Skip to content

Conversation

@jayaddison
Copy link
Contributor

Backports the fix for GHSA-4grg-w6v8-c28g from flask to quart.

@jayaddison

This comment has been minimized.

The `itsdangerous` serializer interface[1] expects keys to be
provided with the oldest key at index zero and the active signing key
at the end of the list.

[1] - https://itsdangerous.palletsprojects.com/en/stable/serializer/#itsdangerous.serializer.Serializer

(cherry picked from commit pallets/flask@fb54159)

Conflicts:
	CHANGES.rst
	src/flask/sessions.py
	tests/test_basic.py
@davidism davidism modified the milestones: 0.20.0, 0.20.1 Jul 29, 2025
@davidism davidism merged commit 8a0e4c4 into pallets:main Jul 29, 2025
10 checks passed
@jayaddison
Copy link
Contributor Author

Thanks again @davidism! And my apologies for yet again opening this from an organization account :|

@jayaddison jayaddison deleted the flask-backports/GHSA-4grg-w6v8-c28g branch July 29, 2025 17:45
@github-actions github-actions bot locked as resolved and limited conversation to collaborators Aug 13, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants