Tim Graham
640c99e8b3
[1.8.x] Added CVE-2016-2512/2513 to security release archive.
...
Backport of 24fc9352183c449a8b11d1c7b442e70aa61a8800 from master
2016-03-01 12:36:20 -05:00
Florian Apolloner
f4e6e02f77
[1.8.x] Fixed CVE-2016-2513 -- Fixed user enumeration timing attack during login.
...
This is a security fix.
2016-02-29 08:07:17 -05:00
Mark Striemer
382ab13731
[1.8.x] Fixed CVE-2016-2512 -- Prevented spoofing is_safe_url() with basic auth.
...
This is a security fix.
2016-02-29 08:07:17 -05:00
Tim Graham
922f228695
[1.8.x] Added stub release notes for security issues.
2016-02-29 08:07:17 -05:00
Simon Charette
4701c81df3
[1.8.x] Fixed #26286 -- Prevented content type managers from sharing their cache.
...
This should prevent managers methods from returning content type instances
registered to foreign apps now that these managers are also attached to models
created during migration phases.
Thanks Tim for the review.
Refs #23822 .
Backport of 3938b3ccaa85f1c366909a4839696007726a09da from master
2016-02-26 16:24:28 -05:00
Tim Graham
3b0b1e071d
[1.8.x] Fixed a function signature in docs/topics/auth/default.txt.
...
Backport of 441c537b66233ae57bf0023f02d8262474229e1a from master
2016-02-24 16:25:37 -05:00
Tim Graham
4b8bd72a9f
[1.8.x] Removed docs of deprecated SimpleTestCase warnings behavior.
...
Removed in Django 1.7 (4f6be9a0c43050500af598527e1453d27c5c5b85).
Backport of 6637cd0ef2fd5f063df82000c18c64c246bb6e1b from master
2016-02-24 09:59:23 -05:00
Jon Dufresne
6c48edae76
[1.8.x] Fixed #26267 -- Fixed BoundField to reallow slices of subwidgets.
...
Backport of b41268135995cef46d40e550f9301fab20cf330d from master
2016-02-24 07:09:08 -05:00
Josh Soref
751e5fcaf7
[1.8.x] Fixed many spelling mistakes in code, comments, and docs.
...
Partial backport of 93452a70e8a62c7408eeded444f5088d4a26212d from master
2016-02-23 10:27:15 -05:00
Tim Graham
2d321d2393
[1.8.x] Fixed #26188 -- Documented how to wrap password hashers.
...
Backport of 5a541e2e6cb01e254f20c302093a24d7dc9af8ce from master
2016-02-23 09:34:04 -05:00
Daniel Quinn
5127ab4e73
[1.8.x] Fixed import location of check_password() in docs.
...
Backport of de7edc005f06c47c1d39d5cb30762d424ee4dabf from master
2016-02-22 12:43:41 -05:00
Sergey Fedoseev
e127fbac7b
[1.8.x] Fixed some code blocks indentation in GIS docs.
...
Backport of dbaa1a6b59b4f8f942e8378465aaeb943c3d9de5 from master
2016-02-19 08:35:57 -05:00
Juan José Conti
3c2282c301
[1.8.x] Used relative models imports in the GIS tutorial.
...
Backport of bb7042cda from master.
2016-02-19 08:30:28 +01:00
Tim Graham
0f667a580a
[1.8.x] Fixed #26204 -- Reallowed dashes in top-level domains for URLValidator.
...
Thanks Shai Berger for the review.
Backport of b1afebf882db5296cd9dcea26ee66d5250922e53 from master
2016-02-18 19:56:36 -05:00
Jon Dufresne
2029105670
[1.8.x] Followed recommended ValidationError use in docs.
...
Backport of 0db7e61076116c2d93d61f98ef31690542359e48 from master
2016-02-17 09:10:09 -05:00
Claude Paroz
5bce665974
[1.8.x] Fixed #26215 -- Fixed RangeField/ArrayField serialization with None values
...
Also added tests for HStoreField.
Thanks Aleksey Bukin for the report and Tim Graham for the initial patch and
the review.
Backport of 928c12eb1 from master.
2016-02-16 21:14:24 +01:00
Tim Graham
766fbcb1d3
[1.8.x] Fixed possible "RuntimeError: maximum recursion depth exceeded" building docs.
...
Backport of 6a71ac61bd8ebd57f036e076a4f7f29cf2d88c00 from master
2016-02-16 07:32:08 -05:00
Ryan Nowakowski
4aab1d4bb3
[1.8.x] Fixed #26221 -- Used find_packages() in reusable apps tutorial.
...
Otherwise the migrations package won't be included in the tarball.
