summaryrefslogtreecommitdiff
path: root/docs
AgeCommit message (Collapse)Author
2015-07-14Fixed #25121 -- Added a warning that filtering sensitive information from ↵Tim Graham
error reporting isn't bulletproof
2015-07-13Fixed #25099 -- Cleaned up HttpRequest representations in error reporting.Vlastimil Zíma
2015-07-13Fixed #25079 -- Added warning if both TEMPLATES and TEMPLATE_* settings are ↵Daniel Roseman
defined. Django ignores the value of the TEMPLATE_* settings if TEMPLATES is also set, which is confusing for users following older tutorials. This change adds a system check that warns if any of the TEMPLATE_* settings have changed from their defaults but the TEMPLATES dict is also non-empty. Removed the TEMPLATE_DIRS from the test settings file; this was marked for removal in 1.10 but no tests fail if it is removed now.
2015-07-13Documented templates system check type.Tim Graham
2015-07-13Fixed #24375 -- Added Migration.initial attributeAndrei Kulakov
The new attribute is checked when the `migrate --fake-initial` option is used. initial will be set to True for all initial migrations (this is particularly useful when initial migrations are split) as well as for squashed migrations.
2015-07-13Fixed #25117 -- Added Romanian char map for Javascript slug generationRazvan Andrei Ionescu
2015-07-13Added 'bookmarklet' to spelling word list.Tim Graham
2015-07-13Fixed #25116 -- Removed long-broken admindocs bookmarkletsBen Spaulding
These were broken back in commit 64e11a6.
2015-07-13Fixed #24984 -- Added link to Jinja2 static tag instructions in staticfiles ↵Chris McCollister
docs.
2015-07-12Updated where I live.Alex Gaynor
2015-07-10Fixed #25103 -- Corrected versionadded for FileResponseMatthew Madurski
2015-07-10Added a link to running the unit tests to new contributors page.Tim Graham
2015-07-10Fixed #25082 -- Documented where to register system checks.Tim Graham
2015-07-10Fixed #25083 -- Added SessionAuthenticationMiddleware to auth installation docsNick Sweeting
2015-07-10Added release note for the UUID serialization backportClaude Paroz
Refs #25019.
2015-07-10Added stub release notes for 1.8.4Claude Paroz
2015-07-09Fixed #25048 -- Documented that runservers strips headers with underscores.Tim Graham
refs 316b8d49746933d1845d600314b002d9b64d3e3d
2015-07-08Added today's security issues to the archive.Tim Graham
2015-07-08Fixed catastrophic backtracking in URLValidator.Shai Berger
Thanks João Silva for reporting the problem and Tim Graham for finding the problematic RE and for review. This is a security fix; disclosure to follow shortly.
2015-07-08Prevented newlines from being accepted in some validators.Tim Graham
This is a security fix; disclosure to follow shortly. Thanks to Sjoerd Job Postmus for the report and draft patch.
2015-07-08Fixed #19324 -- Avoided creating a session record when loading the session.Carl Meyer
The session record is now only created if/when the session is modified. This prevents a potential DoS via creation of many empty session records. This is a security fix; disclosure to follow shortly.
2015-07-08Added security release note stubs.Tim Graham
2015-07-08Removed a confusing sentence in tutorial 5.Tim Graham
2015-07-08Corrected example code for get_query_set upgrade in 1.6 release notesLuke Plant
The conditional setting of `get_query_set` is required for correct behaviour if running Django 1.8. The full gory details are here: http://lukeplant.me.uk/blog/posts/handling-django%27s-get_query_set-rename-is-hard/
2015-07-07Refs #23882 -- Added detection for moved files when using inotify pollingChris Bainbridge
Commit 15f82c7 ("used pyinotify as change detection system when available") introduced a regression where editing a file in vim with default settings (writebackup=auto) no longer causes the dev server to be restarted. On a write, vim moves the monitored file to a backup path and then creates a new file in the original. The new file is not monitored as it has a different inode. Fixed this by also watching for inotify events IN_DELETE_SELF and IN_MOVE_SELF.
2015-07-07Fixed #22804 -- Added warning for unsafe value of 'sep' in SignerDavid Wolever
Thanks Jaap Roes for completing the patch.
2015-07-06Fixed #25059 -- Allowed Punycode TLDs in URLValidatorAlexey Sveshnikov
2015-07-04Fixed #25051 -- Clarified return type of {% now %} tag.Tim Graham
2015-07-03Fixed #24877 -- Added middleware handling of response.render() errors.Sylvain Fankhauser
2015-07-03Fixed #23190 -- Made Paginator.page_range an iteratorRigel Di Scala
2015-07-03Fixed mistake in Model.from_db() example.Luke
2015-07-03Updated mock note since Django no longer works with Python 3.2.Tim Graham
2015-07-03Fixed #25056 -- Documented minimum version of jinja2 for testing.Tim Graham
2015-07-02Fixed #25029 -- Added PersistentRemoteUserMiddleware for login-page-only ↵Jan Pazdziora
external authentication.
2015-07-02Fixed #24997 -- Enabled bulk_create() on proxy modelsWilliam Schwartz
2015-07-01Fixed #4960 -- Added "strip" option to CharFieldCurtis
2015-07-01Fixed #20916 -- Added Client.force_login() to bypass authentication.Jon Dufresne
2015-07-01Fixed #21695 -- Added asvar option to blocktrans.Matthew Somerville
Thanks Bojan Mihelac for the initial patch.
2015-07-01Fixed typo in writing migrations docsClaude Paroz
2015-06-30DEP 0003 -- Added JavaScript unit tests.Trey Hunner
Setup QUnit, added tests, and measured test coverage. Thanks to Nick Sanford for the initial tests.
2015-06-30Fixed #23658 -- Provided the password to PostgreSQL dbshell commandJean-Michel Vourgère
The password from settings.py is written in a temporary .pgpass file file whose name is given to psql using the PGPASSFILE environment variable.
2015-07-01Removed datetime_cast_sql, which is never overridden or used anywhere in Django.Shai Berger
Thanks Tim Graham for review.
2015-06-30Fixed #21803 -- Added support for post-commit callbacksAndreas Pelme
Made it possible to register and run callbacks after a database transaction is committed with the `transaction.on_commit()` function. This patch is heavily based on Carl Meyers django-transaction-hooks <https://django-transaction-hooks.readthedocs.org/>. Thanks to Aymeric Augustin, Carl Meyer, and Tim Graham for review and feedback.
2015-06-30Fixed #25038 -- Reverted incorrect documentation about inspectdb ↵Tim Graham
introspecting views. This reverts commit bd691f4586c8ad45bd059ff9d3621cbf8afdcdce (refs #24177).
2015-06-29Fixed #25018 -- Changed simple_tag to apply conditional_escape() to its output.Luke Plant
This is a security hardening fix to help prevent XSS (and incorrect HTML) for the common use case of simple_tag. Thanks to Tim Graham for the review.
2015-06-27Fixed #22463 -- Added code style guide and JavaScript linting (EditorConfig ↵Trey Hunner
and ESLint)
2015-06-27Fixed #25033 -- Added context_processors.auth to documented admin dependencies.Tim Graham
2015-06-27Fixed #25031 -- Fixed a regression in the unordered_list template filter.Noam
2015-06-27Fixed #25017 -- Allowed customizing the DISALLOWED_USER_AGENTS responsesujayskumar
2015-06-26Fixed #24958 -- Fixed inline forms using UUID-PK parents with auto-PK children.Jason Hoos