| Age | Commit message (Collapse) | Author | |
|---|---|---|---|
| 2016-03-08 | Fixed #26033 -- Added Argon2 password hasher. | Bas Westerbaan | |
| 2016-03-08 | Fixed #25971 -- Made BrokenLinkEmailsMiddleware ignore APPEND_SLASH redirects. | harikrishnakanchi | |
| If APPEND_SLASH=True and the referer is the URL without a trailing '/', then BrokenLinkEmailsMiddleware shouldn't send an email. | |||
| 2016-03-08 | Fixed #26289 -- Enabled shell tab completion on systems using libedit. | Saúl Ibarra Corretgé | |
| 2016-03-08 | Fixed #25933 -- Allowed an unprefixed default language in i18n_patterns(). | Krzysztof Urbaniak | |
| 2016-03-07 | Fixed #26325 -- Made MultiPartParser ignore filenames that normalize to an ↵ | John-Mark Bell | |
| empty string. | |||
| 2016-03-07 | Fixed #26271 -- Fixed i18n_patterns resolution when no language is active | Claude Paroz | |
| Thanks Marten Kenbeek for the report. | |||
| 2016-03-05 | Refs #19527 -- Fixed SQL compiler regression causing Oracle failure. | Tim Graham | |
| 2016-03-05 | Refs #26315 -- Cleaned up argparse options in commands. | Jon Dufresne | |
| * Removed type coercion. Options created by argparse are already coerced to the correct type. * Removed fallback default values. Options created by argparse already have a default value. * Used direct indexing. Options created by argparse are always set. This eliminates the need to use dict.get(). | |||
| 2016-03-05 | Fixed #26315 -- Allowed call_command() to accept a Command object as the ↵ | Jon Dufresne | |
| first argument. | |||
| 2016-03-05 | Cleaned up tests to use call_command() instead of Command.execute(). | Jon Dufresne | |
| 2016-03-04 | Added safety to URL decoding in is_safe_url() on Python 2 | Claude Paroz | |
| The errors='replace' parameter to force_text altered the URL before checking it, which wasn't considered sane. Refs 24fc935218 and ada7a4aef. | |||
| 2016-03-04 | Fixed #26308 -- Prevented crash with binary URLs in is_safe_url() | Claude Paroz | |
| This fixes a regression introduced by c5544d28923. Thanks John Eskew for the reporti and Tim Graham for the review. | |||
| 2016-03-03 | Fixed #26316 -- Factored duplicated code in model/field migration operations. | Akshesh | |
| 2016-03-03 | Passed proper default value to int-type 'verbosity' option | Jon Dufresne | |
| 2016-03-03 | Fixed #26295 -- Allowed using i18n_patterns() in any root URLconf. | Simon Charette | |
| Thanks Tim for the review. | |||
| 2016-03-02 | Fixed #26226 -- Made related managers honor the queryset used for ↵ | Simon Charette | |
| prefetching their results. Thanks Loïc for the suggested improvements and Tim for the review. | |||
| 2016-03-02 | Fixed #26285 -- Deprecated the MySQL-specific __search lookup. | Marc Tamlyn | |
| 2016-03-02 | Refs #19527 -- Allowed QuerySet.bulk_create() to set the primary key of its ↵ | acrefoot | |
| objects. PostgreSQL support only. Thanks Vladislav Manchev and alesasnouski for working on the patch. | |||
| 2016-03-02 | Fixed #26304 -- Ignored unmanaged through model in table introspection. | Matthew Schinckel | |
| 2016-03-01 | Removed obsolete, unused option 'hide_empty' from loaddata command. | Jon Dufresne | |
| Unused since 67235fd4ef1b006fc9cdb2fa20e7bb93b0edff4b. | |||
| 2016-03-01 | Fixed CVE-2016-2513 -- Fixed user enumeration timing attack during login. | Florian Apolloner | |
| This is a security fix. | |||
| 2016-03-01 | Fixed CVE-2016-2512 -- Prevented spoofing is_safe_url() with basic auth. | Mark Striemer | |
| This is a security fix. | |||
| 2016-03-01 | Fixed #26229 -- Improved check for model admin check admin.E124 | Alasdair Nicol | |
| Refs #22792 | |||
| 2016-02-29 | Fixed #26186 -- Documented how app relative relationships of abstract models ↵ | Simon Charette | |
| behave. This partially reverts commit bc7d201bdbaeac14a49f51a9ef292d6312b4c45e. Thanks Tim for the review. Refs #25858. | |||
| 2016-02-29 | Removed unused 'Between' lookup. | Adam Chainz | |
| It was added in 20bab2cf9d02a5c6477d8aac066a635986e0d3f3 and stopped being used for `Range` in 00aa562884a418c4ee20e223ab82c3455997ee7d when `bilateral` was added to `Transform`. | |||
| 2016-02-27 | Fixed #26230 -- Made default_related_name affect related_query_name. | chenesan | |
| 2016-02-26 | Fixed #26264 -- Fixed prefetch_related() crashes with values_list(flat=True) | Attila Tovt | |
| 2016-02-26 | Fixed #21608 -- Prevented logged out sessions being resurrected by ↵ | Tore Lundqvist | |
| concurrent requests. Thanks Simon Charette for the review. | |||
| 2016-02-26 | Fixed #26286 -- Prevented content type managers from sharing their cache. | Simon Charette | |
| This should prevent managers methods from returning content type instances registered to foreign apps now that these managers are also attached to models created during migration phases. Thanks Tim for the review. Refs #23822. | |||
| 2016-02-26 | Fixed #25279 -- Made prefetch_related_objects() public. | Adam Chainz | |
| 2016-02-26 | Fixed #24974 -- Fixed inheritance of formfield_callback for ↵ | Yoong Kang Lim | |
| modelform_factory forms. | |||
| 2016-02-26 | Fixed #24793 -- Unified temporal difference support. | Simon Charette | |
| 2016-02-26 | Fixed #24653 -- Fixed MySQL database introspection when using read_default_file. | zshimanchik | |
| 2016-02-26 | Fixed #26280 -- Fixed cached template loader crash when loading nonexistent ↵ | Ivan Tsouvarev | |
| template. | |||
| 2016-02-26 | Fixed #25811 -- Added a helpful error when making _in queries across ↵ | Edwar Baron | |
| different databases. | |||
| 2016-02-25 | Fixed #26231 -- Used .get_username in admin login template. | Sjoerd Job Postmus | |
| 2016-02-25 | Fixed #26269 -- Prohibited spaces in is_valid_ipv6_address(). | Nick Malakhov | |
| 2016-02-25 | Fixed #26151 -- Refactored MigrationWriter.serialize() | Yoong Kang Lim | |
| Thanks Markus Holtermann for review. | |||
| 2016-02-25 | Fixed #26117 -- Consulted database routers in initial migration detection. | Scott Sexton | |
| Thanks Simon Charette for help. | |||
| 2016-02-25 | Fixed #12233 -- Allowed redirecting authenticated users away from the login ↵ | Olivier Le Thanh Duong | |
| view. contrib.auth.views.login() has a new parameter `redirect_authenticated_user` to automatically redirect authenticated users visiting the login page. Thanks to dmathieu and Alex Buchanan for the original code and to Carl Meyer for the help and review. | |||
| 2016-02-25 | Fixed #14098 -- Prevented crash for introspection errors in inspectdb | Claude Paroz | |
| Thanks Tim Graham for the review. | |||
| 2016-02-24 | Fixed #26266 -- Output the primary key in the GeoJSON serializer properties | Claude Paroz | |
| Thanks Tim Graham for the review. | |||
| 2016-02-24 | Fixed #26267 -- Fixed BoundField to reallow slices of subwidgets. | Jon Dufresne | |
| 2016-02-23 | Fixed #23832 -- Added timezone aware Storage API. | James Aylett | |
| New Storage.get_{accessed,created,modified}_time() methods convert the naive time from now-deprecated {accessed,created_modified}_time() methods into aware objects in UTC if USE_TZ=True. | |||
| 2016-02-23 | Prevented static file corruption when URL fragment contains '..'. | Aymeric Augustin | |
| When running collectstatic with a hashing static file storage backend, URLs referencing other files were normalized with posixpath.normpath. This could corrupt URLs: for example 'a.css#b/../c' became just 'c'. Normalization seems to be an artifact of the historical implementation. It contained a home-grown implementation of posixpath.join which relied on counting occurrences of .. and /, so multiple / had to be collapsed. The new implementation introduced in the previous commit doesn't suffer from this issue. So it seems safe to remove the normalization. There was a test for this normalization behavior but I don't think it's a good test. Django shouldn't modify CSS that way. If a developer has rendundant /s, it's mostly an aesthetic issue and it isn't Django's job to fix it. Conversely, if the user wants a series of /s, perhaps in the URL fragment, Django shouldn't destroy it. Refs #26249. | |||
| 2016-02-23 | Fixed #26249 -- Fixed collectstatic crash for files in STATIC_ROOT ↵ | Aymeric Augustin | |
| referenced by absolute URL. collectstatic crashed when: * a hashing static file storage backend was used * a static file referenced another static file located directly in STATIC_ROOT (not a subdirectory) with an absolute URL (which must start with STATIC_URL, which cannot be empty) It seems to me that the current code reimplements relative path joining and doesn't handle edge cases correctly. I suspect it assumes that STATIC_URL is of the form r'/[^/]+/'. Throwing out that code in favor of the posixpath module makes the logic easier to follow. Handling absolute paths correctly also becomes easier. | |||
| 2016-02-23 | Fixed #25670 -- Allowed dictsort to sort a list of lists. | Andrew Kuchev | |
| Thanks Tim Graham for the review. | |||
| 2016-02-23 | Fixed #26263 -- Deprecated Context.has_key() | Tim Graham | |
| 2016-02-23 | Used call_command return value in staticfiles tests | Claude Paroz | |
| Refs #26190. | |||
| 2016-02-23 | Fixed #26190 -- Returned handle() result from call_command | Claude Paroz | |
| Thanks Tim Graham for the review. | |||