Backport of 11af73eaeb4371ded68460c1591abd6aefa57a90 from master
2016-02-15 19:25:53 -05:00
Tim Graham
180d4cbfe6
[1.8.x] Fixed #26212 -- Made forms.FileField and translation.lazy_number() picklable.
...
Backport of b59f963ad2a49322725b20fac71661bd49643443 from master
2016-02-15 11:52:14 -05:00
Camilo Nova
b9105e7dea
[1.8.x] Added import in docs/topics/email.txt example.
...
Backport of a6f856df52d532d5537191eca237de6efdffe309 from master
2016-02-12 13:45:13 -05:00
Markus Holtermann
3af5643d82
[1.8.x] Fixed allow_migrate() signature in documentation
...
Backport of 228427ab1ab6aaafed4eacfb532f7ddb6cc1ed6c from master
2016-02-12 14:37:10 +11:00
Simon Charette
edff550392
[1.8.x] Fixed #26162 -- Checked query name clashes of hidden relationships.
...
Although reverse accessor clashes should be skipped query name can't be hidden.
Thanks to Ian Foote and Tim Graham for the review.
Backport of a325fb1f9b14b46288d0e1342407be4a6db2bdb1 from master
2016-02-08 10:42:31 -05:00
Tim Graham
2f0de9b0a1
[1.8.x] Fixed #26177 -- Fixed a PostgreSQL crash with TIME_ZONE=None and USE_TZ=False.
...
Backport of 97eb3356b2a7488c8d0ca0e47ef3e538852d44a2 from master
2016-02-08 07:45:10 -05:00
Tim Graham
b650623882
[1.8.x] Added stub release notes for 1.8.10.
...
Backport of d6337e65ed86ac0d2e55ebcbc710c42f87e0a3b6 from master
2016-02-06 09:25:02 -05:00
Carl Meyer
c247753083
[1.8.x] Fix typos in 1.8 release notes.
...
Backport of a0ce4c09ff516af52718885120c2231404515428 from master
2016-02-03 15:27:40 -05:00
Tim Graham
ea2d9f0d4a
[1.8.x] Refs #26089 -- Removed obsolete docs about custom user model testing.
...
Backport of 1e9150443e5696d764ed81c97b53ef0365a5d854 from master
2016-02-02 08:55:37 -05:00
Ramon Moraes
8488fbb2dc
Updated xhtml2pdf URL in docs.
2016-02-02 07:34:21 -05:00
Tim Graham
97f0e0ac24
[1.8.x] Added CVE-2016-2048 to the security archive.
...
Backport of ecd502cfdb57706dd0e84d9928934bcae6b1ef25 from master
2016-02-01 12:43:21 -05:00
Tim Graham
3a7c5f59ab
[1.8.x] Added release date for 1.8.9.
2016-02-01 12:13:54 -05:00
Tim Graham
229666289d
[1.8.x] Fixed #20415 -- Ensured srid isn't localized in OpenLayers JavaScript.
...
Backport of 19d1cb14519186902d7e27813bf2643fe3f7cfa3 from master
2016-01-28 18:02:36 -05:00
Yoong Kang Lim
c2dfc3616a
[1.8.x] Fixed #26136 -- Removed URL reversing by dotted path from JavaScript catalog example.
...
Backport of 31817dd2eb69db54eb559716aae42fe55ada5fea from master
2016-01-27 09:07:07 -05:00
Ben Kraft
79c3950562
[1.8.x] Fixed #26122 -- Fixed copying a LazyObject
...
Shallow copying of `django.utils.functional.LazyObject` or its subclasses has
been broken in a couple of different ways in the past, most recently due to
35355a4.
2016-01-26 06:57:47 -05:00
Tim Graham
d162438c65
[1.8.x] Fixed Sphinx highlight warnings in docs.
...
Backport of 9c43d8252a926f72be5a279186b42848501819b8 from master
2016-01-25 12:10:21 -05:00
Tim Graham
7b6ab2885e
[1.8.x] Refs #26034 -- Added another case fixed by this ticket to release notes.
...
Thanks Shai Berger for the report.
Backport of 497b5d6feee5b7947231bd0ae6edf833773b6cce from master
2016-01-25 08:37:36 -05:00
Tim Graham
bf9385e3aa
[1.8.x] Added Django version trove classifier to reusable apps tutorial.
...
Backport of 2d36c7d515312e7a476041c96a29727ed47eb517 from master
2016-01-24 08:44:30 -05:00
Tim Graham
009c697312
[1.8.x] Fixed #26121 -- Updated MySQL storage engine example.
...
default_storage_engine was introduced in MySQL 5.5.3.
storage_engine was removed in MySQL 5.7.5.
Backport of 79d0a4fdb0d13ba6a843dace2b90ab44e856bd85 from master
2016-01-22 08:22:47 -05:00
Luke Plant
a034ced2ef
[1.8.x] Changed action="."
to action=""
in tests and docs.
...
`action="."` strips query parameters from the URL which is not usually what
you want. Copy-paste coding of these examples could lead to difficult to
track down bugs or even data loss if the query parameter was meant to alter
the scope of a form's POST request.
Backport of 77974a684a2e874bccd8bd9e0939ddcb367a8ed2 from master
2016-01-21 14:00:23 -05:00
Alexander Gaevsky
8502e9f049
[1.8.x] Fixed #26060 -- Fixed crash with reverse OneToOneField in ModelAdmin.readonly_fields.
...
Backport of 9a33d3d76497d9e198de942ee1236c452231262f from master
2016-01-21 13:55:14 -05:00
Alberto Avila
5b3c66d8b6
[1.8.x] Fixed #26071 -- Fixed crash with __in lookup in a Case expression.
...
Partial backport of afe0bb7b13bb8dc4370f32225238012c873b0ee3 from master.
2016-01-13 08:38:07 -05:00
Tim Graham
f8c3d38c2d
[1.8.x] Fixed #26034 -- Fixed incorrect index handling on PostgreSQL on Char/TextField with unique=True and db_index=True.
...
Thanks Simon Charette for review.
Backport of 56aaae58a746eb39d5e92ba60f59f4c750a8e1a8 from master
2016-01-08 14:47:05 -05:00
Tim Graham
ae39a06603
[1.8.x] Fixed #26055 -- Removed an orphaned phrase in docs/howto/deployment/wsgi/modwsgi.txt.
...
Backport of db8f462494d603eba922818479a87f5ddfe1a13b from master
2016-01-08 09:39:29 -05:00
Alexander Gaevsky
40601e5797
[1.8.x] Fixed #24980 -- Fixed day determination in admin calendar widget.
...
Backport of 44930cc4667268c20493d7e97387db2a97d61a26 from master
2016-01-07 19:15:57 +03:00
Claude Paroz
61437dd0a0
[1.8.x] Fixed #26046 -- Fixed a crash with translations and Django-unknown language code
...
Thanks Jens Lundstrom for the report and Tim Graham for the review.
Backport of 632a9f21bc from master.
2016-01-06 20:34:45 +01:00
Scott Pashley
7688089e0f
[1.8.x] Fixed #26035 -- Prevented user-tools from appearing on admin logout page.
...
Backport of 7cc2efc2d6916c05a0a5cb0c0e67f5405d8f6a03 from master
2016-01-06 14:00:52 -05:00
Tim Graham
5c1de942ac
[1.8.x] Added stub release notes for 1.8.9.
...
Backport of 1e57dccb31b1302c7292dfa7eac8d8aeeb76a7d0 from master
2016-01-05 13:19:50 -05:00
Tim Graham
4fd5f06d1e
[1.8.x] Added release date for 1.8.8 release.
...
Backport of 24c1713e2ec29214838be61cc6bf13b6bf380f4f from master
2016-01-02 08:37:08 -05:00
varunnaganathan
f6b4893a9f
[1.8.x] Fixed #25316 -- Fixed a crash with order_by() and values() after annotate().
...
Backport of 3eba9638ee69138c73efb1d1c1d1b806ddafc6cf from master
2016-01-02 08:20:07 -05:00
Anssi Kääriäinen
1261c49690
[1.8.x] Fixed #23372 -- Made loaddata faster if it doesn't find any fixtures.
...
Django's test suite often tries to load fixture files from apps that have
no fixtures at all. This creates a lot of unnecessary disabling and
enabling of constraints which can be expensive on some database.
To speed this up, loaddata now first checks if any fixture file matches.
If no fixture file is matched, then the command exits before disabling
and enabling of constraints is done.
The main benefit of this change is seen on MSSQL, where tests on
Django 1.8 run hours faster.
Backport of ee9f4686b19e2b4a68f5cb4f9d61dc045c1d4c63 from master
2015-12-31 09:20:00 -05:00
Alexander Gaevsky
83174866ac
[1.8.x] Fixed #25465 -- Restored line breaks conversion in admin readonly fields.
...
Backport of 69208a5a1c55d42ca0eaffa900be643d9f801089 from master
2015-12-29 19:56:23 -05:00
Markus Bertheau
b51086d573
[1.8.x] Fixed #13008 -- Added more Cache-Control headers to never_cache() decorator.
...
Backport of 4a438e400b7ce0ab9d0b6876196cbe8d620a4171 from master
2015-12-24 11:25:50 -05:00