Alasdair Nicol
6e24eeef60
[1.8.x] Fixed 27283 -- Fixed typo in 1.8 release notes.
...
Backport of 32031718320e1b4d708b15d8c67738e4c77c9bc7 from master
2016-09-28 06:51:42 -04:00
Tim Graham
d5430a5ff9
[1.8.x] Added CVE-2016-7401 to the security release archive.
...
Backport of 6fe846a8f08dc959003f298b5407e321c6fe3735 from master
2016-09-26 18:30:31 -04:00
Tim Graham
47f5d799b2
[1.8.x] Added a CVE role for Sphinx.
...
Backport of a46742e738b91f79dd7b2e6ecba6dd1604e14d05 from master
2016-09-26 18:30:16 -04:00
Collin Anderson
6118ab7d06
[1.8.x] Fixed CVE-2016-7401 -- Fixed CSRF protection bypass on a site with Google Analytics.
...
This is a security fix.
Backport of "refs #26158 -- rewrote http.parse_cookie() to better match
browsers." 93a135d111c2569d88d65a3f4ad9e6d9ad291452 from master
2016-09-14 13:42:24 -04:00
Tim Graham
717aa88439
[1.8.x] Fixed #26807 -- Documented how to replicate SubfieldBase's assignment behavior.
...
Backport of 518eaf1fa2d86dc1b0ba7adba22b30bcc8f3a497 from master
2016-08-18 21:09:12 -04:00
Tim Graham
2deed2ea08
[1.8.x] Added CVE-2016-6186 to the security release archive.
...
Backport of bc53af13cbf09b0cbac945426c2d51d0ca52fff3 from master
2016-07-18 15:20:55 -04:00
Tim Graham
f68e5a9916
[1.8.x] Fixed XSS in admin's add/change related popup.
...
This is a security fix.
2016-07-18 13:45:11 -04:00
Jon Dufresne
8edfdddbc8
[1.8.x] Fixed #26889 -- Fixed missing PostgreSQL index in SchemaEditor.add_field().
...
Backport of 2e4cfcd2b9a0984ad6c4087a5deebbf33413835c from master
2016-07-13 22:15:43 -04:00
Tim Graham
0f12924eb5
[1.8.x] Updated release notes links to prevent warnings with Sphinx 1.4.2.
...
Backport of 149ace94dfc10504a0e69462c7737f5ce05340a4 from master
2016-06-02 11:50:26 -04:00
Tim Graham
3b2b51712b
[1.8.x] Added release date for 1.8.13.
2016-05-02 18:17:09 -04:00
Joshua Phillips
052e1f17ca
[1.8.x] Fixed #26557 -- Converted empty strings to None when saving GenericIPAddressField.
...
Backport of 4681d65048ca2553895e10c2c492997b0a78ffba from master
2016-04-29 10:17:00 -04:00
Lukasz Wiecek
0a411b2224
[1.8.x] Fixed #26498 -- Fixed TimeField microseconds round-tripping on MySQL and SQLite.
...
Thanks adamchainz for the report and review.
Backport of d3c87a2425b30400c3e6ea76585a9a537b6d0386 from master
2016-04-18 09:49:31 -04:00
Tim Graham
a61b26a651
[1.8.x] Added stub release notes for 1.8.13.
...
Backport of ad3c72118fd79d27c9f958f41d354b59d883d403 from master
2016-04-13 13:22:08 -04:00
Tim Graham
539302ee9a
[1.8.x] Added release date for 1.8.12.
...
Backport of 93539ba2f42fe56bacefd09a9e8f93b31565f746 from master
2016-04-01 13:30:53 -04:00
Tim Graham
0496838e61
[1.8.x] Fixed #26387 -- Restored the functionality of the admin's raw_id_fields in list_editable.
...
Backport of acfaec3db5ba39de52f6e607e74343dccf72fba1 from master
2016-03-25 14:57:12 -04:00
Tim Graham
c7764ca3a0
[1.8.x] Fixed #26324 -- Fixed DurationField with fractional seconds on SQLite.
...
Backport of 4f0cd0fd162122da96978b357ac9fc9534529410 from master
2016-03-10 19:16:31 -05:00
John-Mark Bell
a5e9ae9ad5
[1.8.x] Fixed #26325 -- Made MultiPartParser ignore filenames that normalize to an empty string.
...
Backport of 4b129ac81f4fa38004950d0b307f81d1e9b44af8 from master
2016-03-07 13:22:38 -05:00
Tim Graham
6d312f95f3
[1.8.x] Added stub release notes for 1.8.12.
