Commit Graph

12111 Commits

Author SHA1 Message Date
Carl Meyer 9936fdb11d [1.4.x] Added ALLOWED_HOSTS setting for HTTP host header validation.
This is a security fix; disclosure and advisory coming shortly.
2013-02-19 10:37:54 -07:00
Tim Graham 57b62a74cb [1.4.x] Fixed #19824 - Corrected the class described for Field.primary_key from IntegerField to AutoField.
Thanks Keryn Knight.

Backport of 218bbef0c4 from master
2013-02-16 18:34:34 -05:00
Tim Graham 83e512fa6e [1.4.x] Fixed #19812 - Removed a duplicate phrase in the widget docs.
Thanks diegueus9 for the report and itsallvoodoo for the draft patch.

Backport of 7a80904b00 from master
2013-02-16 18:25:22 -05:00
Alex Hunley 3d6388941d [1.4.x] Fixed #19719 - Removed misleading example from ModelForm documentation
Backport of 976dc07baf from master
2013-02-16 18:09:43 -05:00
Tim Graham 9eb7d59665 [1.4.x] Fixed #19815 - Removed an unused import in tutorial 3.
Thanks pedro.calcao@ for the report.
2013-02-12 20:04:15 -05:00
Anssi Kääriäinen dec7dd99f0 [1.4.x] Removed try-except in django.db.close_connection()
The reason was that the except clause needed to remove a connection
from the django.db.connections dict, but other parts of Django do not
expect this to happen. In addition the except clause was silently
swallowing the exception messages.

Refs #19707, special thanks to Carl Meyer for pointing out that this
approach should be taken.
2013-02-13 00:39:43 +02:00
Claude Paroz b4fb448f83 Fixed WSGIPythonPath instruction in deployment docs
Partial backport of 3abf6105b6 from master. Refs #19042.
2013-02-11 08:42:09 +01:00
Anssi Kääriäinen 209f174e58 [1.4.x] Made custom m2m fields without through easier to use
The change in f105fbe52b made through=None
m2m fields fail in cases where they worked before. It isn't possible to
create such fields using public APIs. The fix is trivial, so it seems
worth fixing this for custom m2m field users.

This is not a backport from master. Master has gotten enough other
changes to related fields internal API that this fix alone isn't enough
to do any good.
2013-02-10 21:57:05 +02:00
Anssi Kääriäinen 9918b3f502 [1.4.x] Fixed #19707 -- Reset transaction state after requests
Backpatch of a4e97cf315.
2013-02-10 17:34:38 +02:00
Anssi Kääriäinen 498a5de07b [1.4.x] Fixed #19645 -- Added tests for TransactionMiddleware
Backpatch of f556df90be. Backpatching
these tests so that it will be easier to backpatch the fix for #19707.
2013-02-10 17:34:27 +02:00
Tim Graham 056b2b5f65 [1.4.x] Fixed #19756 - Corrected a ManyToMany example and added some links and markup.
Backport of 43efefae69 from master
2013-02-07 07:04:52 -05:00
Claude Paroz ec93ecdd10 [1.4.x] Fixed #19702 -- Changed a SQL command syntax to be MySQL 4-compatible
Thanks matf at op.pl for the report.
2013-02-02 14:24:35 +01:00
Claude Paroz 3610d11ba0 [1.5.x] Lowered field ordering requirement in ogrinspect test
This test was randomly failing depending on the library environment.
Backport of a1c470a6f from master.
2013-02-02 14:08:59 +01:00
Claude Paroz 6bd3896fcb [1.4.x] Fixed #18144 -- Added backwards compatibility with old unsalted MD5 passwords
Thanks apreobrazhensky at gmail.com for the report.
Backport of 63d6a50dd from master.
2013-02-02 12:10:38 +01:00
Tim Graham 89ba1b27b4 [1.4.x] Fixed #19555 - Removed '2012' from tutorial 1.
Thanks rodrigorosa.lg and others for the report.

Backport of 99315f709e from master
2013-01-17 16:41:05 -05:00
Tim Graham c26541f5cb [1.4.x] Addeded CSS to bold deprecation notices.
Thanks Sam Lai for mentioning this on the mailing list.

Backport of 227bd3f8db from master
2013-01-09 19:05:20 -05:00
Tim Graham c4a9e5bd8d [1.4.X] Fixed #19506 - Remove 'mysite' prefix in model example.
Thanks Mike O'Connor for the report.

