http://groups.google.com/group/webpy/browse_frm/thread/2fcbcb60a99a1c79/
Aaron's mistake is at post #4, my response is post #5.
Yeah, that's from a while ago. That's about when I stopped using web.py, too.
http://groups.google.com/group/webpy/browse_frm/thread/2fcbcb60a99a1c79/
Aaron's mistake is at post #4, my response is post #5.
Yeah, that's from a while ago. That's about when I stopped using web.py, too.
\But\ from the beginning, everyone using webpy has seem to know flup sessions to be the recommended way of doing sessions:
http://webpy.org/track/wiki/SessionsWithFlup
Let's look at this another way though. If you really need security, then which is better: a simple, quickly verifiable codebase like webpy, or a massive, magical code base like django and turbogears? Do any frameworks make any guarentees of security?
I have seen several high profile sites within the last two years with major, obvious security problems. As hard as this is to believe, I no longer think that security is what will determine the success of most any web app -- at all. Unless you have special needs, feelings of security should not be your primary metric in evaluating a framework.