summaryrefslogtreecommitdiff
path: root/docs/ref/models
diff options
context:
space:
mode:
authorRussell Keith-Magee <russell@keith-magee.com>2011-09-10 00:47:00 +0000
committerRussell Keith-Magee <russell@keith-magee.com>2011-09-10 00:47:00 +0000
commit5f287f75f2277ba821dcf5c444ab12d8eff6cce3 (patch)
treef665fe5b63d6969753ba90080728fc23bd767279 /docs/ref/models
parent33076af6f2aa5285b3a70246e14163b901b512f7 (diff)
Altered the behavior of URLField to avoid a potential DOS vector, and to avoid potential leakage of local filesystem data. A security announcement will be made shortly.
git-svn-id: http://code.djangoproject.com/svn/django/trunk@16760 bcc190cf-cafb-0310-a4f2-bffc1f526a37
Diffstat (limited to 'docs/ref/models')
-rw-r--r--docs/ref/models/fields.txt13
1 files changed, 10 insertions, 3 deletions
diff --git a/docs/ref/models/fields.txt b/docs/ref/models/fields.txt
index 9a40a67439..8b5c0db7f5 100644
--- a/docs/ref/models/fields.txt
+++ b/docs/ref/models/fields.txt
@@ -872,14 +872,21 @@ shortcuts.
``URLField``
------------
-.. class:: URLField([verify_exists=True, max_length=200, **options])
+.. class:: URLField([verify_exists=False, max_length=200, **options])
A :class:`CharField` for a URL. Has one extra optional argument:
+.. deprecated:: 1.3.1
+
+ ``verify_exists`` is deprecated for security reasons as of 1.3.1
+ and will be removed in 1.4. Prior to 1.3.1, the default value was
+ ``True``.
+
.. attribute:: URLField.verify_exists
- If ``True`` (the default), the URL given will be checked for existence
- (i.e., the URL actually loads and doesn't give a 404 response).
+ If ``True``, the URL given will be checked for existence (i.e.,
+ the URL actually loads and doesn't give a 404 response) using a
+ ``HEAD`` request. Redirects are allowed, but will not be followed.
Note that when you're using the single-threaded development server,
validating a URL being served by the same server will hang. This should not