NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #2861 most downloaded on PyPI
The Pyramid Web Framework, a Pylons project
Last release 6 months ago
11 Mar 2026
Ships unpredictably
gaps range from 8 days to 2.5 years
Rarely documented
notes for 10 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
16 years old
157 releases · first in 2010
- No changes from 2.1rc4.
No changes from 2.1rc4.
Add static license specifier LicenseRef-Repoze-BSD-derived to the package metadata to satisfy SPDX license format.
Add static license specifier LicenseRef-Repoze-BSD-derived to the package metadata to satisfy SPDX license format.
One column per quarter.
Add "Operating System :: Independent" trove classifier.
Add "Operating System :: Independent" trove classifier.
Remove static license specifier in metadata, relying on the license file instead.
Remove static license specifier in metadata, relying on the license file instead.
Switch dev dependencies to using dependency groups instead of extras. See https://github.com/Pylons/pyramid/pull/3810
Switch dev dependencies to using dependency groups instead of extras. See https://github.com/Pylons/pyramid/pull/3810
Update Github actions to install Python versions using uv instead of setup-python to support versions that aren't available by default on hosted runner images. See https://github.com/Pylons/pyramid/pull/3810
Remove internal usages of deprecated locale and datetime APIs to reduce deprecation warnings. See https://github.com/Pylons/pyramid/pull/3808
Add support for Python 3.12, 3.13, and 3.14.
Added HTTP 418 error code via pyramid.httpexceptions.HTTPImATeapot. See https://github.com/Pylons/pyramid/pull/3667
Base coverage reports in tests on Python 3.14 instead of Python 3.8.
All scripts now pass a new option __script__ when loading the WSGI app. For example, pserve sets __script__ == 'pserve'. This works for pserve, pshell, prequest, proutes, ptweens, pviews, as well as when using pyramid.paster.bootstrap directly.
When using plaster-pastedeploy to load an INI file, this option will manifest as a new value passed into the global_conf arg of your application factory, where you can use it as part of initializing your app.
Replace usage of md5 in the Pyramid view system with sha256. This is not a security-related feature and is considered an implementation detail that should not impact users.
Replace usage of pkg_resources in pyramid.path.DottedNameResolver. See https://github.com/Pylons/pyramid/pull/3748
Replace usage of pkg_resources in pdistreport and pshell CLI commands. See https://github.com/Pylons/pyramid/pull/3749
Constrain setuptools < 82 to remain compatible with required pkg_resources features. Work continues to fully remove pkg_resources from Pyramid code in future releases. See https://github.com/Pylons/pyramid/pull/3795
Remove internal usages of deprecated locale and datetime APIs to reduce deprecation warnings. See https://github.com/Pylons/pyramid/pull/3808
Fix issues where permissions may be checked on exception views. This is not supposed to happen in normal circumstances.
This also prevents issues where a request.url fails to be decoded when logging info when pyramid.debug_authorization is enabled.
Applications raising pyramid.exceptions.BadCSRFToken and pyramid.exceptions.BadCSRFOrigin were returning invalid HTTP status lines with values like 400 Bad CSRF Origin instead of 400 Bad Request.
The methods LegacySessionCSRFStoragePolicy.check_csrf_token, SessionCSRFStoragePolicy.check_csrf_token and CookieCSRFStoragePolicy.check_csrf_token now use errors='backslashreplace' when encoding the supplied_token to "latin-1". Previously UnicodeEncodeError was raised when supplied_token could not be encoded to "latin-1". See https://github.com/Pylons/pyramid/pull/3800
Drop support for Python 3.6, 3.7, 3.8, and 3.9.
Drop support for l*gettext() methods in the i18n module. These have been deprecated in Python's gettext module since 3.8, and removed in Python 3.11.
Add get_spec method to IPackageOverrides. See https://github.com/Pylons/pyramid/pull/3792
When using a cache buster with asset overrides, the cache buster will find the first existing file in the override stack, rather than taking the first override regardless of whether the file exists or not. See https://github.com/Pylons/pyramid/pull/3792
Deprecated the ability to use a non-existent package with pyramid.config.Configurator.add_static_view and pyramid.static.static_view. This can be fixed by choosing a path located within a real package as the root_dir for your static files. This is almost always either a misconfig or an attempt to define an alias location for use with pyramid.config.Configurator.override_asset. See https://github.com/Pylons/pyramid/pull/3752
Sync the SQLAlchemy Wiki tutorial with changes to the pyramid-cookiecutter-starter. Includes updates to use pyproject.toml to replace separate config files for pytest, coverage, and setuptools. Also upgrades patterns to support SQLAlchemy 2.0. See https://github.com/Pylons/pyramid/pull/3747
Sync the ZODB Wiki tutorial with changes to the pyramid-cookiecutter-starter. Includes updates to use pyproject.toml to replace separate config files for pytest, coverage, and setuptools. See https://github.com/Pylons/pyramid/pull/3751
Nothing published for this version
add the bugfix release to whatsnew
add the bugfix release to whatsnew
add pre-commented forward
Break potential reference cycle between request and context. See https://github.com/Pylons/pyramid/pull/3649
Break potential reference cycle between request and context. See https://github.com/Pylons/pyramid/pull/3649
Remove update_wrapper from pyramid.decorator.reify. See https://github.com/Pylons/pyramid/pull/3657
Overhaul tutorials and update cookiecutter to de-emphasize request.user in favor of request.identity for common use cases. See https://github.com/Pylo
Overhaul tutorials and update cookiecutter to de-emphasize request.user in favor of request.identity for common use cases. See https://github.com/Pylons/pyramid/pull/3629
Improve documentation and patterns with builtin fixtures shipped in the cookiecutters. See https://github.com/Pylons/pyramid/pull/3629
…and were coupled to the vulnerable pickle serialization format which could lead to remove code execution if the secret key is compromised. See https:/…
Add support for Python 3.9. See https://github.com/Pylons/pyramid/issues/3622
The aslist method now handles non-string objects when flattening. See https://github.com/Pylons/pyramid/pull/3594
It is now possible to pass multiple values to the header predicate for route and view configuration. See https://github.com/Pylons/pyramid/pull/3576
Add support for Python 3.8. See https://github.com/Pylons/pyramid/pull/3547
New security APIs have been added to support a massive overhaul of the authentication and authorization system. Read "Upgrading Authentication/Authorization" in the "What's New in Pyramid 2.0" chapter of the documentation for information about using this new system.
pyramid.config.Configurator.set_security_policy.
pyramid.interfaces.ISecurityPolicy
pyramid.request.Request.identity.
pyramid.request.Request.is_authenticated
pyramid.authentication.SessionAuthenticationHelper
pyramid.authorization.ACLHelper
is_authenticated=True/False predicate for route and view configs
See https://github.com/Pylons/pyramid/pull/3465 and https://github.com/Pylons/pyramid/pull/3598
Changed the default serializer on pyramid.session.SignedCookieSessionFactory to use pyramid.session.JSONSerializer instead of pyramid.session.PickleSerializer. Read "Upgrading Session Serialization" in the "What's New in Pyramid 2.0" chapter of the documentation for more information about why this change was made. See https://github.com/Pylons/pyramid/pull/3413
It is now possible to control whether a route pattern contains a trailing slash when it is composed with a route prefix using config.include(..., route_prefix=...) or with config.route_prefix_context(...). This can be done by specifying an empty pattern and setting the new argument inherit_slash=True. For example:
with config.route_prefix_context('/users'):
config.add_route('users', '', inherit_slash=True)
In the example, the resulting pattern will be /users. Similarly, if the route prefix were /users/ then the final pattern would be /users/. If the pattern was '/', then the final pattern would always be /users/. This new setting is only available if the pattern supplied to add_route is the empty string (''). See https://github.com/Pylons/pyramid/pull/3420
No longer define pyramid.request.Request.json_body which is already provided by WebOb. This allows the attribute to now be settable. See https://github.com/Pylons/pyramid/pull/3447
Improve debugging info from pyramid.view.view_config decorator. See https://github.com/Pylons/pyramid/pull/3483
A new parameter, allow_no_origin, was added to pyramid.config.Configurator.set_default_csrf_options as well as pyramid.csrf.check_csrf_origin. This option controls whether a request is rejected if it has no Origin or Referer header - often the result of a user configuring their browser not to send a Referer header for privacy reasons even on same-domain requests. The default is to reject requests without a known origin. It is also possible to allow the special Origin: null header by adding it to the pyramid.csrf_trusted_origins list in the settings. See https://github.com/Pylons/pyramid/pull/3512 and https://github.com/Pylons/pyramid/pull/3518
A new parameter, check_origin, was added to pyramid.config.Configurator.set_default_csrf_options which disables origin checking entirely. See https://github.com/Pylons/pyramid/pull/3518
Added pyramid.interfaces.IPredicateInfo which defines the object passed to predicate factories as their second argument. See https://github.com/Pylons/pyramid/pull/3514
Added support for serving pre-compressed static assets by using the content_encodings argument of pyramid.config.Configurator.add_static_view and pyramid.static.static_view. See https://github.com/Pylons/pyramid/pull/3537
Fix DeprecationWarning emitted by using the imp module. See https://github.com/Pylons/pyramid/pull/3553
Properties created via config.add_request_method(..., property=True) or request.set_property used to be readonly. They can now be overridden via request.foo = ... and until the value is deleted it will return the overridden value. This is most useful when mocking request properties in testing. See https://github.com/Pylons/pyramid/pull/3559
Finished callbacks are now executed as part of the closer that is invoked as part of pyramid.scripting.prepare and pyramid.paster.bootstrap. See https://github.com/Pylons/pyramid/pull/3561
Added pyramid.request.RequestLocalCache which can be used to create simple objects that are shared across requests and can be used to store per-request data. This is useful when the source of data is external to the request itself. Often a reified property is used on a request via pyramid.config.Configurator.add_request_method, or pyramid.decorator.reify, and these work great when the data is generated on-demand when accessing the request property. However, often the case is that the data is generated when accessing some other system and then we want to cache the data for the duration of the request. See https://github.com/Pylons/pyramid/pull/3561
Exposed pyramid.authorization.ALL_PERMISSIONS and pyramid.authorization.DENY_ALL such that all of the ACL-related constants are now importable from the pyramid.authorization namespace. See https://github.com/Pylons/pyramid/pull/3563
pserve now outputs verbose messaging to stderr instead of stdout to circumvent buffering issues that exist by default on stdout. See https://github.com/Pylons/pyramid/pull/3593
Deprecated the authentication and authorization interfaces and principal-based support. See "Upgrading Authentication/Authorization" in the "What's New in Pyramid 2.0" chapter of the documentation for information on equivalent APIs and notes on upgrading. The following APIs are deprecated as a result of this change:
pyramid.config.Configurator.set_authentication_policy
pyramid.config.Configurator.set_authorization_policy
pyramid.interfaces.IAuthenticationPolicy
pyramid.interfaces.IAuthorizationPolicy
pyramid.request.Request.effective_principals
pyramid.request.Request.unauthenticated_userid
pyramid.authentication.AuthTktAuthenticationPolicy
pyramid.authentication.RemoteUserAuthenticationPolicy
pyramid.authentication.RepozeWho1AuthenticationPolicy
pyramid.authentication.SessionAuthenticationPolicy
pyramid.authentication.BasicAuthAuthenticationPolicy
pyramid.authorization.ACLAuthorizationPolicy
The effective_principals view and route predicates.
