summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorVinay Sajip <vinay_sajip@yahoo.co.uk>2010-06-29 15:13:14 +0000
committerVinay Sajip <vinay_sajip@yahoo.co.uk>2010-06-29 15:13:14 +0000
commit5a48d63bc1a70442f65ddc540edd143c52b5c3a3 (patch)
tree6946d333818f28be9b2021f6f0c804798e4ec6c2
parenta14cd7c186de010d7696da7b678555833da2cc7c (diff)
downloadcpython-5a48d63bc1a70442f65ddc540edd143c52b5c3a3.tar.gz
Added information about pickle security and SocketHandler.
-rw-r--r--Doc/library/logging.rst5
1 files changed, 5 insertions, 0 deletions
diff --git a/Doc/library/logging.rst b/Doc/library/logging.rst
index 16b3e7280e..fbb0935680 100644
--- a/Doc/library/logging.rst
+++ b/Doc/library/logging.rst
@@ -2039,6 +2039,11 @@ sends logging output to a network socket. The base class uses a TCP socket.
Pickles the record's attribute dictionary in binary format with a length
prefix, and returns it ready for transmission across the socket.
+ Note that pickles aren't completely secure. If you are concerned about
+ security, you may want to override this method to implement a more secure
+ mechanism. For example, you can sign pickles using HMAC and then verify
+ them on the receiving end, or alternatively you can disable unpickling of
+ global objects on the receiving end.
.. method:: send(packet)