Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It shouldn't be more than changing those two lines:

https://github.com/mitsuhiko/itsdangerous/blob/59f3bf7877e21...

And the tests, of course.



My point exactly! Armin (the maker/maintainer of the module) will probably consider doing this somewhere in the future.


I just pushed out a release that makes it possible to override the digest in a subclass easier.


While overrideability is good, wouldn't it be better to also be 'secure by default'? I'd imagine that SHA-2 would be more sensible default for most users.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: