Metadata-Version: 2.0
Name: more.itsdangerous
Version: 0.0.2
Summary: An identity policy for morepath using itsdangerous.
Home-page: http://github.com/morepath/more.itsdangerous
Author: Seantis GmbH
Author-email: info@seantis.ch
License: BSD
Platform: any
Classifier: Intended Audience :: Developers
Classifier: Programming Language :: Python
Classifier: Programming Language :: Python :: 3
Classifier: Topic :: Software Development :: Libraries :: Python Modules
Classifier: License :: OSI Approved :: BSD License
Requires-Dist: itsdangerous
Requires-Dist: morepath
Provides-Extra: test
Requires-Dist: coverage; extra == 'test'
Requires-Dist: pytest; extra == 'test'


Usage
-----

.. code-block:: python

    import morepath
    from more.itsdangerous import IdentityPolicy

    class App(morepath.App):
        pass

    @App.identity_policy()
    def get_identity_policy():
        return IdentityPolicy()

    @App.verify_identity()
    def verify_identity(identity):
        # trust the identity established by the identity policy (we could keep
        # checking if the user is really in the database here - or if it was
        # removed in the meantime)
        return True

See `<http://morepath.readthedocs.org/en/latest/security.html>`_ to learn more
about Morepath's security model and and have
a look at the commented source code:

`<https://github.com/morepath/more.itsdangerous/blob/master/more/itsdangerous/identity_policy.py>`_

The IdentityPolicy class is meant to be extended because everyone has differing
needs. It simply provides a way to store the identity as a signed cookie, using
itsdangerous.

Usage in Development
--------------------

By default, the cookies created by more.itsdangerous are
`HttpOnly <http://en.wikipedia.org/wiki/HTTP_cookie#HttpOnly_cookie>`_ and
`Secure <http://en.wikipedia.org/wiki/HTTP_cookie#Secure_cookie>`_.

If you have differing needs or if you are running a development server you
might have to change the identity policy's configuration:

.. code-block:: python

    @App.identity_policy()
    def get_identity_policy():
        # make the cookies work under http, not just https
        return IdentityPolicy(secure=False)

Note that this should only be used in development. In this day and age you do
not want to transmit cookies over http!

Run the Tests
-------------

Install tox and run it::

    pip install tox
    tox

Limit the tests to a specific python version::

    tox -e py27

Conventions
-----------

More Itsdangerous follows PEP8 as close as possible. To test for it run::

    tox -e pep8

More Itsdangerous uses `Semantic Versioning <http://semver.org/>`_

Build Status
------------

.. image:: https://travis-ci.org/morepath/more.itsdangerous.png
  :target: https://travis-ci.org/morepath/more.itsdangerous
  :alt: Build Status

Coverage
--------

.. image:: https://coveralls.io/repos/morepath/more.itsdangerous/badge.png?branch=master
  :target: https://coveralls.io/r/morepath/more.itsdangerous?branch=master
  :alt: Project Coverage

Latests PyPI Release
--------------------
.. image:: https://pypip.in/v/more.itsdangerous/badge.png
  :target: https://crate.io/packages/more.itsdangerous
  :alt: Latest PyPI Release

License
-------
more.itsdangerous is released under the revised BSD license

Changelog
---------

0.0.2 (2016-04-18)
~~~~~~~~~~~~~~~~~~~

- Adds compatibility with Morepath 0.14+.
  [henri-hulski]

0.0.1 (2015-04-29)
~~~~~~~~~~~~~~~~~~~

- Initial release
  [href]


