Plone.protect

Latest version: v5.0.2

Safety actively analyzes 723650 Python packages for vulnerabilities to keep your Python projects secure.

Scan your dependencies

Page 6 of 9

3.0.14

-------------------

- Handle TypeError caused by getToolByName on an
invalid context
[vangheem]

- You can opt out of clickjacking protection by setting the
environment variable ``PLONE_X_FRAME_OPTIONS`` to an empty string.
[maurits]

- Be more flexible in parsing the ``PLONE_CSRF_DISABLED`` environment
variable. We are no longer case sensitive, and we accept ``true``,
``t``, ``yes``, ``y``, ``1`` as true values.
[maurits]

- Avoid TypeError when checking the content-type header.
[maurits]

3.0.13

-------------------

- Always force html serializer as the XHTML variant seems
to cause character encoding issues
[vangheem]

3.0.12

-------------------

- Do not check writes to temporary storage like session storage
[davisagli]

3.0.11

-------------------

- play nicer with inline JavaScript
[vangheem]

3.0.10

-------------------

- make imports backward compatible
[vangheem]

3.0.9

------------------

- patch pluggable auth with marmoset patch because
the patch would not apply otherwise depending on
somewhat-random import order
[vangheem]

- get auto-csrf protection working on the zope root
[vangheem]

Page 6 of 9

© 2025 Safety CLI Cybersecurity Inc. All Rights Reserved.