User 1 uploads a file User 2 downloads it, and caches it User 1 uploads a new file to the same URL, with the same MD5 hash User 2 will keep using the old file indefinitely
Sure, user 1 has to upload two files with the same hash on purpose On Thu, Sep 10, 2020 at 11:07 AM Adam Johnson <m...@adamj.eu> wrote: > What would this protect against? > > On Thu, 10 Sep 2020 at 03:56, Francisco Couzo <francisco...@gmail.com> > wrote: > >> I think it would be a good idea to make ConditionalGetMiddleware use a >> hash function that's not as easy to find a collision as MD5, most probably >> SHA-256 or BLAKE2. >> I don't see a problem with just changing it, it will just invalidate the >> old cache. >> If there's an agreement on changing the hash function, I can make the PR. >> >> >> >> >> >> >> >> >> >> -- >> >> >> You received this message because you are subscribed to the Google Groups >> "Django developers (Contributions to Django itself)" group. >> >> >> To unsubscribe from this group and stop receiving emails from it, send an >> email to django-developers+unsubscr...@googlegroups.com. >> >> >> To view this discussion on the web visit >> https://groups.google.com/d/msgid/django-developers/ff591d46-97fc-43d6-9d1c-d0ba24d7b1a8n%40googlegroups.com >> <https://groups.google.com/d/msgid/django-developers/ff591d46-97fc-43d6-9d1c-d0ba24d7b1a8n%40googlegroups.com?utm_medium=email&utm_source=footer> >> . >> >> >> -- > Adam > > -- > You received this message because you are subscribed to the Google Groups > "Django developers (Contributions to Django itself)" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to django-developers+unsubscr...@googlegroups.com. > To view this discussion on the web visit > https://groups.google.com/d/msgid/django-developers/CAMyDDM1Db5tRDNXQEMLuX6UdOmjhUq0_-Dr_9kK%3DB5AUqsXG%2Bg%40mail.gmail.com > <https://groups.google.com/d/msgid/django-developers/CAMyDDM1Db5tRDNXQEMLuX6UdOmjhUq0_-Dr_9kK%3DB5AUqsXG%2Bg%40mail.gmail.com?utm_medium=email&utm_source=footer> > . > -- You received this message because you are subscribed to the Google Groups "Django developers (Contributions to Django itself)" group. To unsubscribe from this group and stop receiving emails from it, send an email to django-developers+unsubscr...@googlegroups.com. To view this discussion on the web visit https://groups.google.com/d/msgid/django-developers/CAHx8S1vpoP9txnZrV4fTfwRJBCF2q-QtjnYpw%2BwAgGKbg4V5yQ%40mail.gmail.com.