[Python-Dev] PEP 506 secrets module

Guido van Rossum guido at python.org
Thu Jan 14 13:47:09 EST 2016


I think the discussion petered out and nobody asked me to approve it yet
(or I lost track of it). I'm almost happy to approve it in the current
state. My only quibble is with some naming -- I'm not sure that a
super-generic name like 'equal' is better than the original
('compare_digest'), and I would have picked a different name for token_url
-- probably token_urlsafe. But maybe Steven can convince me that the names
currently in the PEP are better. (I also don't like the wishy-washy
position of the PEP on the actual specs of the proposed functions. But I'm
fine with the actual implementation shown as the spec.)

On Thu, Jan 14, 2016 at 10:36 AM, Brett Cannon <brett at python.org> wrote:

> I noticed an article about default rand usage in Go
> <http://blog.sgmansfield.com/2016/01/the-hidden-dangers-of-default-rand/>
> from the Go Weekly newsletter and it reminded me about PEP 506 and the
> secrets module. That's when I noticed that the PEP is still open. What is
> the current blocker on the PEP?
>
> On Thu, 15 Oct 2015 at 17:57 Steven D'Aprano <steve at pearwood.info> wrote:
>
>> Hi,
>>
>> As extensively discussed on Python-Ideas, the secrets module and PEP 506
>> is (I hope) ready for pronouncement.
>>
>> https://www.python.org/dev/peps/pep-0506/
>>
>> There is code and tests here:
>>
>> https://bitbucket.org/sdaprano/secrets
>>
>>
>> or you can run
>>
>> hg clone https://sdaprano@bitbucket.org/sdaprano/secrets
>>
>>
>> The code is written for and tested on Python 2.6, 2.7, 3.1 - 3.4.
>>
>>
>>
>> --
>> Steve
>> _______________________________________________
>> Python-Dev mailing list
>> Python-Dev at python.org
>> https://mail.python.org/mailman/listinfo/python-dev
>> Unsubscribe:
>> https://mail.python.org/mailman/options/python-dev/brett%40python.org
>>
>
> _______________________________________________
> Python-Dev mailing list
> Python-Dev at python.org
> https://mail.python.org/mailman/listinfo/python-dev
> Unsubscribe:
> https://mail.python.org/mailman/options/python-dev/guido%40python.org
>
>


-- 
--Guido van Rossum (python.org/~guido)
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mail.python.org/pipermail/python-dev/attachments/20160114/54202db4/attachment.html>


More information about the Python-Dev mailing list