Is that backwards?
672 karma · joined August 2, 2011
Is that backwards?
Python/Django Software Engineers
YOU: You are passionate about open source and like to try new technologies. You do not necessarily come from a traditional computer science background, but you have achieved mastery and you are particularly well suited to engineering. You are a self-starter and learn easily. You would like to get paid to write open source software.
US: Fusionbox offers custom software development solutions to a wide range of clients using new technologies. Fusionbox is a place for talented people who are serious about engineering. We are committed to the open source community (https://github.com/fusionbox) and Pythonic sensibility.
Your tests aren't a shell script, but certainly you can compile and run your tests from a shell script.
Basically, we made a really good content editor and wanted to get running quickly, so put our content editor in a Mezzanine page type. However, Widgy is a generic tree editor so potentially could be used for the page tree too.
- With plain HTTP, the attacker would have to be in a MITM position to intercept traffic. With Heartblead, he can read traffic he wouldn't normally have access to from the server's memory.
- There may be secrets in memory that would never even be sent over the network that are now accessible. For example, if running a web app in the same process doing SSL termination, private keys such as Django's SECRET_KEY may be available. Under certain situations, knowledge of the SECRET_KEY can effect remote code execution.
In short, Heartbleed gives the entire world the ability to read memory from your server. This is much worse than an HTTP MITM.
The JSON support in postgres allows a hybrid approach. Put the common data in a tabular format, with a JSON column that stores all the extra, variable data.
How can self-XSS be prevented with a CSRF token? Can't the script included via self-XSS get the token out of the page and use it to make requests that appear as if they originate from the app itself? Can't a script injected through self-XSS do absolutely anything the page can do in the first place?
ALTER TABLE foo ADD CONSTRAINT temporal_pk EXCLUDE USING GIST (
identity_id WITH =,
valid_range WITH &&
);
It'd be nice if temporal foreign keys were supported too, where the existence of contiguous child rows through the valid_range of the parent was enforced, but I've had to use a trigger for that.[1]: http://www.postgresql.org/docs/9.3/static/rangetypes.html [2]: http://www.postgresql.org/docs/9.3/static/ddl-constraints.ht...
Not in C. Dereferencing a NULL pointer is undefined behavior, so any of the actions described by the parent would be correct.
> Model.objects.annotate(Count('foos')).filter(foos__lt=10)
The only reason this doesn't work is because the property annotate creates isn't called `foos` by default. You just need to do this: Model.objects.annotate(foos=Count('foos')).filter(foos__lt=10)
and Django now knows to add a `HAVING COUNT(foos) < 10` clause.Even if you don't use South's automatic migration generation, its database-independent schema modification api [1], dependency tracking, and tracking of which migrations have been run, are useful and necessary. In fact, the automatic generation of migrations is an optional feature of South that was not in it when first released.
When you need to write SQL and interact with your database directly, using `db.execute` inside a South migration is a nice way to do it.
[1]: http://south.readthedocs.org/en/latest/databaseapi.html
import freezegun; freezegun.monkey_patch()
from datetime import datetime
After that, freeze_time would just set a flag on your datetime class.