Barry Warsaw barry at canonical.com
Tue Sep 28 14:22:39 CEST 2010

Thanks for the branch Jimmy.  I think you make some good points about enabling some form of authentication in the REST server.  I've looked at:


which provides examples of hooking up repoze.who.  Did you think about that and if so, why did you choose not to use it (adding a dependency and the extra code complexity is a valid answer :).

Have you thought about using something like OAuth?  Are you concerned at all about cleartext passwords?

Finally, while your patch looks basically decent (I'd quibble with some whitespace, but that's unimportant), please consider adding a test and/or some documentation (the latter perhaps as a doctest).  And are you willing and able to assign your copyright to the FSF?
