summaryrefslogtreecommitdiff
path: root/docs/ref
diff options
context:
space:
mode:
authorAhmed Nassar <a.moh.nassar00@gmail.com>2025-03-08 16:35:10 +0200
committerSarah Boyce <42296566+sarahboyce@users.noreply.github.com>2025-03-19 14:28:42 +0100
commitec7044c706f48f5ab3d9e4c35e4078b9f9dcaaf2 (patch)
tree728764e3cac25453c9936eaae272cc3cc019a017 /docs/ref
parented1e7c02c9db2cc28b3ab5621ce6315fcee54b27 (diff)
Fixed #36000 -- Deprecated HTTP as the default protocol in urlize and urlizetrunc.
Diffstat (limited to 'docs/ref')
-rw-r--r--docs/ref/settings.txt16
-rw-r--r--docs/ref/templates/builtins.txt40
2 files changed, 50 insertions, 6 deletions
diff --git a/docs/ref/settings.txt b/docs/ref/settings.txt
index 556cbb4b1e..ab82b539b0 100644
--- a/docs/ref/settings.txt
+++ b/docs/ref/settings.txt
@@ -2955,6 +2955,21 @@ enabled if a proxy which sets this header is in use.
:setting:`USE_X_FORWARDED_HOST` takes priority over this setting.
+.. setting:: URLIZE_ASSUME_HTTPS
+
+``URLIZE_ASSUME_HTTPS``
+-----------------------
+
+.. versionadded:: 6.0
+.. deprecated:: 6.0
+
+Default: ``False``
+
+Set this transitional setting to ``True`` to opt into using HTTPS as the
+default protocol when none is provided in URLs processed by the
+:tfilter:`urlize` and :tfilter:`urlizetrunc` template filters during the Django
+6.x release cycle.
+
.. setting:: WSGI_APPLICATION
``WSGI_APPLICATION``
@@ -3766,6 +3781,7 @@ Security
* :setting:`SECRET_KEY`
* :setting:`SECRET_KEY_FALLBACKS`
+* :setting:`URLIZE_ASSUME_HTTPS`
* :setting:`X_FRAME_OPTIONS`
Serialization
diff --git a/docs/ref/templates/builtins.txt b/docs/ref/templates/builtins.txt
index 247f5e9890..f5470ad0eb 100644
--- a/docs/ref/templates/builtins.txt
+++ b/docs/ref/templates/builtins.txt
@@ -2905,9 +2905,23 @@ For example:
{{ value|urlize }}
-If ``value`` is ``"Check out www.djangoproject.com"``, the output will be
-``"Check out <a href="http://www.djangoproject.com"
-rel="nofollow">www.djangoproject.com</a>"``.
+If ``value`` is ``"Check out www.djangoproject.com"``, the output will be:
+
+.. code-block:: html+django
+
+ Check out <a href="http://www.djangoproject.com" rel="nofollow">www.djangoproject.com</a>
+
+.. deprecated:: 6.0
+
+ The default protocol when none is provided will change from HTTP to HTTPS
+ in Django 7.0. Hence, the output will become:
+
+ .. code-block:: html+django
+
+ Check out <a href="https://www.djangoproject.com" rel="nofollow">www.djangoproject.com</a>
+
+ Set the transitional setting :setting:`URLIZE_ASSUME_HTTPS` to ``True`` to
+ opt into using HTTPS during the Django 6.x release cycle.
In addition to web links, ``urlize`` also converts email addresses into
``mailto:`` links. If ``value`` is
@@ -2942,9 +2956,23 @@ For example:
{{ value|urlizetrunc:15 }}
-If ``value`` is ``"Check out www.djangoproject.com"``, the output would be
-``'Check out <a href="http://www.djangoproject.com"
-rel="nofollow">www.djangoproj…</a>'``.
+If ``value`` is ``"Check out www.djangoproject.com"``, the output would be:
+
+.. code-block:: html+django
+
+ Check out <a href="http://www.djangoproject.com" rel="nofollow">www.djangoproj…</a>
+
+.. deprecated:: 6.0
+
+ The default protocol when none is provided will change from HTTP to HTTPS
+ in Django 7.0. Hence, the output will become:
+
+ .. code-block:: html+django
+
+ Check out <a href="https://www.djangoproject.com" rel="nofollow">www.djangoproj…</a>
+
+ Set the transitional setting :setting:`URLIZE_ASSUME_HTTPS` to ``True`` to
+ opt into using HTTPS during the Django 6.x release cycle.
As with urlize_, this filter should only be applied to plain text.