Skip to content

Conversation

@Fidget-Spinner
Copy link
Member

@Fidget-Spinner Fidget-Spinner commented Jan 21, 2021

  • Remove html_getfile.
  • Use locally generated secret to prevent other users from accessing a running web server.

EDIT: Honestly I'm not sure if we need to remove html_getfile now that there's a token to validate the user.

https://bugs.python.org/issue42988

@Fidget-Spinner Fidget-Spinner changed the title bpo-42988: Remove html_getfile operation from pydoc due to security concerns bpo-42988: Improve pydoc web server security Jan 22, 2021
@github-actions
Copy link

This PR is stale because it has been open for 30 days with no activity.

@github-actions github-actions bot added the stale Stale PR or inactive for long period of time. label Feb 26, 2021
@vstinner
Copy link
Member

I merged PR #25015 fix instead.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

awaiting review stale Stale PR or inactive for long period of time.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants