Django 1.8.2 security release patches unusually dangerous bug – update ASAP
djangoproject.com
djangoproject.com
data SessionKey = ValidSessionKey | InvalidSessionKey
Then the developer making the modification code would have been much less likely to type "InvalidSessionKey" whereas the None/"" behavior is just an idiom. The problem here is that the domain knowledge of: "" is a valid sessionwasn't communicated by the code.