<feed xmlns='http://www.w3.org/2005/Atom'>
<title>django.git/tests/regressiontests/admin_views/tests.py, branch stable/1.3.x</title>
<subtitle>django
</subtitle>
<id>http://cgit.adnoto.dev/django.git/atom?h=stable%2F1.3.x</id>
<link rel='self' href='http://cgit.adnoto.dev/django.git/atom?h=stable%2F1.3.x'/>
<link rel='alternate' type='text/html' href='http://cgit.adnoto.dev/django.git/'/>
<updated>2013-02-12T11:13:42Z</updated>
<entry>
<title>[1.3.x] Checked object permissions on admin history view.</title>
<updated>2013-02-12T11:13:42Z</updated>
<author>
<name>Carl Meyer</name>
<email>carl@oddbird.net</email>
</author>
<published>2013-02-04T23:57:59Z</published>
<link rel='alternate' type='text/html' href='http://cgit.adnoto.dev/django.git/commit/?id=d3a45e10c8ac8268899999129daa27652ec0da35'/>
<id>urn:sha1:d3a45e10c8ac8268899999129daa27652ec0da35</id>
<content type='text'>
This is a security fix. Disclosure and advisory coming shortly.

Patch by Russell Keith-Magee.
</content>
</entry>
<entry>
<title>[1.3.X] Reverting r16878 (improved admin error message) per advice from jezdez. refs #16837</title>
<updated>2011-09-22T22:55:47Z</updated>
<author>
<name>Paul McMillan</name>
<email>Paul@McMillan.ws</email>
</author>
<published>2011-09-22T22:55:47Z</published>
<link rel='alternate' type='text/html' href='http://cgit.adnoto.dev/django.git/commit/?id=e3bc2590816b684bc44ce8516b3786a5027cc384'/>
<id>urn:sha1:e3bc2590816b684bc44ce8516b3786a5027cc384</id>
<content type='text'>
git-svn-id: http://code.djangoproject.com/svn/django/branches/releases/1.3.X@16891 bcc190cf-cafb-0310-a4f2-bffc1f526a37
</content>
</entry>
<entry>
<title>[1.3.X] Fixed #16837 -- Improved error messages for admin login. Thanks Wim Feijen for the patch.</title>
<updated>2011-09-22T05:36:57Z</updated>
<author>
<name>Paul McMillan</name>
<email>Paul@McMillan.ws</email>
</author>
<published>2011-09-22T05:36:57Z</published>
<link rel='alternate' type='text/html' href='http://cgit.adnoto.dev/django.git/commit/?id=2a4aa8bcf7be28bac9d5ed6a029c2c3f52f389e7'/>
<id>urn:sha1:2a4aa8bcf7be28bac9d5ed6a029c2c3f52f389e7</id>
<content type='text'>
git-svn-id: http://code.djangoproject.com/svn/django/branches/releases/1.3.X@16878 bcc190cf-cafb-0310-a4f2-bffc1f526a37
</content>
</entry>
<entry>
<title>Fixed a number of tests that were failing in Oracle due to false assumptions about the primary keys of objects.</title>
<updated>2011-03-09T00:39:35Z</updated>
<author>
<name>Ian Kelly</name>
<email>ian.g.kelly@gmail.com</email>
</author>
<published>2011-03-09T00:39:35Z</published>
<link rel='alternate' type='text/html' href='http://cgit.adnoto.dev/django.git/commit/?id=9e637d3061bfd620be3e2bb6a79e2d8d08154f91'/>
<id>urn:sha1:9e637d3061bfd620be3e2bb6a79e2d8d08154f91</id>
<content type='text'>
git-svn-id: http://code.djangoproject.com/svn/django/trunk@15779 bcc190cf-cafb-0310-a4f2-bffc1f526a37
</content>
</entry>
<entry>
<title>Updated test assertions that have been deprecated by the move to unittest2. In summary, this means:</title>
<updated>2011-03-03T15:04:39Z</updated>
<author>
<name>Russell Keith-Magee</name>
<email>russell@keith-magee.com</email>
</author>
<published>2011-03-03T15:04:39Z</published>
<link rel='alternate' type='text/html' href='http://cgit.adnoto.dev/django.git/commit/?id=afd040d4d3a06fe92e3080870b2ff2095ce86a75'/>
<id>urn:sha1:afd040d4d3a06fe92e3080870b2ff2095ce86a75</id>
<content type='text'>
 assert_ -&gt; assertTrue
 assertEquals -&gt; assertEqual
 failUnless -&gt; assertTrue

For full details, see http://www.voidspace.org.uk/python/articles/unittest2.shtml#deprecations

git-svn-id: http://code.djangoproject.com/svn/django/trunk@15728 bcc190cf-cafb-0310-a4f2-bffc1f526a37
</content>
</entry>
<entry>
<title>Fixed #12475 -- Fixed an edge case with hidden fields in ModelAdmin changelists when used in conjunction with list_display_links or list_editable. Thanks, Simon Meers, Julien Phalip, Karen and master.</title>
<updated>2011-03-03T13:20:45Z</updated>
<author>
<name>Jannis Leidel</name>
<email>jannis@leidel.info</email>
</author>
<published>2011-03-03T13:20:45Z</published>
<link rel='alternate' type='text/html' href='http://cgit.adnoto.dev/django.git/commit/?id=b921f1bac090cecd87e0b99b4c7c2d7581bcf2da'/>
<id>urn:sha1:b921f1bac090cecd87e0b99b4c7c2d7581bcf2da</id>
<content type='text'>
git-svn-id: http://code.djangoproject.com/svn/django/trunk@15722 bcc190cf-cafb-0310-a4f2-bffc1f526a37
</content>
</entry>
<entry>
<title>Fixed #15517 -- Fixed regression in admin search_fields option introduced in r15526. Thanks Fabian Buechler for the report and fix and Julien Phalip for adding tests.</title>
<updated>2011-03-01T02:04:35Z</updated>
<author>
<name>Ramiro Morales</name>
<email>cramm0@gmail.com</email>
</author>
<published>2011-03-01T02:04:35Z</published>
<link rel='alternate' type='text/html' href='http://cgit.adnoto.dev/django.git/commit/?id=bd3b5e8c2b36633134ab63e5a6af7b5f5839a7c4'/>
<id>urn:sha1:bd3b5e8c2b36633134ab63e5a6af7b5f5839a7c4</id>
<content type='text'>
git-svn-id: http://code.djangoproject.com/svn/django/trunk@15677 bcc190cf-cafb-0310-a4f2-bffc1f526a37
</content>
</entry>
<entry>
<title>Fixed #10918 -- Ensure that the search widget on a raw_id_admin uses the right field name when the ForeignKey has a to_field definition. Thanks to David Cramer for the report, Collin Anderson for the fix, and Julien Phalip for the test.</title>
<updated>2011-02-26T12:44:25Z</updated>
<author>
<name>Russell Keith-Magee</name>
<email>russell@keith-magee.com</email>
</author>
<published>2011-02-26T12:44:25Z</published>
<link rel='alternate' type='text/html' href='http://cgit.adnoto.dev/django.git/commit/?id=b5b5ba6cd9179372cead3e6d19f732285e80b799'/>
<id>urn:sha1:b5b5ba6cd9179372cead3e6d19f732285e80b799</id>
<content type='text'>
git-svn-id: http://code.djangoproject.com/svn/django/trunk@15657 bcc190cf-cafb-0310-a4f2-bffc1f526a37
</content>
</entry>
<entry>
<title>Prevented non-admin users from accessing the admin redirect shortcut.</title>
<updated>2011-02-24T13:34:51Z</updated>
<author>
<name>Jacob Kaplan-Moss</name>
<email>jacob@jacobian.org</email>
</author>
<published>2011-02-24T13:34:51Z</published>
<link rel='alternate' type='text/html' href='http://cgit.adnoto.dev/django.git/commit/?id=174d8db57caf56e845aee54c02b57c14b777f892'/>
<id>urn:sha1:174d8db57caf56e845aee54c02b57c14b777f892</id>
<content type='text'>
If the admin shortcut view (e.g. /admin/r/&lt;content-type&gt;/&lt;pk&gt;/) is
publically-accessible, and if a public users can guess a content-type ID
(which isn't hard given that they're sequential), then the redirect view could
possibly leak data by redirecting to pages a user shouldn't "know about." So
the redirect view needs the same protection as the rest of the admin site.

Thanks to Jason Royes for pointing this out.

git-svn-id: http://code.djangoproject.com/svn/django/trunk@15639 bcc190cf-cafb-0310-a4f2-bffc1f526a37
</content>
</entry>
<entry>
<title>Fixed #14012 (again) -- Admin app: Don't show the full user edition view after adding a user in a FK popup. Thanks dburke for reporting this regression introduced in r14628.</title>
<updated>2011-02-24T01:00:57Z</updated>
<author>
<name>Ramiro Morales</name>
<email>cramm0@gmail.com</email>
</author>
<published>2011-02-24T01:00:57Z</published>
<link rel='alternate' type='text/html' href='http://cgit.adnoto.dev/django.git/commit/?id=4b13e76debbb64818559b504a2dd043af5fcad33'/>
<id>urn:sha1:4b13e76debbb64818559b504a2dd043af5fcad33</id>
<content type='text'>
git-svn-id: http://code.djangoproject.com/svn/django/trunk@15637 bcc190cf-cafb-0310-a4f2-bffc1f526a37
</content>
</entry>
</feed>
