paulb@68 | 1 | Introduction
|
paulb@68 | 2 | ------------
|
paulb@68 | 3 |
|
paulb@301 | 4 | WebStack is a package which provides a common API for Python Web
|
paulb@301 | 5 | applications, regardless of the underlying server or framework environment.
|
paulb@301 | 6 | It should be possible with WebStack to design and implement an application,
|
paulb@301 | 7 | to choose a deployment environment, and then to be able to deploy the
|
paulb@301 | 8 | application in a different environment later on without having to go back
|
paulb@301 | 9 | and rewrite substantial parts of the application.
|
paulb@60 | 10 |
|
paulb@362 | 11 | Quick Start
|
paulb@362 | 12 | -----------
|
paulb@362 | 13 |
|
paulb@362 | 14 | Try running the demo:
|
paulb@362 | 15 |
|
paulb@362 | 16 | python tools/demo.py
|
paulb@362 | 17 |
|
paulb@363 | 18 | An introductory guide to creating applications can be found in the docs
|
paulb@363 | 19 | directory - see docs/index.html for the start page.
|
paulb@363 | 20 |
|
paulb@363 | 21 | Contact, Copyright and Licence Information
|
paulb@363 | 22 | ------------------------------------------
|
paulb@363 | 23 |
|
paulb@363 | 24 | The current Web page for WebStack at the time of release is:
|
paulb@363 | 25 |
|
paulb@363 | 26 | http://www.boddie.org.uk/python/WebStack.html
|
paulb@363 | 27 |
|
paulb@363 | 28 | Copyright and licence information can be found in the docs directory - see
|
paulb@413 | 29 | docs/COPYING.txt, docs/LICENCE.txt and docs/LICENCE-PyServlet.txt for more
|
paulb@413 | 30 | information.
|
paulb@363 | 31 |
|
paulb@68 | 32 | Framework Support
|
paulb@68 | 33 | -----------------
|
paulb@68 | 34 |
|
paulb@218 | 35 | Currently, BaseHTTPRequestHandler (via BaseHTTPServer in the standard
|
paulb@301 | 36 | library), CGI, Jython/Java Servlet API, mod_python, Twisted, Webware, WSGI
|
paulb@301 | 37 | and Zope 2 are supported. Each framework has its own set of strengths and
|
paulb@301 | 38 | weaknesses, but the idea is that deployment concerns can be considered
|
paulb@301 | 39 | separately from the implementation of application functionality. Consult the
|
paulb@301 | 40 | NOTES.txt files in each framework's subdirectory of the docs directory for
|
paulb@301 | 41 | some notes on how applications may be run in each environment.
|
paulb@60 | 42 |
|
paulb@244 | 43 | Tested Frameworks Release Information
|
paulb@244 | 44 | ----------------- -------------------
|
paulb@68 | 45 |
|
paulb@362 | 46 | BaseHTTPRequestHandler Python 2.2.2, Python 2.3.3, Python 2.4.1
|
paulb@405 | 47 | CGI Apache 2.0.44, Apache 2.0.53, AOLserver 4.0.10, lighttpd 1.3.15
|
paulb@438 | 48 | Jython/Java Servlet API Jython 2.1, Java JDK 1.3.1_02, Tomcat 4.1.31 (Servlet 2.3)
|
paulb@244 | 49 | mod_python 3.0.3 (3.1.3 for framework cookie and session support)
|
paulb@308 | 50 | Twisted 1.0.5, 1.3.0
|
paulb@438 | 51 | Webware 0.8.1, CVS (2004-02-06), 0.9b2
|
paulb@304 | 52 | WSGI run_with_cgi (PEP 333)
|
paulb@388 | 53 | Zope 2.7.2-0, 2.8.0-final
|
paulb@388 | 54 |
|
paulb@495 | 55 | New in WebStack 1.1 (Changes since WebStack 1.0)
|
paulb@495 | 56 | ------------------------------------------------
|
paulb@492 | 57 |
|
paulb@495 | 58 | * Added a Repositories package to provide session-like support for
|
paulb@495 | 59 | different kinds of storage.
|
paulb@495 | 60 | * Added an explicit filesystem encoding to the Calendar example and adopted
|
paulb@495 | 61 | the DirectoryRepository from the Repositories package.
|
paulb@495 | 62 | * Added a values method to Helpers.Session.Wrapper.
|
paulb@492 | 63 | * Fixed the distribution names in the Ubuntu changelog.
|
paulb@492 | 64 |
|
paulb@409 | 65 | New in WebStack 1.0 (Changes since WebStack 0.10)
|
paulb@409 | 66 | -------------------------------------------------
|
paulb@409 | 67 |
|
paulb@474 | 68 | * Changed the behaviour of get_path, get_path_without_query, get_path_info,
|
paulb@474 | 69 | get_virtual_path_info, get_processed_virtual_path_info and
|
paulb@474 | 70 | get_fields_from_path to return Unicode data decoded using the optional
|
paulb@474 | 71 | encoding parameter or a common default encoding.
|
paulb@474 | 72 | * Fixed file upload values so that FileContent objects are returned for such
|
paulb@474 | 73 | fields in get_fields_from_body and get_fields.
|
paulb@474 | 74 | (Warning! Except for Twisted!)
|
paulb@474 | 75 | * Fixed the JavaServlet support so that streams and file content are
|
paulb@474 | 76 | obtained as "almost" plain strings.
|
paulb@474 | 77 | * Updated/fixed LoginResource and LoginRedirectResource to use the updated
|
paulb@474 | 78 | path API and to handle special characters properly.
|
paulb@474 | 79 | * Added convenience methods to Transaction for the decoding and encoding of
|
paulb@474 | 80 | path values (to and from Unicode objects) - see the decode_path and
|
paulb@474 | 81 | encode_path methods.
|
paulb@474 | 82 | * Added the notion of processed virtual path info - the part of the original
|
paulb@474 | 83 | path info not represented in the current virtual path info.
|
paulb@474 | 84 | * Added "pass through" behaviour to ResourceMap.MapResource (prompted by a
|
paulb@474 | 85 | patch from Scott Robinson).
|
paulb@474 | 86 | * Fixed ResourceMap.MapResource to handle non-existent resources properly
|
paulb@474 | 87 | (where the virtual path info is only one component in length).
|
paulb@474 | 88 | * Added Debian package support.
|
paulb@474 | 89 | * Added automatic session directory creation for the WebStack sessions
|
paulb@474 | 90 | implementation.
|
paulb@474 | 91 | * Added support for the repeated retrieval of sessions from the same
|
paulb@474 | 92 | WebStack session store, avoiding deadlocks.
|
paulb@474 | 93 | * Fixed the calendar example, making it perform a proper function.
|
paulb@474 | 94 | * Made the BaseHTTPRequestHandler and Twisted SimpleWithLogin applications
|
paulb@474 | 95 | include the Login application, since Konqueror (at least) does not share
|
paulb@474 | 96 | cookies across different port numbers on the same host.
|
paulb@474 | 97 | * Added the SimpleWithLogin and Login applications to the demonstration.
|
paulb@474 | 98 | * Improved the documentation, adding information on request headers, and
|
paulb@474 | 99 | describing file upload and session support limitations.
|
paulb@476 | 100 | * Improved the AOLserver-related notes for CGI and Webware, adding a patch
|
paulb@476 | 101 | for Webware in order to work around AOLserver issues.
|
paulb@409 | 102 |
|
paulb@388 | 103 | New in WebStack 0.10 (Changes since WebStack 0.9)
|
paulb@388 | 104 | -------------------------------------------------
|
paulb@388 | 105 |
|
paulb@474 | 106 | * Changes to make the tools/demo.py script work on Windows (and other)
|
paulb@474 | 107 | platforms (suggested by Jim Madsen).
|
paulb@474 | 108 | * Fixed end of header newlines for CGI (suggested by Matt Harrison).
|
paulb@474 | 109 | * Minor documentation fixes and improvements, adding information on
|
paulb@474 | 110 | AOLserver in the CGI and Webware notes.
|
paulb@474 | 111 | * Changed the mod_python server name method to use the server object rather
|
paulb@474 | 112 | than the connection object.
|
paulb@474 | 113 | * Added a parameter to the ResourceMap.MapResource class to permit automatic
|
paulb@474 | 114 | redirects into resource hierarchies when no trailing "/" was given in the
|
paulb@474 | 115 | URL; changed the updated virtual path info so that empty values may be set
|
paulb@474 | 116 | (the guarantee that "/" will always appear no longer applies).
|
paulb@474 | 117 | * Fixed virtual path info retrieval when the value is an empty string.
|
paulb@192 | 118 |
|
paulb@314 | 119 | New in WebStack 0.9 (Changes since WebStack 0.8)
|
paulb@314 | 120 | ------------------------------------------------
|
paulb@314 | 121 |
|
paulb@474 | 122 | * Standardised error handling in the adapters so that tracebacks can be
|
paulb@474 | 123 | suppressed and an internal server error condition raised.
|
paulb@474 | 124 | * Added overriding of path info in transactions.
|
paulb@474 | 125 | * Added a ResourceMap resource for dispatching to different resources
|
paulb@474 | 126 | according to path components.
|
paulb@474 | 127 | * Standardised deployment for some frameworks (see docs/deploying.html).
|
paulb@474 | 128 | * Introductory documentation in XHTML format.
|
paulb@474 | 129 | * Added server name and port methods to the transaction.
|
paulb@474 | 130 | * Added a simple demonstration application, incorporating many of the
|
paulb@474 | 131 | examples and launched under a single script.
|
paulb@474 | 132 | * Fixed mod_python native sessions.
|
paulb@474 | 133 | * Fixed Zope request stream access.
|
paulb@474 | 134 | * WebStack is now licensed under the LGPL - see docs/COPYING.txt for
|
paulb@474 | 135 | details.
|
paulb@314 | 136 |
|
paulb@300 | 137 | New in WebStack 0.8 (Changes since WebStack 0.7)
|
paulb@295 | 138 | ------------------------------------------------
|
paulb@295 | 139 |
|
paulb@474 | 140 | * Added a standard exception, EndOfResponse, which can be used to
|
paulb@474 | 141 | immediately stop the processing/production of a response; this is useful
|
paulb@474 | 142 | when resources need to issue a redirect without unnecessary content being
|
paulb@474 | 143 | generated, for example.
|
paulb@474 | 144 | * Fixed path information for Zope.
|
paulb@474 | 145 | * Added WSGI support.
|
paulb@474 | 146 | * Verified Twisted 1.3.0 support with Python 2.3.3.
|
paulb@295 | 147 |
|
paulb@300 | 148 | New in WebStack 0.7 (Changes since WebStack 0.6)
|
paulb@192 | 149 | ------------------------------------------------
|
paulb@192 | 150 |
|
paulb@474 | 151 | * Fixed path information semantics.
|
paulb@474 | 152 | * Fixed file upload semantics.
|
paulb@474 | 153 | * Fixed content type handling for Unicode output and for interpreting
|
paulb@474 | 154 | request body fields/parameters (although some improvement remains).
|
paulb@474 | 155 | * Added a method to discover the chosen response stream encoding.
|
paulb@474 | 156 | * Fixed field/parameter retrieval so that path and body fields are distinct,
|
paulb@474 | 157 | regardless of the framework employed.
|
paulb@474 | 158 | * Added a method to get a combination of path and body fields (suggested by
|
paulb@474 | 159 | Jacob Smullyan).
|
paulb@474 | 160 | * Introduced Zope 2 support.
|
paulb@474 | 161 | * Improved Jython/Java Servlet API support (although a special PyServlet
|
paulb@474 | 162 | class must now be used, and certain libraries must be deployed with
|
paulb@474 | 163 | applications).
|
paulb@474 | 164 | * Introduced authentication/authorisation support for Jython/Java Servlet
|
paulb@474 | 165 | API.
|
paulb@474 | 166 | * Session support has been added (except for Webware 0.8.1).
|
paulb@474 | 167 | * Alternative cookie support for mod_python has been added.
|
paulb@474 | 168 | * Cookie support now supports encoded Unicode sequences for names and
|
paulb@474 | 169 | values.
|
paulb@68 | 170 |
|
paulb@300 | 171 | New in WebStack 0.6 (Changes since WebStack 0.5)
|
paulb@178 | 172 | ------------------------------------------------
|
paulb@178 | 173 |
|
paulb@474 | 174 | * Introduced Jython/Java Servlet API support.
|
paulb@474 | 175 | * Minor fixes to example applications and to BaseHTTPRequestHandler.
|
paulb@178 | 176 |
|
paulb@300 | 177 | New in WebStack 0.5 (Changes since WebStack 0.4)
|
paulb@171 | 178 | ------------------------------------------------
|
paulb@171 | 179 |
|
paulb@474 | 180 | * Changed request body fields/parameters so that they are now represented
|
paulb@474 | 181 | using Unicode objects rather than plain strings.
|
paulb@474 | 182 | * Introduced better support for Unicode in response streams.
|
paulb@171 | 183 |
|
paulb@300 | 184 | New in WebStack 0.4 (Changes since WebStack 0.3)
|
paulb@160 | 185 | ------------------------------------------------
|
paulb@140 | 186 |
|
paulb@474 | 187 | * Added application definition of user identity, permitting alternative
|
paulb@474 | 188 | authentication mechanisms.
|
paulb@474 | 189 | * Improved BaseHTTPRequestHandler and mod_python reliability around fields
|
paulb@474 | 190 | from request bodies.
|
paulb@474 | 191 | * Provided stream and environment parameterisation in the CGI adapter.
|
paulb@474 | 192 | * Added LoginRedirect and Login examples.
|
paulb@474 | 193 | * Added get_path_without_query and fixed get_path behaviour.
|
paulb@140 | 194 |
|
paulb@300 | 195 | New in WebStack 0.3 (Changes since WebStack 0.2)
|
paulb@160 | 196 | ------------------------------------------------
|
paulb@120 | 197 |
|
paulb@474 | 198 | * Added better header support for Webware (suggested by Ian Bicking).
|
paulb@474 | 199 | * Introduced CGI and Java Servlet support (the latter is currently
|
paulb@474 | 200 | broken/unfinished).
|
paulb@474 | 201 | * Introduced support for cookies.
|
paulb@120 | 202 |
|
paulb@68 | 203 | Future Work
|
paulb@68 | 204 | -----------
|
paulb@68 | 205 |
|
paulb@308 | 206 | (Essential)
|
paulb@308 | 207 |
|
paulb@460 | 208 | Twisted 1.3.0 does not provide file upload metadata, and Twisted Web 0.5.0
|
paulb@460 | 209 | also seems to be missing this functionality. It isn't obvious whether Twisted
|
paulb@460 | 210 | Web2 will just copy its predecessors and provide a similarly limited API.
|
paulb@460 | 211 | Perhaps the Twisted support needs to resemble the CGI support much more when
|
paulb@460 | 212 | handling fields.
|
paulb@460 | 213 |
|
paulb@308 | 214 | JythonServlet libraries need to be configured using sys.add_package when
|
paulb@308 | 215 | these do not feature in the compiled-in list. Adding such configuration to
|
paulb@308 | 216 | the handler may be most appropriate (since the web.xml file can be too
|
paulb@308 | 217 | arcane), but this needs testing.
|
paulb@308 | 218 |
|
paulb@308 | 219 | (Important)
|
paulb@308 | 220 |
|
paulb@165 | 221 | Things to consider for future releases: improved cookie support, redirects,
|
paulb@218 | 222 | access to shared resources and much better documentation.