Deprecated pyramid.security.principals_allowed_by_permission. This method continues to work with the deprecated pyramid.interfaces.IAuthorizationPolicy interface but will not work with the new pyramid.interfaces.ISecurityPolicy. See https://github.com/Pylons/pyramid/pull/3465
Deprecated several ACL-related aspects of pyramid.security. Equivalent objects should now be imported from the pyramid.authorization namespace. This includes:
pyramid.security.Everyone
pyramid.security.Authenticated
pyramid.security.ALL_PERMISSIONS
pyramid.security.DENY_ALL
pyramid.security.ACLAllowed
pyramid.security.ACLDenied
Deprecated pyramid.session.PickleSerializer. See https://github.com/pylons/pyramid/issues/2709, and https://github.com/pylons/pyramid/pull/3353, and https://github.com/pylons/pyramid/pull/3413
Drop support for Python 2.7, 3.4, and 3.5. See https://github.com/Pylons/pyramid/pull/3421, and https://github.com/Pylons/pyramid/pull/3547, and https://github.com/Pylons/pyramid/pull/3634
Removed the pyramid.compat module. Integrators should use the six module or vendor shims they are using into their own codebases going forward. https://github.com/Pylons/pyramid/pull/3421
pcreate and the builtin scaffolds have been removed in favor of using the cookiecutter tool and the pyramid-cookiecutter-starter cookiecutter. The script and scaffolds were deprecated in Pyramid 1.8. See https://github.com/Pylons/pyramid/pull/3406
Changed the default hashalg on pyramid.authentication.AuthTktCookieHelper to sha512. See https://github.com/Pylons/pyramid/pull/3557
Removed pyramid.interfaces.ITemplateRenderer. This interface was deprecated since Pyramid 1.5 and was an interface used by libraries like pyramid_mako and pyramid_chameleon but provided no functionality within Pyramid itself. See https://github.com/Pylons/pyramid/pull/3409
Removed pyramid.security.has_permission, pyramid.security.authenticated_userid, pyramid.security.unauthenticated_userid, and pyramid.security.effective_principals. These methods were deprecated in Pyramid 1.5 and all have equivalents available as properties on the request. For example, request.authenticated_userid. See https://github.com/Pylons/pyramid/pull/3410
Removed support for supplying a media range to the accept predicate of both pyramid.config.Configurator.add_view and pyramid.config.Configurator.add_route. These options were deprecated in Pyramid 1.10 and WebOb 1.8 because they resulted in uncontrollable matching that was not compliant with the RFC. See https://github.com/Pylons/pyramid/pull/3411
Removed pyramid.session.UnencryptedCookieSessionFactoryConfig. This session factory was replaced with pyramid.session.SignedCookieSessionFactory in Pyramid 1.5 and has been deprecated since then. See https://github.com/Pylons/pyramid/pull/3412
Removed pyramid.session.signed_serialize, and pyramid.session.signed_deserialize. These methods were only used by the now-removed pyramid.session.UnencryptedCookieSessionFactoryConfig and were coupled to the vulnerable pickle serialization format which could lead to remove code execution if the secret key is compromised. See https://github.com/Pylons/pyramid/pull/3412
Changed the default serializer on pyramid.session.SignedCookieSessionFactory to use pyramid.session.JSONSerializer instead of pyramid.session.PickleSerializer. Read "Upgrading Session Serialization" in the "What's New in Pyramid 2.0" chapter of the documentation for more information about why this change was made. See https://github.com/Pylons/pyramid/pull/3413
pyramid.request.Request.invoke_exception_view will no longer be called by the default execution policy. See https://github.com/Pylons/pyramid/pull/3496
pyramid.config.Configurator.scan will no longer, by default, execute Venusian decorator callbacks registered for categories other than 'pyramid'. To find any decorator regardless of category, specify config.scan(..., categories=None). See https://github.com/Pylons/pyramid/pull/3510
The second argument to predicate factories has been changed from config to info, an instance of pyramid.interfaces.IPredicateInfo. This limits the data available to predicates but still provides the package, registry, settings and dotted-name resolver which should cover most use cases and is largely backward compatible. See https://github.com/Pylons/pyramid/pull/3514
Removed the check_csrf predicate. Instead, use pyramid.config.Configurator.set_default_csrf_options and the require_csrf view option to enable automatic CSRF checking. See https://github.com/Pylons/pyramid/pull/3521
Update the default behavior of pyramid.authenticationAuthTktAuthenticationPolicy and pyramid.authentication.AuthTktCookieHelper to only set a single cookie without a domain parameter when no other domain constraints are specified. Prior to this change, wild_domain=False (the default) was effectively treated the same as wild_domain=True, in which a cookie was defined such that browsers would use it both for the request's domain, as well as any subdomain. In the new behavior, cookies will only affect the current domain, and not subdomains, by default. See https://github.com/Pylons/pyramid/pull/3587
Restore build of PDF on Read The Docs. See https://github.com/Pylons/pyramid/issues/3290
Fix docs build for Sphinx 2.0. See https://github.com/Pylons/pyramid/pull/3480
Significant updates to the wiki, wiki2 tutorials to demonstrate the new security policy usage as well as a much more production-ready test harness. See https://github.com/Pylons/pyramid/pull/3557
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
- No major changes from 1.10b1.
No major changes from 1.10b1.
Fix deprecated escape sequences in preparation for Python 3.8. See https://github.com/Pylons/pyramid/pull/3400
Fix the pyramid.testing.DummyRequest to support the new request.accept API so that acceptable_offers is available even when code sets the value to a string. See https://github.com/Pylons/pyramid/pull/3396
Fix deprecated escape sequences in preparation for Python 3.8. See https://github.com/Pylons/pyramid/pull/3400
…handling code. The old MIMEAccept has been deprecated. The new methods follow the RFC's more closely. See https://github.com/Pylons/pyramid/pull/3251
Add a _depth and _category arguments to all of the venusian decorators. The _category argument can be used to affect which actions are registered when performing a config.scan(..., category=...) with a specific category. The _depth argument should be used when wrapping the decorator in your own. This change affects pyramid.view.view_config, pyramid.view.exception_view_config, pyramid.view.forbidden_view_config, pyramid.view.notfound_view_config, pyramid.events.subscriber and pyramid.response.response_adapter decorators. See https://github.com/Pylons/pyramid/pull/3105 and https://github.com/Pylons/pyramid/pull/3122
Fix the pyramid.request.Request class name after using set_property or config.add_request_method such that the str(request.__class__) would appear as pyramid.request.Request instead of pyramid.util.Request. See https://github.com/Pylons/pyramid/pull/3129
In cherrypy_server_runner, prefer imports from the cheroot package over the legacy imports from cherrypy.wsgiserver. See https://github.com/Pylons/pyramid/pull/3235
Add a context manager route_prefix_context to the pyramid.config.Configurator to allow for convenient setting of the route_prefix for include and add_route calls inside the context. See https://github.com/Pylons/pyramid/pull/3279
Modify the builtin session implementations to support SameSite options on cookies and set the default to 'Lax'. This affects pyramid.session.BaseCookieSessionFactory, pyramid.session.SignedCookieSessionFactory, and pyramid.session.UnencryptedCookieSessionFactoryConfig. See https://github.com/Pylons/pyramid/pull/3300
Modify pyramid.authentication.AuthTktAuthenticationPolicy and pyramid.csrf.CookieCSRFStoragePolicy to support the SameSite option on cookies and set the default to 'Lax'. See https://github.com/Pylons/pyramid/pull/3319
Added new pyramid.httpexceptions.HTTPPermanentRedirect exception/response object for a HTTP 308 redirect. See https://github.com/Pylons/pyramid/pull/3302
Within pshell, allow the user-defined setup function to be a generator, in which case it may wrap the command's lifecycle. See https://github.com/Pylons/pyramid/pull/3318
Within pshell, variables defined by the [pshell] settings are available within the user-defined setup function. See https://github.com/Pylons/pyramid/pull/3318
Add support for Python 3.7. Add testing on Python 3.8 with allowed failures. See https://github.com/Pylons/pyramid/pull/3333
Added the pyramid.config.Configurator.add_accept_view_order directive, allowing users to specify media type preferences in ambiguous situations such as when several views match. A default ordering is defined for media types that prefers human-readable html/text responses over JSON. See https://github.com/Pylons/pyramid/pull/3326
Support a list of media types in the accept predicate used in pyramid.config.Configurator.add_route. See https://github.com/Pylons/pyramid/pull/3326
Added pyramid.session.JSONSerializer. See "Upcoming Changes to ISession in Pyramid 2.0" in the "Sessions" chapter of the documentation for more information about this feature. See https://github.com/Pylons/pyramid/pull/3353
Add a registry argument to pyramid.renderers.get_renderer to allow users to avoid threadlocals during renderer lookup. See https://github.com/Pylons/pyramid/pull/3358
Pyramid's test suite is no longer distributed with the universal wheel. See https://github.com/Pylons/pyramid/pull/3387
All Python code is now formatted automatically using black. See https://github.com/Pylons/pyramid/pull/3388
Set appropriate code and title attributes on the HTTPClientError and HTTPServerError exception classes. This prevents inadvertently returning a 520 error code. See https://github.com/Pylons/pyramid/pull/3280
Replace webob.acceptparse.MIMEAccept from WebOb with webob.acceptparse.create_accept_header in the HTTP exception handling code. The old MIMEAccept has been deprecated. The new methods follow the RFC's more closely. See https://github.com/Pylons/pyramid/pull/3251
Catch extra errors like AttributeError when unpickling "trusted" session cookies with bad pickle data in them. This would occur when sharing a secret between projects that shouldn't actually share session cookies, like when reusing secrets between projects in development. See https://github.com/Pylons/pyramid/pull/3325
The pyramid.interfaces.ISession interface will move to require JSON-serializable objects in Pyramid 2.0. See "Upcoming Changes to ISession in Pyramid 2.0" in the "Sessions" chapter of the documentation for more information about this change. See https://github.com/Pylons/pyramid/pull/3353
The pyramid.session.signed_serialize and pyramid.session.signed_deserialize functions will be removed in Pyramid 2.0, along with the removal of pyramid.session.UnencryptedCookieSessionFactoryConfig which was deprecated in Pyramid 1.5. Please switch to using the SignedCookieSessionFactory, copying the code, or another session implementation if you're still using these features. See https://github.com/Pylons/pyramid/pull/3353
Media ranges are deprecated in the accept argument of pyramid.config.Configurator.add_route. Use a list of explicit media types to add_route to support multiple types.
Media ranges are deprecated in the accept argument of pyramid.config.Configurator.add_view. There is no replacement for ranges to add_view, but after much discussion the workflow is fundamentally ambiguous in the face of various client-supplied values for the Accept header. See https://github.com/Pylons/pyramid/pull/3326
On Python 3.4+ the repoze.lru dependency is dropped. If you were using this package directly in your apps you should make sure that you are depending on it directly within your project. See https://github.com/Pylons/pyramid/pull/3140
Remove the permission argument from pyramid.config.Configurator.add_route. This was an argument left over from a feature removed in Pyramid 1.5 and has had no effect since then. See https://github.com/Pylons/pyramid/pull/3299
Modify the builtin session implementations to set SameSite='Lax' on cookies. This affects pyramid.session.BaseCookieSessionFactory, pyramid.session.SignedCookieSessionFactory, and pyramid.session.UnencryptedCookieSessionFactoryConfig. See https://github.com/Pylons/pyramid/pull/3300
Variables defined in the [pshell] section of the settings will no longer override those set by the setup function. See https://github.com/Pylons/pyramid/pull/3318
pyramid.config.Configurator.add_notfound_view uses default redirect class exception pyramid.httpexceptions.HTTPTemporaryRedirect instead of previous pyramid.httpexceptions.HTTPFound. See https://github.com/Pylons/pyramid/pull/3328
Removed pyramid.config.Configurator.set_request_property which had been deprecated since Pyramid 1.5. Instead use pyramid.config.Configurator.add_request_method with reify=True or property=True. See https://github.com/Pylons/pyramid/pull/3368
Removed the principal keyword argument from pyramid.security.remember which had been deprecated since Pyramid 1.6 and replaced by the userid argument. See https://github.com/Pylons/pyramid/pull/3369
Removed the pyramid.tests subpackage that used to contain the Pyramid test suite. These changes also changed the format of the repository to move the code into a src folder. See https://github.com/Pylons/pyramid/pull/3387
Ad support for Read The Docs Ethical Ads. See https://github.com/Pylons/pyramid/pull/3360 and https://docs.readthedocs.io/en/latest/advertising/ethical-advertising.html
Add support for alembic to the pyramid-cookiecutter-alchemy cookiecutter and update the wiki2 tutorial to explain how it works. See https://github.com/Pylons/pyramid/pull/3307 and https://github.com/Pylons/pyramid-cookiecutter-alchemy/pull/7
Bump Sphinx to >= 1.7.4 in setup.py to support emphasize-lines in PDFs and to pave the way for xelatex support. See https://github.com/Pylons/pyramid/pull/3271, https://github.com/Pylons/pyramid/issues/667, and https://github.com/Pylons/pyramid/issues/2572
Added extra tests to the quick tutorial. See https://github.com/Pylons/pyramid/pull/3375
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Updated documentation links for docs.pylonsproject.org to use HTTPS.
No major changes from 1.9b1.
Updated documentation links for docs.pylonsproject.org to use HTTPS.
Add an informative error message when unknown predicates are supplied. The new message suggests alternatives based on the list of known predicates. Se
Add an informative error message when unknown predicates are supplied. The new message suggests alternatives based on the list of known predicates. See https://github.com/Pylons/pyramid/pull/3054
Added integrity attributes for JavaScripts in cookiecutters, scaffolds, and resulting source files in tutorials. See https://github.com/Pylons/pyramid/issues/2548
Update RELEASING.txt for updating cookiecutters. Change cookiecutter URLs to use shortcut. See https://github.com/Pylons/pyramid/issues/3042
Ensure the correct threadlocals are pushed during view execution when invoked from request.invoke_exception_view. See https://github.com/Pylons/pyramid/pull/3060
Fix a bug in which pyramid.security.ALL_PERMISSIONS failed to return a valid iterator in its __iter__ implementation. See https://github.com/Pylons/pyramid/pull/3074
Normalize the permission results to a proper class hierarchy. pyramid.security.ACLAllowed is now a subclass of pyramid.security.Allowed and pyramid.security.ACLDenied is now a subclass of pyramid.security.Denied. See https://github.com/Pylons/pyramid/pull/3084
Add a quote_via argument to pyramid.encode.urlencode to follow the stdlib's version and enable custom quoting functions. See https://github.com/Pylons/pyramid/pull/3088
Support _query=None and _anchor=None in request.route_url as well as query=None and anchor=None in request.resource_url. Previously this would cause an ? and a #, respectively, in the url with nothing after it. Now the unnecessary parts are dropped from the generated URL. See https://github.com/Pylons/pyramid/pull/3034
Revamp the IRouter API used by IExecutionPolicy to force pushing/popping the request threadlocals. The IRouter.make_request(environ) API has been replaced by IRouter.request_context(environ) which should be used as a context manager. See https://github.com/Pylons/pyramid/pull/3086
request.exception and request.exc_info will only be set if the response was generated by the EXCVIEW tween. This is to avoid any confusion where a res
request.exception and request.exc_info will only be set if the response was generated by the EXCVIEW tween. This is to avoid any confusion where a response was generated elsewhere in the pipeline and not in direct relation to the original exception. If anyone upstream wants to catch and render responses for exceptions they should set request.exception and request.exc_info themselves to indicate the exception that was squashed when generating the response.
Similar behavior occurs with request.invoke_exception_view in which the exception properties are set to reflect the exception if a response is successfully generated by the method.
This is a very minor incompatibility. Most tweens right now would give priority to the raised exception and ignore request.exception. This change just improves and clarifies that bookkeeping by trying to be more clear about the relationship between the response and its squashed exception. See https://github.com/Pylons/pyramid/pull/3029 and https://github.com/Pylons/pyramid/pull/3031
This dependency on plaster_pastedeploy should be considered subject to Pyramid's deprecation policy and may be removed in the future. Applications sho…
The file format used by all p* command line scripts such as pserve and pshell, as well as the pyramid.paster.bootstrap function is now replaceable thanks to a new dependency on plaster.
For now, Pyramid is still shipping with integrated support for the PasteDeploy INI format by depending on the plaster_pastedeploy binding library. This may change in the future.
Added an execution policy hook to the request pipeline. An execution policy has the ability to control creation and execution of the request objects before they enter the rest of the pipeline. This means for a single request environ the policy may create more than one request object.
The first library to use this feature is pyramid_retry.
CSRF support has been refactored out of sessions and into its own independent API in the pyramid.csrf module. It supports a pluggable pyramid.interfaces.ICSRFStoragePolicy which can be used to define your own mechanism for generating and validating CSRF tokens. By default, Pyramid continues to use the pyramid.csrf.LegacySessionCSRFStoragePolicy that uses the request.session.get_csrf_token and request.session.new_csrf_token APIs under the hood to preserve compatibility. Two new policies are shipped as well, pyramid.csrf.SessionCSRFStoragePolicy and pyramid.csrf.CookieCSRFStoragePolicy which will store the CSRF tokens in the session and in a standalone cookie, respectively. The storage policy can be changed by using the new pyramid.config.Configurator.set_csrf_storage_policy config directive.
CSRF tokens should be used via the new pyramid.csrf.get_csrf_token, pyramid.csrf.new_csrf_token and pyramid.csrf.check_csrf_token APIs in order to continue working if the storage policy is changed. Also, the pyramid.csrf.get_csrf_token function is injected into templates to be used conveniently in UI code.
See https://github.com/Pylons/pyramid/pull/2854 and https://github.com/Pylons/pyramid/pull/3019
Support an open_url config setting in the pserve section of the config file. This url is used to open a web browser when pserve --browser is invoked. When this setting is unavailable the pserve script will attempt to guess the port the server is using from the server:<server_name> section of the config file but there is no requirement that the server is being run in this format so it may fail. See https://github.com/Pylons/pyramid/pull/2984
The pyramid.config.Configurator can now be used as a context manager which will automatically push/pop threadlocals (similar to config.begin() and config.end()). It will also automatically perform a config.commit() and thus it is only recommended to be used at the top-level of your app. See https://github.com/Pylons/pyramid/pull/2874
The threadlocals are now available inside any function invoked via config.include. This means the only config-time code that cannot rely on threadlocals is code executed from non-actions inside the main. This can be alleviated by invoking config.begin() and config.end() appropriately or using the new context manager feature of the configurator. See https://github.com/Pylons/pyramid/pull/2989
HTTPException's accepts a detail kwarg that may be used to pass additional details to the exception. You may now pass objects so long as they have a valid __str__ method. See https://github.com/Pylons/pyramid/pull/2951
Fix a reference cycle causing memory leaks in which the registry would keep a Configurator instance alive even after the configurator was discarded. Another fix was also added for the global_registries object in which the registry was stored in a closure preventing it from being deallocated. See https://github.com/Pylons/pyramid/pull/2967
Fix a bug directly invoking pyramid.scripts.pserve.main with the --reload option in which sys.argv is always used in the subprocess instead of the supplied argv. See https://github.com/Pylons/pyramid/pull/2962
Pyramid currently depends on plaster_pastedeploy to simplify the transition to plaster by maintaining integrated support for INI files. This dependency on plaster_pastedeploy should be considered subject to Pyramid's deprecation policy and may be removed in the future. Applications should depend on the appropriate plaster binding to satisfy their needs.
Retrieving CSRF token from the session has been deprecated in favor of equivalent methods in the pyramid.csrf module. The CSRF methods (ISession.get_csrf_token and ISession.new_csrf_token) are no longer required on the ISession interface except when using the default pyramid.csrf.LegacySessionCSRFStoragePolicy.
Also, pyramid.session.check_csrf_token is now located at pyramid.csrf.check_csrf_token.
See https://github.com/Pylons/pyramid/pull/2854 and https://github.com/Pylons/pyramid/pull/3019
Added the execution policy to the routing diagram in the Request Processing chapter. See https://github.com/Pylons/pyramid/pull/2993
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
- No major changes from 1.8b1.
No major changes from 1.8b1.
Added an override option to config.add_translation_dirs to allow later calls to place translation directories at a higher priority than earlier calls.
Added an override option to config.add_translation_dirs to allow later calls to place translation directories at a higher priority than earlier calls. See https://github.com/Pylons/pyramid/pull/2902
Improve registry documentation to discuss uses as a component registry and as a dictionary. See https://github.com/Pylons/pyramid/pull/2893
Quick Tour, Quick Tutorial, and most other remaining documentation updated to use cookiecutters instead of pcreate and scaffolds. See https://github.com/Pylons/pyramid/pull/2888 and https://github.com/Pylons/pyramid/pull/2889
Fix unittests in wiki2 to work without different dependencies between py2 and py3. See https://github.com/Pylons/pyramid/pull/2899
Update Windows documentation to track newer Python 3 improvements to the installer. See https://github.com/Pylons/pyramid/pull/2900
Updated the mod_wsgi tutorial to use cookiecutters and Apache 2.4+. See https://github.com/Pylons/pyramid/pull/2901
Support for the IContextURL interface that was deprecated in Pyramid 1.3 has been removed. See https://github.com/Pylons/pyramid/pull/2822
Support for the IContextURL interface that was deprecated in Pyramid 1.3 has been removed. See https://github.com/Pylons/pyramid/pull/2822
Following the Pyramid deprecation period (1.6 -> 1.8), daemon support for pserve has been removed. This includes removing the daemon commands (start, stop, restart, status) as well as the following arguments: --daemon, --pid-file, --log-file, --monitor-restart, --status, --user, --group, --stop-daemon
To run your server as a daemon you should use a process manager instead of pserve.
pcreate is now interactive by default. You will be prompted if a file already exists with different content. Previously if there were similar files it would silently skip them unless you specified --interactive or --overwrite. See https://github.com/Pylons/pyramid/pull/2775
Removed undocumented argument cachebust_match from pyramid.static.static_view. This argument was shipped accidentally in Pyramid 1.6. See https://github.com/Pylons/pyramid/pull/2681
Change static view to avoid setting the Content-Encoding response header to an encoding guessed using Python's mimetypes module. This was causing clients to decode the content of gzipped files when downloading them. The client would end up with a foo.txt.gz file on disk that was already decoded, thus should really be foo.txt. Also, the Content-Encoding should only have been used if the client itself broadcast support for the encoding via Accept-Encoding request headers. See https://github.com/Pylons/pyramid/pull/2810
Settings are no longer accessible as attributes on the settings object (e.g. request.registry.settings.foo). This was deprecated in Pyramid 1.2. See https://github.com/Pylons/pyramid/pull/2823
Python 3.6 compatibility. https://github.com/Pylons/pyramid/issues/2835
pcreate learned about --package-name to allow you to create a new project in an existing folder with a different package name than the project name. See https://github.com/Pylons/pyramid/pull/2783
The _get_credentials private method of BasicAuthAuthenticationPolicy has been extracted into standalone function extract_http_basic_credentials in pyramid.authentication module, this function extracts HTTP Basic credentials from a request object, and returns them as a named tuple. See https://github.com/Pylons/pyramid/pull/2662
Pyramid 1.4 silently dropped a feature of the configurator that has been restored. It's again possible for action discriminators to conflict across different action orders. See https://github.com/Pylons/pyramid/pull/2757
pyramid.paster.bootstrap and its sibling pyramid.scripting.prepare can now be used as context managers to automatically invoke the closer and pop threadlocals off of the stack to prevent memory leaks. See https://github.com/Pylons/pyramid/pull/2760
Added pyramid.config.Configurator.add_exception_view and the pyramid.view.exception_view_config decorator. It is now possible using these methods or via the new exception_only=True option to add_view to add a view which will only be matched when handling an exception. Previously any exception views were also registered for a traversal context that inherited from the exception class which prevented any exception-only optimizations. See https://github.com/Pylons/pyramid/pull/2660
Added the exception_only boolean to pyramid.interfaces.IViewDeriverInfo which can be used by view derivers to determine if they are wrapping a view which only handles exceptions. This means that it is no longer necessary to perform request-time checks for request.exception to determine if the view is handling an exception - the pipeline can be optimized at config-time. See https://github.com/Pylons/pyramid/pull/2660
pserve should now work with gevent and other workers that need to monkeypatch the process, assuming the server and / or the app do so as soon as possible before importing the rest of pyramid. See https://github.com/Pylons/pyramid/pull/2797
Pyramid no longer copies the settings object passed to the pyramid.config.Configurator(settings=). The original dict is kept. See https://github.com/Pylons/pyramid/pull/2823
The csrf trusted origins setting may now be a whitespace-separated list of domains. Previously only a python list was allowed. Also, it can now be set using the PYRAMID_CSRF_TRUSTED_ORIGINS environment variable similar to other settings. See https://github.com/Pylons/pyramid/pull/2823
pserve --reload now uses the hupper library to monitor file changes. This comes with many improvements:
If the watchdog package is installed then monitoring will be done using inotify instead of cpu and disk-intensive polling.
The monitor is now a separate process that will not crash and starts up before any of your code.
The monitor will not restart the process after a crash until a file is saved.
The monitor works on windows.
You can now trigger a reload manually from a pyramid view or any other code via hupper.get_reloader().trigger_reload(). Kind of neat.
You can trigger a reload by issuing a SIGHUP to the monitor process.
A new [pserve] section is supported in your config files with a watch_files key that can configure pserve --reload to monitor custom file paths. See https://github.com/Pylons/pyramid/pull/2827
Allow streaming responses to be made from subclasses of pyramid.httpexceptions.HTTPException. Previously the response would be unrolled while testing for a body, making it impossible to stream a response. See https://github.com/Pylons/pyramid/pull/2863
Update starter, alchemy and zodb scaffolds to support IPv6 by using the new listen directives in waitress. See https://github.com/Pylons/pyramid/pull/2853
All p* scripts now use argparse instead of optparse. This improves their --help output as well as enabling nicer documentation of their options. See https://github.com/Pylons/pyramid/pull/2864
Any deferred configuration action registered via config.action may now depend on threadlocal state, such as asset overrides, being active when the action is executed. See https://github.com/Pylons/pyramid/pull/2873
Asset specifications for directories passed to config.add_translation_dirs now support overriding the entire asset specification, including the folder name. Previously only the package name was supported and the folder would always need to have the same name. See https://github.com/Pylons/pyramid/pull/2873
config.begin() will propagate the current threadlocal request through as long as the registry is the same. For example:
request = Request.blank(...)
config.begin(request) # pushes a request
config.begin() # propagates the previous request through unchanged
assert get_current_request() is request
Added a new callback option to config.set_default_csrf_options which can be used to determine per-request whether CSRF checking should be enabled to allow for a mix authentication methods. Only cookie-based methods generally require CSRF checking. See https://github.com/Pylons/pyramid/pull/2778
Fixed bug in proutes such that it now shows the correct view when a class and attr is involved. See: https://github.com/Pylons/pyramid/pull/2687
Fix a FutureWarning in Python 3.5 when using re.split on the format setting to the proutes script. See https://github.com/Pylons/pyramid/pull/2714
Fix a RuntimeWarning emitted by WebOb when using arbitrary objects as the userid in the AuthTktAuthenticationPolicy. This is now caught by the policy and the object is serialized as a base64 string to avoid the cryptic warning. Since the userid will be read back as a string on subsequent requests a more useful warning is emitted encouraging you to use a primitive type instead. See https://github.com/Pylons/pyramid/pull/2715
Pyramid 1.6 introduced the ability for an action to invoke another action. There was a bug in the way that config.add_view would interact with custom view derivers introduced in Pyramid 1.7 because the view's discriminator cannot be computed until view derivers and view predicates have been created in earlier orders. Invoking an action from another action would trigger an unrolling of the pipeline and would compute discriminators before they were ready. The new behavior respects the order of the action and ensures the discriminators are not computed until dependent actions from previous orders have executed. See https://github.com/Pylons/pyramid/pull/2757
Fix bug in i18n where the default domain would always use the Germanic plural style, even if a different plural function is defined in the relevant messages file. See https://github.com/Pylons/pyramid/pull/2859
The config.override_asset method now occurs during pyramid.config.PHASE1_CONFIG such that it is ordered to execute before any calls to config.add_translation_dirs. See https://github.com/Pylons/pyramid/pull/2873
The pcreate script and related scaffolds have been deprecated in favor of the popular cookiecutter project.
All of Pyramid's official scaffolds as well as the tutorials have been ported to cookiecutters:
Update Typographical Conventions. https://github.com/Pylons/pyramid/pull/2838
Add pyramid_nacl_session to session factories. See https://github.com/Pylons/pyramid/issues/2791
Update HACKING.txt from stale branch that was never merged to master. See https://github.com/Pylons/pyramid/pull/2782
Updated Windows installation instructions and related bits. See https://github.com/Pylons/pyramid/issues/2661
Fix an inconsistency in the documentation between view predicates and route predicates and highlight the differences in their APIs. See https://github.com/Pylons/pyramid/pull/2764
Clarify a possible misuse of the headers kwarg to subclasses of pyramid.httpexceptions.HTTPException in which more appropriate kwargs from the parent class pyramid.response.Response should be used instead. See https://github.com/Pylons/pyramid/pull/2750
The SQLAlchemy + URL Dispatch + Jinja2 (wiki2) and ZODB + Traversal + Chameleon (wiki) tutorials have been updated to utilize the new cookiecutters and drop support for the pcreate scaffolds.
See https://github.com/Pylons/pyramid/pull/2881 and https://github.com/Pylons/pyramid/pull/2883.
Improve output of p* script descriptions for help. See https://github.com/Pylons/pyramid/pull/2886
Quick Tour updated to use cookiecutters instead of pcreate and scaffolds. See https://github.com/Pylons/pyramid/pull/2888
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Fix a bug in the wiki2 tutorial where bcrypt is always expecting byte strings. See https://github.com/Pylons/pyramid/pull/2576
Fix a bug in the wiki2 tutorial where bcrypt is always expecting byte strings. See https://github.com/Pylons/pyramid/pull/2576
Simplify windows detection code and remove some duplicated data. See https://github.com/Pylons/pyramid/pull/2585 and https://github.com/Pylons/pyramid/pull/2586
Fixed the exception view tween to re-raise the original exception if no exception view could be found to handle the exception. This better allows twee
Fixed the exception view tween to re-raise the original exception if no exception view could be found to handle the exception. This better allows tweens further up the chain to handle exceptions that were left unhandled. Previously they would be converted into a PredicateMismatch exception if predicates failed to allow the view to handle the exception. See https://github.com/Pylons/pyramid/pull/2567
Exposed the pyramid.interfaces.IRequestFactory interface to mirror the public pyramid.interfaces.IResponseFactory interface.
Fix request.invoke_exception_view to raise an HTTPNotFound exception if no view is matched. Previously None would be returned if no views were matched
Fix request.invoke_exception_view to raise an HTTPNotFound exception if no view is matched. Previously None would be returned if no views were matched and a PredicateMismatch would be raised if a view "almost" matched (a view was found matching the context). See https://github.com/Pylons/pyramid/pull/2564
Add defaults for py.test configuration and coverage to all three scaffolds, and update documentation accordingly. See https://github.com/Pylons/pyramid/pull/2550
Add linkcheck to Makefile for Sphinx. To check the documentation for broken links, use the command make linkcheck SPHINXBUILD=$VENV/bin/sphinx-build. Also removed and fixed dozens of broken external links.
Fix the internal runner for scaffold tests to ensure they work with pip and py.test. See https://github.com/Pylons/pyramid/pull/2565
Removed inclusion of pyramid_tm in development.ini for alchemy scaffold See https://github.com/Pylons/pyramid/issues/2538
Removed inclusion of pyramid_tm in development.ini for alchemy scaffold See https://github.com/Pylons/pyramid/issues/2538
A default permission set via config.set_default_permission will no longer be enforced on an exception view. This has been the case for a while with the default exception views (config.add_notfound_view and config.add_forbidden_view), however for any other exception view a developer had to remember to set permission=NO_PERMISSION_REQUIRED or be surprised when things didn't work. It is still possible to force a permission check on an exception view by setting the permission argument manually to config.add_view. This behavior is consistent with the new CSRF features added in the 1.7 series. See https://github.com/Pylons/pyramid/pull/2534
This release announces the beta period for 1.7.
This release announces the beta period for 1.7.
Fix an issue where some files were being included in the alchemy scafffold which had been removed from the 1.7 series. See https://github.com/Pylons/pyramid/issues/2525
Automatic CSRF checks are now disabled by default on exception views. They can be turned back on by setting the appropriate require_csrf option on the
Automatic CSRF checks are now disabled by default on exception views. They can be turned back on by setting the appropriate require_csrf option on the view. See https://github.com/Pylons/pyramid/pull/2517
The automatic CSRF API was reworked to use a config directive for setting the options. The pyramid.require_default_csrf setting is no longer supported. Instead, a new config.set_default_csrf_options directive has been introduced that allows the developer to specify the default value for require_csrf as well as change the CSRF token, header and safe request methods. The pyramid.csrf_trusted_origins setting is still supported. See https://github.com/Pylons/pyramid/pull/2518
CSRF origin checks had a bug causing the checks to always fail. See https://github.com/Pylons/pyramid/pull/2512
Fix the test suite to pass on windows. See https://github.com/Pylons/pyramid/pull/2520
Following the Pyramid deprecation period (1.4 -> 1.6), AuthTktAuthenticationPolicy's default hashing algorithm is changing from md5 to sha512. If you…
Following the Pyramid deprecation period (1.4 -> 1.6), AuthTktAuthenticationPolicy's default hashing algorithm is changing from md5 to sha512. If you are using the authentication policy and need to continue using md5, please explicitly set hashalg to 'md5'.
