summaryrefslogtreecommitdiff
path: root/docs/internals
diff options
context:
space:
mode:
authorRussell Keith-Magee <russell@keith-magee.com>2011-09-10 01:08:24 +0000
committerRussell Keith-Magee <russell@keith-magee.com>2011-09-10 01:08:24 +0000
commit1a76dbefdfc60e2d5954c0ba614c3d054ba9c3f0 (patch)
tree053c60d65b333df990de1250af0085ec75baf953 /docs/internals
parentfbe2eead2fa9d808658ca582241bcacb02618840 (diff)
[1.3.X] Altered the behavior of URLField to avoid a potential DOS vector, and to avoid potential leakage of local filesystem data. A security announcement will be made shortly.
Backport of r16760 from trunk. git-svn-id: http://code.djangoproject.com/svn/django/branches/releases/1.3.X@16763 bcc190cf-cafb-0310-a4f2-bffc1f526a37
Diffstat (limited to 'docs/internals')
-rw-r--r--docs/internals/deprecation.txt6
1 files changed, 6 insertions, 0 deletions
diff --git a/docs/internals/deprecation.txt b/docs/internals/deprecation.txt
index c7f8bcbcc0..3f0f998b4a 100644
--- a/docs/internals/deprecation.txt
+++ b/docs/internals/deprecation.txt
@@ -108,6 +108,12 @@ their deprecation, as per the :ref:`Django deprecation policy
beyond that of a simple ``TextField`` since the removal of oldforms.
All uses of ``XMLField`` can be replaced with ``TextField``.
+ * ``django.db.models.fields.URLField.verify_exists`` has been
+ deprecated due to intractable security and performance
+ issues. Validation behavior has been removed in 1.4, and the
+ argument will be removed in 1.5.
+
+
* 1.5
* The ``mod_python`` request handler has been deprecated since the 1.3
release. The ``mod_wsgi`` handler should be used instead.