aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
-rw-r--r--debian/changelog4
-rw-r--r--debian/patches/05_do-not-ascribe-cookies-to-the-target-domain.patch17
-rw-r--r--debian/patches/series1
3 files changed, 3 insertions, 19 deletions
diff --git a/debian/changelog b/debian/changelog
index e114d5c..05090d6 100644
--- a/debian/changelog
+++ b/debian/changelog
@@ -9,11 +9,13 @@ requests (2.7.0-1) UNRELEASED; urgency=medium
- Refresh.
* debian/patches/04_make-requests.packages.urllib3-same-as-urllib3.patch
- Refresh.
+ * debian/patches/05_do-not-ascribe-cookies-to-the-target-domain.patch
+ - Remove since fixed upstream.
* debian/python{,3}-requests.links
- Remove links thanks to the import machinery in
04_make-requests.packages.urllib3-same-as-urllib3.patch
- -- Daniele Tricoli <eriol@mornie.org> Sun, 03 May 2015 21:22:49 +0200
+ -- Daniele Tricoli <eriol@mornie.org> Sun, 03 May 2015 21:30:10 +0200
requests (2.4.3-6) unstable; urgency=medium
diff --git a/debian/patches/05_do-not-ascribe-cookies-to-the-target-domain.patch b/debian/patches/05_do-not-ascribe-cookies-to-the-target-domain.patch
deleted file mode 100644
index 3dd3bba..0000000
--- a/debian/patches/05_do-not-ascribe-cookies-to-the-target-domain.patch
+++ /dev/null
@@ -1,17 +0,0 @@
-Description: Session fixation and cookie stealing.
- See http://www.openwall.com/lists/oss-security/2015/03/14/4 for a complete
- description.
-Origin: https://github.com/kennethreitz/requests/commit/3bd8afbff29e50b38f889b2f688785a669b9aafc
-Bug-Debian: https://bugs.debian.org/780506
-
---- a/requests/sessions.py
-+++ b/requests/sessions.py
-@@ -168,7 +168,7 @@
- except KeyError:
- pass
-
-- extract_cookies_to_jar(prepared_request._cookies, prepared_request, resp.raw)
-+ extract_cookies_to_jar(prepared_request._cookies, req, resp.raw)
- prepared_request._cookies.update(self.cookies)
- prepared_request.prepare_cookies(prepared_request._cookies)
-
diff --git a/debian/patches/series b/debian/patches/series
index bcd27f4..38fffac 100644
--- a/debian/patches/series
+++ b/debian/patches/series
@@ -2,4 +2,3 @@
02_use-system-chardet-and-urllib3.patch
03_export-IncompleteRead.patch
04_make-requests.packages.urllib3-same-as-urllib3.patch
-05_do-not-ascribe-cookies-to-the-target-domain.patch