...
Backport of c960af4adb87f8ce87f5698902b68e8332e448cb from master
2016-03-05 10:02:12 -05:00
Claude Paroz
beb392b85e
[1.8.x] Added safety to URL decoding in is_safe_url() on Python 2
...
The errors='replace' parameter to force_text altered the URL before checking
it, which wasn't considered sane. Refs 24fc935218 and ada7a4aef.
Backport of 552f03869e from master.
2016-03-04 23:39:46 +01:00
Claude Paroz
28bed24f55
[1.8.x] Fixed #26308 -- Prevented crash with binary URLs in is_safe_url()
...
This fixes a regression introduced by c5544d28923.
Thanks John Eskew for the reporti and Tim Graham for the review.
Backport of ada7a4aef from master.
2016-03-04 21:16:51 +01:00
Tim Graham
f294b3833b
[1.8.x] Added stub release notes for 1.8.11.
...
Backport of 2f0c785a4c2353a3035ba6022cec5e25fb9d569b from master
2016-03-04 09:48:11 -05:00
Alasdair Nicol
e4be3c80a1
[1.8.x] Fixed #26309 -- Documented that login URL settings no longer support dotted paths.
...
Backport of 2404d209a5e8c4573927e14587735562b79e13ed from master
2016-03-03 07:49:06 -05:00
Dmitry Dygalo
6a9bb1447c
[1.8.x] Fixed typo in 1.8.10 release date.
...
Backport of 5155c2b4587629c4bc77a11846e5b9d3ba5a43ef from master
2016-03-02 07:10:21 -05:00
Tim Graham
640c99e8b3
[1.8.x] Added CVE-2016-2512/2513 to security release archive.
...
Backport of 24fc9352183c449a8b11d1c7b442e70aa61a8800 from master
2016-03-01 12:36:20 -05:00
Florian Apolloner
f4e6e02f77
[1.8.x] Fixed CVE-2016-2513 -- Fixed user enumeration timing attack during login.
...
This is a security fix.
2016-02-29 08:07:17 -05:00
Mark Striemer
382ab13731
[1.8.x] Fixed CVE-2016-2512 -- Prevented spoofing is_safe_url() with basic auth.
...
This is a security fix.
2016-02-29 08:07:17 -05:00
Tim Graham
922f228695
[1.8.x] Added stub release notes for security issues.
2016-02-29 08:07:17 -05:00
Simon Charette
4701c81df3
[1.8.x] Fixed #26286 -- Prevented content type managers from sharing their cache.
...
This should prevent managers methods from returning content type instances
registered to foreign apps now that these managers are also attached to models
created during migration phases.
Thanks Tim for the review.
Refs #23822 .
Backport of 3938b3ccaa85f1c366909a4839696007726a09da from master
2016-02-26 16:24:28 -05:00
Jon Dufresne
6c48edae76
[1.8.x] Fixed #26267 -- Fixed BoundField to reallow slices of subwidgets.
...
Backport of b41268135995cef46d40e550f9301fab20cf330d from master
2016-02-24 07:09:08 -05:00
Tim Graham
0f667a580a
[1.8.x] Fixed #26204 -- Reallowed dashes in top-level domains for URLValidator.
...
Thanks Shai Berger for the review.
Backport of b1afebf882db5296cd9dcea26ee66d5250922e53 from master
2016-02-18 19:56:36 -05:00
Claude Paroz
5bce665974
[1.8.x] Fixed #26215 -- Fixed RangeField/ArrayField serialization with None values
...
Also added tests for HStoreField.
Thanks Aleksey Bukin for the report and Tim Graham for the initial patch and
the review.
Backport of 928c12eb1 from master.
2016-02-16 21:14:24 +01:00
Tim Graham
180d4cbfe6
[1.8.x] Fixed #26212 -- Made forms.FileField and translation.lazy_number() picklable.
...
Backport of b59f963ad2a49322725b20fac71661bd49643443 from master
2016-02-15 11:52:14 -05:00
Simon Charette
edff550392
[1.8.x] Fixed #26162 -- Checked query name clashes of hidden relationships.
...
Although reverse accessor clashes should be skipped query name can't be hidden.
Thanks to Ian Foote and Tim Graham for the review.
Backport of a325fb1f9b14b46288d0e1342407be4a6db2bdb1 from master
2016-02-08 10:42:31 -05:00
Tim Graham
2f0de9b0a1
[1.8.x] Fixed #26177 -- Fixed a PostgreSQL crash with TIME_ZONE=None and USE_TZ=False.
