Plone.session

Latest version: v4.0.4

Safety actively analyzes 723954 Python packages for vulnerabilities to keep your Python projects secure.

Scan your dependencies

Page 7 of 7

3.0a1

------------------

- Avoid deprecation warning for the sha module in Python 2.6.
[hannosch]

- Declare test dependencies in an extra.
[hannosch]

- Specify package dependencies.
[hannosch]

- Fixed the remaining tests to work with the new keyring backend.
[hannosch]

- Fixed a component lookup call in the HashSession source.
[davisagli, hannosch]

- Update default (hash) session source to use plone.keyring to manage the secrets.
[wichert]

2.1

----------------

- Protect the setupSession call with the ManageUsers permission.
Fixes possible privilege escalation.
[maurits]

- Make the cookie lifetime configurable. Patch by Rok Garbas.
Fixes http://dev.plone.org/plone/ticket/7248
[wichert, garbas]

2.0

----------------

- Fix CSRF protection for managing server secrets via the Plone session
plugin for PAS. Fixes http://dev.plone.org/plone/ticket/8176
[witsch]

1.2

----------------

- Use the binascii base64 methods to encode/decode the session cookie. This
prevents newlines being inserted in long cookies.
[wichert]

1.1

----------------

- Use the userid instead of the login name in session identifiers. This has the
side-effect of working around a bug in PAS which caused us to mix up users when
the login name used was an inexact match for another login name.
[wichert]

1.0

----------------

- First stable release
[wichert]

Page 7 of 7

© 2025 Safety CLI Cybersecurity Inc. All Rights Reserved.