|
paulb@68 | 223 |
|
paulb@363 | 224 | Field access needs testing, especially for anything using the
|
paulb@363 | 225 | cgi.FieldStorage class, and the way file uploads are exposed should be
|
paulb@363 | 226 | reviewed (currently the meta-data is not exposed). The acquisition of fields
|
paulb@363 | 227 | from specific sources should be tested with different request methods - some
|
paulb@363 | 228 | frameworks provide path fields in the body fields dictionary, others (eg.
|
paulb@363 | 229 | Zope) change the fields exposed depending on request method.
|
paulb@248 | 230 |
|
paulb@363 | 231 | Interpretation of path field encodings needs to be verified. Currently,
|
paulb@363 | 232 | stray path fields are handled (eg. in WebStack.Helpers.Request) as being
|
paulb@363 | 233 | ISO-8859-1, but it might be the case that some such fields might be
|
paulb@438 | 234 | submitted as UTF-8. The decode_path method on Transaction does do much of the
|
paulb@460 | 235 | work that is likely to be required, however. Still, a good policy for decoding
|
paulb@460 | 236 | path fields, reducing the number of times one might specify the encoding in
|
paulb@460 | 237 | various method calls, may be important.
|
paulb@438 | 238 |
|
paulb@438 | 239 | An interesting test of encodings is to introduce things like the following to
|
paulb@438 | 240 | the path info and query string sections of the URL: %25F0?%E6=%F8&%25F0=%F8
|
paulb@438 | 241 | This should produce the following decoded result: %F0?æ=ø&%F0=ø
|
paulb@438 | 242 | (The above needs to be read in ISO-8859-1 or ISO-8859-15.)
|
paulb@102 | 243 |
|
paulb@102 | 244 | Cookie objects need defining strictly, especially since the standard library
|
paulb@363 | 245 | Cookie object behaves differently to mod_python (and possibly Webware)
|
paulb@363 | 246 | Cookie objects. Moreover, the set_cookie_value method needs to provide
|
paulb@363 | 247 | access to the usual cookie parameters as supported by the frameworks. The
|
paulb@363 | 248 | standard library Cookie module has issues with Unicode cookie names (and
|
paulb@363 | 249 | possibly values) - this is worked around, but it would be best to resolve
|
paulb@363 | 250 | this comprehensively.
|
paulb@90 | 251 |
|
paulb@363 | 252 | UTF-16 (and possibly other encodings) causes problems with HTML form data
|
paulb@363 | 253 | sent in POST requests using the application/x-www-form-urlencoded content
|
paulb@363 | 254 | type. This should be reviewed at a later date when proper standardisation
|
paulb@363 | 255 | has taken place.
|
paulb@218 | 256 |
|
paulb@239 | 257 | Session support, especially through WebStack.Helpers.Session, should be
|
paulb@248 | 258 | reviewed and be made compatible with non-cookie mechanisms.
|
paulb@248 | 259 |
|
paulb@248 | 260 | HeaderValue objects should be employed more extensively. Thus, the header
|
paulb@469 | 261 | access methods may need to change their behaviour slightly. The get_headers
|
paulb@469 | 262 | method should potentially return a list for each item in the dictionary.
|
paulb@248 | 263 |
|
paulb@304 | 264 | WSGI support could demand that a special "end of headers" method be
|
paulb@304 | 265 | introduced into WebStack, thus making response output more efficient (and
|
paulb@304 | 266 | probably also for other frameworks, too).
|
paulb@304 | 267 |
|
paulb@363 | 268 | The algorithm employed in the WebStack.Helpers.Auth.get_token function
|
paulb@363 | 269 | should be reviewed and improved for better security.
|
paulb@332 | 270 |
|
paulb@336 | 271 | Investigate proper support for HEAD, OPTIONS and other request methods.
|
paulb@336 | 272 |
|
paulb@438 | 273 | Consider packages for different operating systems (other than Debian).
|
paulb@365 | 274 |
|
paulb@460 | 275 | Provide some 500 error content when handle_errors is true.
