| Age | Commit message (Collapse) | Author | |
|---|---|---|---|
| 2015-07-08 | [1.4.x] Bumped version for 1.4.21 release.1.4.21 | Tim Graham | |
| 2015-07-08 | [1.4.x] Prevented newlines from being accepted in some validators. | Tim Graham | |
| This is a security fix; disclosure to follow shortly. Thanks to Sjoerd Job Postmus for the report and draft patch. | |||
| 2015-07-08 | [1.4.x] Fixed #19324 -- Avoided creating a session record when loading the ↵ | Carl Meyer | |
| session. The session record is now only created if/when the session is modified. This prevents a potential DoS via creation of many empty session records. This is a security fix; disclosure to follow shortly. | |||
| 2015-07-08 | [1.4.x] Added security release note stubs. | Tim Graham | |
| 2015-07-01 | [1.4.x] Backported .gitignore and .hgignore from master. | Tim Graham | |
| 2015-04-04 | [1.4.x] Added link to download page to find supported versions. | Tim Graham | |
| Backport of 8c4827ec1d44fee05db189766174c115795a495e from master | |||
| 2015-03-18 | [1.4.x] Post-release version bump. | Tim Graham | |
| 2015-03-18 | [1.4.x] Bumped version for 1.4.20 release.1.4.20 | Tim Graham | |
| 2015-03-18 | [1.4.x] Made is_safe_url() reject URLs that start with control characters. | Tim Graham | |
| This is a security fix; disclosure to follow shortly. | |||
| 2015-03-18 | [1.4.x] Added stub release notes for security releases. | Tim Graham | |
| 2015-02-06 | [1.4.x] Fix an encoding preamble so the tests pass on 2.7.9. | Carl Meyer | |
| It seems there was a change in the parsing of encoding preambles in Python 2.7.9, compared to previous 2.7.x Pythons. This is a backport of the only piece of e520a73eeea6b185b719901ab9985ecef00e5664 that's needed to prevent an import failure under 2.7.9. | |||
| 2015-01-28 | [1.4.x] Fixed #24238 -- Removed unused WSGIRequestHandler.get_environ() | Tim Graham | |
| Also moved the test as it wasn't running. | |||
| 2015-01-27 | [1.4.x] Post-release version bump. | Tim Graham | |
| 2015-01-27 | [1.4.x] Bumped version for 1.4.19 release.1.4.19 | Tim Graham | |
| 2015-01-26 | [1.4.x] Fixed #24158 -- Allowed GZipMiddleware to work with streaming responses | Benjamin Richter | |
| Backport of django.utils.text.compress_sequence and fix for django.middleware.gzip.GZipMiddleware when using iterators as response.content. | |||
| 2015-01-19 | [1.4.x] Designated Django 1.8 as the next LTS. | Tim Graham | |
| Backport of c38db4d7e072e9a5002cb4897d9104e5eaa292ed from master | |||
| 2015-01-14 | [1.4.x] Fixed a static view test on Windows. | Tim Graham | |
| Backport of a6f144fd4fee0090de3a99b1f50a4142722e7946 from master | |||
| 2015-01-13 | [1.4.x] Post-release version bump. | Tim Graham | |
| 2015-01-13 | [1.4.x] Bumped version for 1.4.18 release.1.4.18 | Tim Graham | |
| 2015-01-13 | [1.4.x] Added dates to release notes. | Tim Graham | |
| 2015-01-05 | [1.4.x] Prevented views.static.serve() from using large memory on large files. | Tim Graham | |
| This is a security fix. Disclosure following shortly. | |||
| 2015-01-05 | [1.4.x] Fixed is_safe_url() to handle leading whitespace. | Tim Graham | |
| This is a security fix. Disclosure following shortly. | |||
| 2015-01-05 | [1.4.x] Stripped headers containing underscores to prevent spoofing in WSGI ↵ | Carl Meyer | |
| environ. This is a security fix. Disclosure following shortly. Thanks to Jedediah Smith for the report. | |||
| 2015-01-05 | [1.4.x] Added stub release notes for security releases. | Tim Graham | |
| 2015-01-05 | [1.4.x] Fixed #24081 -- Downgraded six to 1.8.0. | Tim Graham | |
| This reverts commit a25c444bc701b496f2b05f57fc3ec42cdac9dd85. six 1.9+ requires Python 2.6 so this commit restores Python 2.5 compatibility. | |||
| 2015-01-02 | [1.4.x] Removed wheel generation from Makefile. | Tim Graham | |
| 2015-01-02 | [1.4.x] Post-release version bump. | Tim Graham | |
| 2015-01-02 | [1.4.x] Bumped version for 1.4.17 release.1.4.17 | Tim Graham | |
| 2015-01-02 | [1.4.x] Added dates to release notes. | Tim Graham | |
| Backport of 15cd71ed24945ff7be5716580603fd65c0d45ef7 from master | |||
| 2015-01-02 | [1.4.x] Updated six to 1.9.0. | Tim Graham | |
| Backport of 52f0b2b62262743d5f935ddae29428e661b5d8ea from master | |||
| 2014-11-25 | [1.4.x] Fixed #23754 -- Always allowed reference to the primary key in the admin | Simon Charette | |
| This change allows dynamically created inlines "Add related" button to work correcly as long as their associated foreign key is pointing to the primary key of the related model. Thanks to amorce for the report, Julien Phalip for the initial patch, and Collin Anderson for the review. Backport of f9c4e14aeca7df79991bca8ac2d743953cbd095c from master | |||
| 2014-11-13 | [1.4.x] Removed thread customizations of six which are now built-in. | Tim Graham | |
| Backport of 7ef81b5cdd4c8eda12aa7786484a0bfde00aaaa4 from master | |||
| 2014-11-04 | [1.4.x] Updated six to 1.8.0. | Tim Graham | |
| Backport of 81477c91f6 from master | |||
| 2014-10-22 | [1.4.x] Post-release version bump. | Tim Graham | |
| 2014-10-22 | [1.4.x] Bump version numbers for bugfix release.1.4.16 | James Bennett | |
| 2014-10-22 | [1.4.x] Added release dates to release notes. | Tim Graham | |
| Backport of 9dc782b631 from master | |||
| 2014-10-10 | [1.4.x] Fixed #23631 -- Removed outdated note on MySQL timezone support. | Tim Graham | |
| Thanks marfire for the report. Backport of 9db3653670 from master | |||
| 2014-10-06 | [1.4.x] Fixed #23604 -- Allowed related m2m fields to be references in the ↵ | Emmanuelle Delescolle | |
| admin. Thanks Simon Charette for review. Backport of a24cf21722 from master | |||
| 2014-09-29 | [1.4.x] Required numpy < 1.9 for tests; refs #23489. | Tim Graham | |
| Backport of 4743a94429 from stable/1.7.x | |||
| 2014-09-17 | [1.4.x] Fixed #23499 -- Error in built-in template tag "now" documentation | Joseph Dougherty | |
| Backport of ab8248361e0a7b4fc7684eaaa5891e16b8562683 from master. | |||
| 2014-09-11 | [1.4.x] Fixed #20036 -- Improved GEOS version string parsing | Claude Paroz | |
| Thanks chikiro.spam at gmail.com for the report. | |||
| 2014-09-08 | [1.4.x] Fixed #23431 -- Allowed inline and hidden references to admin fields. | Simon Charette | |
| This fixes a regression introduced by the 53ff096982 security fix. Thanks to @a1tus for the report and Tim for the review. refs #23329. Backport of 342ccbd from master | |||
| 2014-09-02 | [1.4.x] Added dates to release notes. | Tim Graham | |
| Backport of 0fd23545db from master | |||
| 2014-09-02 | [1.4.x] Post release version bump. | Tim Graham | |
| 2014-09-02 | [1.4.x] Bump version numbers for bugfix release.1.4.15 | James Bennett | |
| 2014-08-27 | [1.4.x] Fixed #23329 -- Allowed inherited and m2m fields to be referenced in ↵ | Simon Charette | |
| the admin. Thanks to Trac alias Markush2010 and ross for the detailed reports. Backport of 3cbb759 from master | |||
| 2014-08-26 | [1.4.x] Fixed spelling mistake in file docs. | Tim Graham | |
| Backport of a3e88e64a4 from master | |||
| 2014-08-20 | [1.4.x] Bumped version number post-release. | Tim Graham | |
| 2014-08-20 | [1.4.x] Added dates to release notes. | Tim Graham | |
| 2014-08-20 | [1.4.x] Bump version numbers for security release.1.4.14 | James Bennett | |
