summaryrefslogtreecommitdiff
AgeCommit message (Collapse)Author
2024-10-08[5.1.x] Bumped version for 5.1.2 release.5.1.2Natalia
2024-10-08[5.1.x] Added release date for 5.1.2.Natalia
Backport of 5bb433e99bc24625295e05448fdf173dc72028ad from main.
2024-10-08[5.1.x] Fixed #35809 -- Set background color for selected rows in the ↵nessita
admin's form select widget. Regression in b47bdb4cd9149ee2a39bf1cc9996a36a940bd7d9. Thank you Giannis Terzopoulos for the review, and Tom Carrick and Sarah Boyce for the review. Backport of 679d57816d716cbc7cff3b364ae265d70444ebd9 from main.
2024-10-07[5.1.x] Updated translations from Transifex.nessita
2024-10-02[5.1.x] Reindented attributes and methods for classes in ↵nessita
docs/ref/middleware.txt. Backport of 1feedc8ef8a34484cb5afe33f5c45b543b860210 from main.
2024-10-02[5.1.x] Fixed #35670 -- Clarified the return value for ↵Aditya Chaudhary
LoginRequiredMiddleware's methods. Backport of efc3b0c627f7e3cb4e337280ecd2483758dcb0a5 from main.
2024-09-30[5.1.x] Relocated path() explanation to docs/ref/urls.txt to simplify ↵Chiara Mezzavilla
tutorial 1. Co-authored-by: Natalia <124304+nessita@users.noreply.github.com> Backport of 73e8e811416dcb5007ad9cc9d1632aaca95bf302 from main.
2024-09-26[5.1.x] Fixed #35734 -- Used JSONB_BUILD_OBJECT database function on ↵John Parton
PostgreSQL when using server-side bindings. Regression in 81ccf92f154c6d9eac3e30bac0aa67574d0ace15. Backport of f22ff4561ada77be98ca4db3ce117caca897696e from main.
2024-09-23[5.1.x] Made cosmetic edits to the Steering council docs.Sarah Boyce
Backport of 39de2e97a06d0317973b280bc159ca6f89fc64e3 from main.
2024-09-21[5.1.x] Removed setting the release schedule from Steering Council ↵Sarah Boyce
prerogatives as per DEP 44. Backport of 121747fdba5862ac8c4e26ec3b8f597385e9aa05 from main.
2024-09-16[5.1.x] Fixed #35767 -- Adjusted customizing User model docs.Carlton Gibson
Backport of c0128e3a81cfb07238324b185958a88631e94963 from main.
2024-09-11[5.1.x] Added example of email sending with additional capabilities to ↵Ronny V.
docs/topics/email.txt. Co-authored-by: Mike Edmunds <medmunds@gmail.com> Backport of f4813211e2d8017b56b7447f56ad17df3fae9aa3 from main.
2024-09-11[5.1.x] Fixed #35732 -- Wrapped ConcatPair expression in parentheses to ↵Gastón Avila
ensure operator precedence. When ConcatPair was updated to use || this lost the implicit wrapping from CONCAT(...). This broke the WHERE clauses when used in combination with PostgreSQL trigram similarity. Regression in 6364b6ee1071381eb3a23ba6b821fc0d6f0fce75. Backport of c3ca6075cc0ad425bcf905fe14062f38eb9fbcbf from main. Co-authored-by: Emiliano Cuenca <106986074+emicuencac@users.noreply.github.com>
2024-09-11[5.1.x] Refs #35060 -- Fixed the update to update_fields in overridden ↵Clifford Gama
save() method docs. Regression in 3915d4c70d0d7673abe675525b58117a5099afd3. Backport of 38c206515494cb28c48f77c10145a8aa9a172629 from main.
2024-09-07[5.1.x] Fixed #35681 -- Corrected geoip2 docs when describing GeoIP2Exception.Jon Ribbens
Backport of 826ef006681eae1e9b4bd0e4f18fa13713025cba from main.
2024-09-05[5.1.x] Fixed #35737 -- Clarified where "models" comes from in tutorial 7.Mariatta
Backport of 01a4d8a3c741b3129d481ef3515084a199d21222 from main.
2024-09-05[5.1.x] Updated instruction for deploying with Uvicorn and Gunicorn.SirenityK
Backport of 03d52d2a52af89381ee5b1030c672f0daf27be12 from main.
2024-09-05[5.1.x] Fixed #32831 -– Allowed cache tests to be retried via a new ↵Wassef Ben Ahmed
"retry" decorator. Backport of 957c54d945fedb58febff05e4ce82377cc43f9f4 from main.
2024-09-03[5.1.x] Added CVE-2024-45230 and CVE-2024-45231 to security archive.Natalia
Backport of aa5293068782dfa2d2173c75c8477f58a9989942 from main.
2024-09-03[5.1.x] Added stub release notes for 5.1.2.Natalia
Backport of 60073a3e6bece123b95b226d191873e81b54aab1 from main.
2024-09-03[5.1.x] Post-release version bump.Natalia
2024-09-03[5.1.x] Bumped version for 5.1.1 release.5.1.1Natalia
2024-09-03[5.1.x] Fixed CVE-2024-45231 -- Avoided server error on password reset when ↵Natalia
email sending fails. On successful submission of a password reset request, an email is sent to the accounts known to the system. If sending this email fails (due to email backend misconfiguration, service provider outage, network issues, etc.), an attacker might exploit this by detecting which password reset requests succeed and which ones generate a 500 error response. Thanks to Thibaut Spriet for the report, and to Mariusz Felisiak, Adam Johnson, and Sarah Boyce for the reviews.
2024-09-03[5.1.x] Fixed CVE-2024-45230 -- Mitigated potential DoS in urlize and ↵Sarah Boyce
urlizetrunc template filters. Thanks MProgrammer (https://hackerone.com/mprogrammer) for the report.
2024-08-30[5.1.x] Fixed #35716 -- Fixed VariableDoesNotExist when rendering admin ↵Sarah Boyce
fieldsets. Regression in 01ed59f753139afb514170ee7f7384c155ecbc2d. Thank you to Fábio Domingues and Marijke Luttekes for the report, and thank you to Natalia Bidart for the review. Backport of fd1dd767783b5a7ec1a594fcc5885e7e4178dd26 from main.
2024-08-28[5.1.x] Fixed #35688 -- Restored timezone and role setters to be PostgreSQL ↵Sarah Boyce
DatabaseWrapper methods. Following the addition of PostgreSQL connection pool support in Refs #33497, the methods for configuring the database role and timezone were moved to module-level functions. This change prevented subclasses of DatabaseWrapper from overriding these methods as needed, for example, when creating wrappers for other PostgreSQL-based backends. Thank you Christian Hardenberg for the report and to Florian Apolloner and Natalia Bidart for the review. Regression in fad334e1a9b54ea1acb8cce02a25934c5acfe99f. Co-authored-by: Natalia <124304+nessita@users.noreply.github.com> Backport of 7380ac57340653854bc2cfe0ed80298cdac6061d from main.
2024-08-28[5.1.x] Removed outdated note about lack of subquery support in MySQL.Adam Johnson
Backport of 26a67943ac5c2f196621220b24f4314d84471d07 from main.
2024-08-28[5.1.x] Fixed typos in docs/howto/initial-data.txt.Jacob Walls
Backport of 920efe503f8a1b16a497a792075c987080f3280a from main.
2024-08-28[5.1.x] Fixed #35666 -- Documented stacklevel usage and testing, and ↵Simon Charette
adjusted test suite accordingly. Over the years we've had multiple instances of hit and misses when emitting warnings: either setting the wrong stacklevel or not setting it at all. This work adds assertions for the existing warnings that were declaring the correct stacklevel, but were lacking tests for it. Backport of 57307bbc7d88927989cf5b314f16d6e13ade04e6 from main.
2024-08-28[5.1.x] Refs #35405 -- Adjusted deprecation warning stacklevel in ↵Simon Charette
FieldCacheMixin.get_cache_name(). Backport of 39abd56a7fb1e2f735040df0fdfc08f57d91a49b from main.
2024-08-28[5.1.x] Refs #35326 -- Adjusted deprecation warning stacklevel in ↵Simon Charette
FileSystemStorage.OS_OPEN_FLAGS. Backport of 47f18a722624527cc72eef44cfc9d1e07ea4b4e0 from main.
2024-08-28[5.1.x] Refs #35060 -- Adjusted deprecation warning stacklevel in ↵Simon Charette
Model.save()/asave(). Backport of 52ed2b645e1dd8c9a874cfd21c4c9f2500032626 from main.
2024-08-28[5.1.x] Refs #34900 -- Updated requirements for Python 3.13.Mariusz Felisiak
Backport of 07a4d23283586bc4578eb9c82a7ad14af3724057 from main.
2024-08-28[5.1.x] Fixed typo in docs/ref/models/expressions.txt.Mariusz Felisiak
Backport of fed11ba4617a5fa151bbabb91eb27ec01dd7c942 from main.
2024-08-27[5.1.x] Refs #34609 -- Fixed deprecation warning stack level in format_html().Adam Johnson
Co-authored-by: Simon Charette <charette.s@gmail.com> Backport of 2b71b2c8dcd40f2604310bb3914077320035b399 from main.
2024-08-27[5.1.x] Fixed grammatical error in stub release notes for upcoming security ↵Natalia
release. Backport of b941de340daed4ce88f04a8012b9dba00ccb1359 from main.
2024-08-27[5.1.x] Added stub release notes and release date for 5.1.1, 5.0.9, and 4.2.16.Natalia
Backport of 67efd42517af0faf24872df4295b39e98ce826af from main.
2024-08-26[5.1.x] Improved test coverage of urlize.Sarah Boyce
Backport of c6d1f98d2685f34e009e0fffdcff4ad275e55879 from main.
2024-08-22[5.1.x] Sorted alphabetically forms list in docs/topics/auth/default.txt.nessita
Backport of 7adb6dd98d50a238f3eca8c15b16b5aec12575fd from main.
2024-08-19[5.1.x] Fixed #35678 -- Removed "usable_password" field from ↵Natalia
BaseUserCreationForm. Refs #34429: Following the implementation allowing the setting of unusable passwords via the admin site, the `BaseUserCreationForm` and `UserCreationForm` were extended to include a new field for choosing whether password-based authentication for the new user should be enabled or disabled at creation time. Given that these forms are designed to be extended when implementing custom user models, this branch ensures that this new field is moved to a new, admin-dedicated, user creation form `AdminUserCreationForm`. Regression in e626716c28b6286f8cf0f8174077f3d2244f3eb3. Thanks Simon Willison for the report, Fabian Braun and Sarah Boyce for the review. Backport of 0ebed5fa95f53b87383901bbd9341ef3c974344f from main.
2024-08-19[5.1.x] Refs #35678 -- Split tests for BaseUserCreationForm when using a ↵Natalia
custom User model. This work also allows to subclass BaseUserCreationFormTest to reuse the tests and assertions for testing forms that extend BaseUserCreationForm, which is now used for UserCreationFormTest, increasing its coverage. Backport of b60fd8722f305ec29c87f34d3fea262e56394ebd from main.
2024-08-13[5.1.x] Fixed #35665 -- Fixed a crash when passing an empty order_by to Window.Simon Charette
This also caused un-ordered sliced prefetches to crash as they rely on Window. Regression in e16d0c176e9b89628cdec5e58c418378c4a2436a that made OrderByList piggy-back ExpressionList without porting the empty handling that the latter provided. Supporting explicit empty ordering on Window functions and slicing is arguably a foot-gun design due to how backends will return undeterministic results but this is a problem that requires a larger discussion. Refs #35064. Thanks Andrew Backer for the report and Mariusz for the review. Backport of 602fe961e6834d665f2359087a1272e9f9806b71 from main.
2024-08-13[5.1.x] Fixed typo of --no-startup in django-admin docs.David Smith
Backport of 5ae99226669bc516ecb0ed17066ec11a898fddab from main.
2024-08-08[5.1.x] Doc'd that SessionMiddleware is required for the admin site.Jure Cuhalev
The system check "admin.E410" was already checking for this, but the requirement was not listed in docs/ref/contrib/admin/index.txt. Backport of f8ef4579ea710f93ec7edc93c6f3f216bd55d6be from main.
2024-08-08[5.1.x] Refs #35591 -- Emphasized that runserver is not suitable for production.Andrew Miller
Backport of cec62fb99e8ff63f30c7871a048ab15081142668 from main.
2024-08-08[5.1.x] Refs #31405 -- Improved LoginRequiredMiddleware documentation.Adam Johnson
co-authored-by: Sarah Boyce <42296566+sarahboyce@users.noreply.github.com> Backport of 49815f70e4508ae21135f725da177fc2935de32c from main.
2024-08-08[5.1.x] Fixed #35661 -- Fixed test_too_many_digits_to_rander() test crash on ↵Mariusz Felisiak
PyPy. Thanks Michał Górny for the report. Backport of 7fb15ad5bcae05324ee8913e4b2c6c982e8f2de0 from main.
2024-08-07[5.1.x] Added stub release notes for 5.1.1.Natalia
Backport of 790f0f8868b0cde9a9bec1f0621efa53b00c87df from main.
2024-08-07[5.1.x] Post-release version bump.Natalia
2024-08-07[5.1.x] Bumped version for 5.1 release.5.1Natalia