* Passing ``secure=False`` or ``httponly=False`` to
`.RequestHandler.set_cookie` now works as expected (previously only the
presence of the argument was considered and its value was ignored).
+ * Parsing of the ``If-None-Match`` header now follows the RFC and supports
+ weak validators.
+ * `.RequestHandler.get_arguments` now requires that its ``strip`` argument
+ be of type bool. This helps prevent errors caused by the slightly dissimilar
+ interfaces between the singular and plural methods.
+ * Errors raised in ``_handle_request_exception`` are now logged more reliably.
+ * `.RequestHandler.redirect` now works correctly when called from a handler
+ whose path begins with two slashes.
+ * Passing messages containing ``%`` characters to `tornado.web.HTTPError`
+ no longer causes broken error messages.
+* Key versioning support for cookie signing. ``cookie_secret`` application
+ setting can now contain a dict of valid keys with version as key. The
+ current signing key then must be specified via ``key_version`` setting.
`tornado.websocket`
~~~~~~~~~~~~~~~~~~~