OpenStack Identity Authentication Library
Go to file
Luong Anh Tuan 7e11cab57b Replace yaml.load() with yaml.safe_load()
Avoid dangerous file parsing and object serialization libraries.
yaml.load is the obvious function to use but it is dangerous[1]
Because yaml.load return Python object may be dangerous if you
receive a YAML document from an untrusted source such as the
Internet. The function yaml.safe_load limits this ability to
simple Python objects like integers or lists.

In addition, Bandit flags yaml.load() as security risk so replace
all occurrences with yaml.safe_load(). Thus I replace yaml.load()
with yaml.safe_load()

[1]https://security.openstack.org/guidelines/dg_avoid-dangerous-input-parsing-libraries.html

Change-Id: Ia45006ce1382022e5c776d06fdc3c33e9b4d8c47
Closes-Bug: #1634265
2017-01-16 15:34:40 +07:00
doc Add a full listing of all auth plugins and there options 2017-01-10 14:40:28 +00:00
keystoneauth1 Replace yaml.load() with yaml.safe_load() 2017-01-16 15:34:40 +07:00
releasenotes Only log application/json in session to start 2017-01-10 05:45:13 +00:00
tools Add Constraints support 2016-12-21 11:24:09 +11:00
.coveragerc Update coverage to keystoneauth1 2015-12-09 11:46:00 +11:00
.gitignore Add release notes for keystoneauth 2015-11-29 20:05:16 -05:00
.gitreview Initial Split of python-keystoneclient to keystoneauth 2015-04-20 14:49:59 -07:00
.mailmap Add mailmap entry 2014-05-07 12:12:43 -07:00
.testr.conf Move to the keystoneauth1 namespace 2015-06-25 16:48:54 -07:00
CONTRIBUTING.rst Initial Split of python-keystoneclient to keystoneauth 2015-04-20 14:49:59 -07:00
HACKING.rst Initial Split of python-keystoneclient to keystoneauth 2015-04-20 14:49:59 -07:00
LICENSE Initial Split of python-keystoneclient to keystoneauth 2015-04-20 14:49:59 -07:00
README.rst Show team and repo badges on README 2016-11-25 16:43:03 +01:00
requirements.txt Updated from global requirements 2016-12-02 05:06:05 +00:00
setup.cfg Remove references to Python 3.4 2017-01-05 15:27:51 -08:00
setup.py Updated from global requirements 2015-09-17 12:12:42 +00:00
test-requirements.txt Remove discover from test-requirements 2016-12-15 08:48:10 +01:00
tox.ini Remove references to Python 3.4 2017-01-05 15:27:51 -08:00

README.rst

Team and repository tags

image

keystoneauth

Latest Version

Downloads

This package contains tools for authenticating to an OpenStack-based cloud. These tools include:

  • Authentication plugins (password, token, and federation based)
  • Discovery mechanisms to determine API version support
  • A session that is used to maintain client settings across requests (based on the requests Python library)

Further information: