkowitz wrote:
> > I guess I'm just being thick here.  What is the convenience being lost? 
> > The additional 10 characters per remote invocation doesn't seem that
> > significant to me. 
> 
> it does to me, if only because of the existing code using it. if you
> want to deprecate the current way of doing things, that'd work, i think:
> but let's not spawn a massive refactoring frenzy all at once, please?

Heh.  I have to deal with a volume of code about 4 times the size that
is publicly visible, so that is not lost on me :).

I do plan to slowly deprecate it, with warning messages printed each
time a "bad" remote method is called.  Otherwise I'd be sure to miss at
least one remote notification on the first pass (after all, part of the
problem is that they're difficult to locate right now since they're not
tagged with anything distinctive...)

-- 
"Cannot stand to be one of many -- I'm not what they are."
        -Guster, "Rocketship"
                glyph lefkowitz; ninjaneer, freelance demiurge
    glyph @ [ninjaneering|twistedmatrix].com
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 232 bytes
Desc: This is a digitally signed message part
Url : http://twistedmatrix.com/pipermail/twisted-python/attachments/20020216/f894b4a1/attachment.pgp 


More information about the Twisted-Python mailing list