This change does mean that any existing auth tickets (and associated cookies) will no longer be valid, and users will no longer be logged in, and have to login to their accounts again.
The check_csrf_token function no longer validates a csrf token in the query string of a request. Only headers and request bodies are supported. See https://github.com/Pylons/pyramid/pull/2500
Added a new setting, pyramid.require_default_csrf which may be used to turn on CSRF checks globally for every POST request in the application. This should be considered a good default for websites built on Pyramid. It is possible to opt-out of CSRF checks on a per-view basis by setting require_csrf=False on those views. See https://github.com/Pylons/pyramid/pull/2413
Added a require_csrf view option which will enforce CSRF checks on any request with an unsafe method as defined by RFC2616. If the CSRF check fails a BadCSRFToken exception will be raised and may be caught by exception views (the default response is a 400 Bad Request). This option should be used in place of the deprecated check_csrf view predicate which would normally result in unexpected 404 Not Found response to the client instead of a catchable exception. See https://github.com/Pylons/pyramid/pull/2413 and https://github.com/Pylons/pyramid/pull/2500
Added an additional CSRF validation that checks the origin/referrer of a request and makes sure it matches the current request.domain. This particular check is only active when accessing a site over HTTPS as otherwise browsers don't always send the required information. If this additional CSRF validation fails a BadCSRFOrigin exception will be raised and may be caught by exception views (the default response is 400 Bad Request). Additional allowed origins may be configured by setting pyramid.csrf_trusted_origins to a list of domain names (with ports if on a non standard port) to allow. Subdomains are not allowed unless the domain name has been prefixed with a .. See https://github.com/Pylons/pyramid/pull/2501
Added a new pyramid.session.check_csrf_origin API for validating the origin or referrer headers against the request's domain. See https://github.com/Pylons/pyramid/pull/2501
Pyramid HTTPExceptions will now take into account the best match for the clients Accept header, and depending on what is requested will return text/html, application/json or text/plain. The default for / is still text/html, but if application/json is explicitly mentioned it will now receive a valid JSON response. See https://github.com/Pylons/pyramid/pull/2489
A new event and interface (BeforeTraversal) has been introduced that will notify listeners before traversal starts in the router. See https://github.com/Pylons/pyramid/pull/2469 and https://github.com/Pylons/pyramid/pull/1876
Add a new "view deriver" concept to Pyramid to allow framework authors to inject elements into the standard Pyramid view pipeline and affect all views in an application. This is similar to a decorator except that it has access to options passed to config.add_view and can affect other stages of the pipeline such as the raw response from a view or prior to security checks. See https://github.com/Pylons/pyramid/pull/2021
Allow a leading = on the key of the request param predicate. For example, '=abc=1' is equivalent down to request.params['=abc'] == '1'. See https://github.com/Pylons/pyramid/pull/1370
A new request.invoke_exception_view(...) method which can be used to invoke an exception view and get back a response. This is useful for rendering an exception view outside of the context of the excview tween where you may need more control over the request. See https://github.com/Pylons/pyramid/pull/2393
Allow using variable substitutions like %(LOGGING_LOGGER_ROOT_LEVEL)s for logging sections of the .ini file and populate these variables from the pserve command line -- e.g.: pserve development.ini LOGGING_LOGGER_ROOT_LEVEL=DEBUG See https://github.com/Pylons/pyramid/pull/2399
A complete overhaul of the docs:
Use pip instead of easy_install.
Become opinionated by preferring Python 3.4 or greater to simplify installation of Python and its required packaging tools.
Use venv for the tool, and virtual environment for the thing created, instead of virtualenv.
Use py.test and pytest-cov instead of nose and coverage.
Further updates to the scaffolds as well as tutorials and their src files.
A complete overhaul of the alchemy scaffold as well as the Wiki2 SQLAlchemy + URLDispatch tutorial to introduce more modern features into the usage of SQLAlchemy with Pyramid and provide a better starting point for new projects. See https://github.com/Pylons/pyramid/pull/2024
Fix pserve --browser to use the --server-name instead of the app name when selecting a section to use. This was only working for people who had server and app sections with the same name, for example [app:main] and [server:main]. See https://github.com/Pylons/pyramid/pull/2292
The check_csrf view predicate has been deprecated. Use the new require_csrf option or the pyramid.require_default_csrf setting to ensure that the BadCSRFToken exception is raised. See https://github.com/Pylons/pyramid/pull/2413
Support for Python 3.3 will be removed in Pyramid 1.8. https://github.com/Pylons/pyramid/issues/2477
Python 2.6 is no longer supported by Pyramid. See https://github.com/Pylons/pyramid/issues/2368
Dropped Python 3.2 support. See https://github.com/Pylons/pyramid/pull/2256
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Continue removal of pserve daemon/process management features by deprecating --user and --group options. See https://github.com/Pylons/pyramid/pull/21…
Continue removal of pserve daemon/process management features by deprecating --user and --group options. See https://github.com/Pylons/pyramid/pull/2190
Remove the cachebust option from config.add_static_view. See config.add_cache_buster for the new way to attach cache busters to static assets. See htt
Remove the cachebust option from config.add_static_view. See config.add_cache_buster for the new way to attach cache busters to static assets. See https://github.com/Pylons/pyramid/pull/2186
Modify the pyramid.interfaces.ICacheBuster API to be a simple callable instead of an object with match and pregenerate methods. Cache busters are now focused solely on generation. Matching has been dropped.
Note this affects usage of pyramid.static.QueryStringCacheBuster and pyramid.static.ManifestCacheBuster.
Add a new config.add_cache_buster API for attaching cache busters to static assets. See https://github.com/Pylons/pyramid/pull/2186
Ensure that IAssetDescriptor.abspath always returns an absolute path. There were cases depending on the process CWD that a relative path would be returned. See https://github.com/Pylons/pyramid/pull/2188
Your coding agent can read these notes before it upgrades. Set up the MCP server →