Added information about pickle security and SocketHandler.

This commit is contained in:
Vinay Sajip 2010-06-29 15:13:14 +00:00
parent 1c919a64ed
commit 86aa90539b
1 changed files with 5 additions and 0 deletions

View File

@ -2039,6 +2039,11 @@ sends logging output to a network socket. The base class uses a TCP socket.
Pickles the record's attribute dictionary in binary format with a length
prefix, and returns it ready for transmission across the socket.
Note that pickles aren't completely secure. If you are concerned about
security, you may want to override this method to implement a more secure
mechanism. For example, you can sign pickles using HMAC and then verify
them on the receiving end, or alternatively you can disable unpickling of
global objects on the receiving end.
.. method:: send(packet)