|
paulb@460 | 276 |
|
paulb@355 | 277 | (Completed/rejected)
|
paulb@355 | 278 |
|
paulb@355 | 279 | The location of deployed applications in the filesystem should be exposed to
|
paulb@355 | 280 | those applications. (This is actually available in the __file__ module
|
paulb@355 | 281 | variable.)
|
paulb@355 | 282 |
|
paulb@355 | 283 | Path information should be consistent across all frameworks, and the "path
|
paulb@355 | 284 | info" value should be meaningful. (This should now be correct.)
|
paulb@355 | 285 |
|
paulb@460 | 286 | Investigate the nicer functions in the cgi module, discarding the "magic"
|
paulb@460 | 287 | stuff like FieldStorage. (These nicer functions are used by projects like
|
paulb@460 | 288 | Twisted - as of 1.3.0 at least - and do not give the necessary information we
|
paulb@460 | 289 | require.)
|
paulb@460 | 290 |
|
paulb@159 | 291 | Release Procedures
|
paulb@159 | 292 | ------------------
|
paulb@159 | 293 |
|
paulb@159 | 294 | Update the WebStack/__init__.py __version__ attribute.
|
paulb@329 | 295 | Change the version number and package filename/directory in the documentation.
|
paulb@332 | 296 | Change code examples in the documentation if appropriate.
|
paulb@159 | 297 | Update the release notes (see above).
|
paulb@159 | 298 | Check the setup.py file and ensure that all package directories are mentioned.
|
paulb@417 | 299 | Check the release information in the PKG-INFO file and in the package
|
paulb@417 | 300 | changelog (and other files).
|
paulb@253 | 301 | Tag, export.
|
paulb@247 | 302 | Generate the PyServlet classes.
|
paulb@355 | 303 | Generate the API documentation.
|
paulb@384 | 304 | Remove generated .pyc files: rm `find . -name "*.pyc"`
|
paulb@253 | 305 | Archive, upload.
|
paulb@367 | 306 | Upload the introductory documentation.
|
paulb@365 | 307 | Update PyPI, PythonInfo Wiki, Vaults of Parnassus entries.
|
paulb@355 | 308 |
|
paulb@355 | 309 | Generating the API Documentation
|
paulb@355 | 310 | --------------------------------
|
paulb@355 | 311 |
|
paulb@363 | 312 | In order to prepare the API documentation, it is necessary to generate some
|
paulb@363 | 313 | Web pages from the Python source code. For this, the epydoc application must
|
paulb@475 | 314 | be available on your system. Then, inside the distribution directory, run the
|
paulb@355 | 315 | apidocs.sh tool script as follows:
|
paulb@355 | 316 |
|
paulb@355 | 317 | ./tools/apidocs.sh
|
paulb@355 | 318 |
|
paulb@355 | 319 | Some warnings may be generated by the script, but the result should be a new
|
paulb@475 | 320 | apidocs directory within the distribution directory.
|
paulb@472 | 321 |
|
paulb@472 | 322 | Making Packages
|
paulb@472 | 323 | ---------------
|
paulb@472 | 324 |
|
paulb@485 | 325 | To make Debian-based packages:
|
paulb@472 | 326 |
|
paulb@485 | 327 | 1. Create new package directories under packages if necessary.
|
paulb@474 | 328 | 2. Make a symbolic link in the distribution's root directory to keep the
|
paulb@474 | 329 | Debian tools happy:
|
paulb@472 | 330 |
|
paulb@485 | 331 | ln -s packages/ubuntu-hoary/python2.4-webstack/debian/
|
paulb@472 | 332 |
|
paulb@474 | 333 | 3. Run the package builder:
|
paulb@472 | 334 |
|
paulb@474 | 335 | dpkg-buildpackage -rfakeroot
|
paulb@472 | 336 |
|
paulb@474 | 337 | 4. Locate and tidy up the packages in the parent directory of the
|
paulb@474 | 338 | distribution's root directory.
|