...
Backport of 97eb3356b2a7488c8d0ca0e47ef3e538852d44a2 from master
2016-02-08 07:45:10 -05:00
Tim Graham
b650623882
[1.8.x] Added stub release notes for 1.8.10.
...
Backport of d6337e65ed86ac0d2e55ebcbc710c42f87e0a3b6 from master
2016-02-06 09:25:02 -05:00
Carl Meyer
c247753083
[1.8.x] Fix typos in 1.8 release notes.
...
Backport of a0ce4c09ff516af52718885120c2231404515428 from master
2016-02-03 15:27:40 -05:00
Tim Graham
ea2d9f0d4a
[1.8.x] Refs #26089 -- Removed obsolete docs about custom user model testing.
...
Backport of 1e9150443e5696d764ed81c97b53ef0365a5d854 from master
2016-02-02 08:55:37 -05:00
Tim Graham
97f0e0ac24
[1.8.x] Added CVE-2016-2048 to the security archive.
...
Backport of ecd502cfdb57706dd0e84d9928934bcae6b1ef25 from master
2016-02-01 12:43:21 -05:00
Tim Graham
3a7c5f59ab
[1.8.x] Added release date for 1.8.9.
2016-02-01 12:13:54 -05:00
Tim Graham
229666289d
[1.8.x] Fixed #20415 -- Ensured srid isn't localized in OpenLayers JavaScript.
...
Backport of 19d1cb14519186902d7e27813bf2643fe3f7cfa3 from master
2016-01-28 18:02:36 -05:00
Ben Kraft
79c3950562
[1.8.x] Fixed #26122 -- Fixed copying a LazyObject
...
Shallow copying of `django.utils.functional.LazyObject` or its subclasses has
been broken in a couple of different ways in the past, most recently due to
35355a4.
2016-01-26 06:57:47 -05:00
Tim Graham
7b6ab2885e
[1.8.x] Refs #26034 -- Added another case fixed by this ticket to release notes.
...
Thanks Shai Berger for the report.
Backport of 497b5d6feee5b7947231bd0ae6edf833773b6cce from master
2016-01-25 08:37:36 -05:00
Alexander Gaevsky
8502e9f049
[1.8.x] Fixed #26060 -- Fixed crash with reverse OneToOneField in ModelAdmin.readonly_fields.
...
Backport of 9a33d3d76497d9e198de942ee1236c452231262f from master
2016-01-21 13:55:14 -05:00
Alberto Avila
5b3c66d8b6
[1.8.x] Fixed #26071 -- Fixed crash with __in lookup in a Case expression.
...
Partial backport of afe0bb7b13bb8dc4370f32225238012c873b0ee3 from master.
2016-01-13 08:38:07 -05:00
Tim Graham
f8c3d38c2d
[1.8.x] Fixed #26034 -- Fixed incorrect index handling on PostgreSQL on Char/TextField with unique=True and db_index=True.
...
Thanks Simon Charette for review.
Backport of 56aaae58a746eb39d5e92ba60f59f4c750a8e1a8 from master
2016-01-08 14:47:05 -05:00
Alexander Gaevsky
40601e5797
[1.8.x] Fixed #24980 -- Fixed day determination in admin calendar widget.
...
Backport of 44930cc4667268c20493d7e97387db2a97d61a26 from master
2016-01-07 19:15:57 +03:00
Claude Paroz
61437dd0a0
[1.8.x] Fixed #26046 -- Fixed a crash with translations and Django-unknown language code
...
Thanks Jens Lundstrom for the report and Tim Graham for the review.
Backport of 632a9f21bc from master.
2016-01-06 20:34:45 +01:00
Scott Pashley
7688089e0f
[1.8.x] Fixed #26035 -- Prevented user-tools from appearing on admin logout page.
...
Backport of 7cc2efc2d6916c05a0a5cb0c0e67f5405d8f6a03 from master
2016-01-06 14:00:52 -05:00
Tim Graham
5c1de942ac
[1.8.x] Added stub release notes for 1.8.9.
...
Backport of 1e57dccb31b1302c7292dfa7eac8d8aeeb76a7d0 from master
2016-01-05 13:19:50 -05:00
Tim Graham
4fd5f06d1e
[1.8.x] Added release date for 1.8.8 release.
...
Backport of 24c1713e2ec29214838be61cc6bf13b6bf380f4f from master
2016-01-02 08:37:08 -05:00