Backport of 52a2588df6 from master
2012-12-21 15:53:44 -05:00
Ramiro Morales 6474105107 [1.4.x] Added PASSWORD_HASHERS to settings reference document.
abd0f304b1 from master.
2012-12-19 15:13:06 -03:00
Alex Gaynor 8ab2aceb65 [1.4.X] Fixed #18099 -- corrected a typo in the initial data docs. Thanks to Bradley Ayers for the patch.
Backport of f5a9e5e9 from master
2012-12-15 16:42:19 -05:00
Florian Apolloner f2530dcb17 [1.4.X] Fixed a test failure in the comment tests.
Backport of 1eb0da1c5b from master.
2012-12-10 23:37:12 +01:00
James Bennett 1f0af3c529 [1.4.x] Bump version numbers for security release. 2012-12-10 15:45:04 -06:00
Florian Apolloner 319627c184 [1.4.X] Fixed a security issue in get_host.
Full disclosure and new release forthcoming.
2012-12-10 22:14:16 +01:00
Florian Apolloner b2ae0a63ae [1.4.X] Fixed #18856 -- Ensured that redirects can't be poisoned by malicious users. 2012-12-10 22:14:16 +01:00
Julien Phalip 8c9a8fd5c4 [1.4.x] Fixed the admin_filters tests for Postgres.
Backport of c196e01100
2012-12-04 10:41:22 -08:00
Sebastián Magrí c72172244e [1.4.x] Fixed #19318 -- Ensured that the admin's SimpleListFilter options can be displayed as selected even if the lookup's first element is not a string.
Backport of 88e1715639
2012-12-03 20:58:54 -08:00
Anssi Kääriäinen 3e4058be9f [1.4.x] Fixed ordering-related failure in m2m_through_regress tests
Backpatch of dc569c8801
2012-11-24 16:10:16 +02:00
Aymeric Augustin 046300c43b [1.4.x] Restored Python 2.5 compatibility in m2m_through_regress tests.
Refs #18823.
2012-11-24 09:49:30 +01:00
Anssi Kääriäinen c7dcb1d808 [1.4.x] Fixed SQLite's collapsing of same-valued instances in bulk_create
SQLite used INSERT INTO tbl SELECT %s UNION SELECT %s, the problem
was that there should have been UNION ALL instead of UNION.

Refs #19351

Backpatch of a27582484c
2012-11-24 01:28:25 +02:00
Tim Graham 9ee9a7265a [1.4.X] Fixed #19317 - Added an image for warning blocks in the docs
Thanks tome for the suggestion and patch.

Backport of 3587991ba8 from master
2012-11-22 08:50:50 -05:00
Preston Holmes 19710955e4 [1.4.x] Added examples of using startproject/app with URLs
thanks to Brent O'Connor for the idea and intial docs
2012-11-21 22:08:31 -08:00
Luke Plant 9003d6fece [1.4.x] Corrected docs about default value of MESSAGE_STORAGE
Backport of a32f30c79c from master
2012-11-20 23:18:26 +00:00
Tim Graham 06c14a63a2 [1.4.X] Fixed #13997 - Added an example of constructing a MultiWidget and documented the value_from_datadict method.
Backport of 04775b4598 from master
2012-11-17 17:55:28 -05:00
Anssi Kääriäinen 25e041f270 [1.4.x] Fixed #19058 -- Fixed Oracle GIS crash
The problem is the same as in #10888 which was reintroduced when
bulk_insert was added. Thanks to Jani Tiainen for report, patch and
also testing the final patch on Oracle GIS.

Backpatch of 92d7f541da
2012-11-15 16:22:28 +02:00
Nicolas Ippolito fdb855e7b2 [1.4.X] Typo in comments doc
Backport of 17b14d4819 from master
2012-11-13 05:25:55 -05:00
Aymeric Augustin f8c005b4ec Fixed #19225 -- Typo in shortcuts docs.
Thanks SunPowered for the report.
2012-11-02 09:30:42 +01:00
Aymeric Augustin 2733253633 [1.4.x] Fixed #19208 -- Docs for mod_wsgi daemon mode
Thanks Graham Dumpleton for the patch.

Backport of bc00075 from master.
2012-10-29 21:40:32 +01:00
Claude Paroz ad2d57a2cc [1.4.x] Fixed #19172 -- Isolated poisoned_http_host tests from 500 handlers
Thanks bernardofontes for the report.

Backport of b774c5993 from master.
2012-10-29 17:30:51 +01:00
Anssi Kääriäinen 37c87b785d [1.4.x] Fixed #18823 -- Ensured m2m.clear() works when using through+to_field
There was a potential data-loss issue involved -- when clearing
instance's m2m assignments it was possible some other instance's
m2m data was deleted instead.

This commit also improved None handling for to_field cases.

Backpatch of 611c4d6f1c
2012-10-28 17:38:26 +02:00
Tim Graham baf1f1dcde [1.4.X] Fixed #9471 - Expanded ModelAdmin.raw_id_fields docs; thanks adroffne for the suggestion.
Backport of da958eb209 from master
2012-10-24 17:50:37 -04:00
Carl Meyer ce168bb899 [1.4.x] Fix an HTML-parser test that's failed in Python 2.6.8 since 5c79dd58.
The problem description in #18239 asserted that
http://bugs.python.org/issue670664 was fixed in Python 2.6.8, but based on
http://bugs.python.org/issue670664#msg146770 it appears that's not correct; the
fix was only applied in 2.7, 3.2, and Python trunk. Therefore we must use our
patched HTMLParser subclass in all Python 2.6 versions.

Backport of fcec904e4f from master. Fixes #19148.
2012-10-23 18:57:59 +02:00
Preston Holmes e86e4ce0bd Added 1.4.2 release notes 2012-10-21 07:50:30 -07:00
Tim Graham 6c1c490f64 [1.4.X] Fixed #13869 - Warned that QuerySet.iterator() doesn't affect DB driver caching; thanks jtiai for the suggestion.
Backport of 2f722d9728 from master
2012-10-20 15:23:06 -04:00
Tim Graham 13bbe9161d [1.4.x] Fixed arguments for get_inline_instances; refs #17006. 2012-10-20 09:57:51 -04:00
Tim Graham e7685b87c1 [1.4.X] Fixed #17006 - Documented ModelAdmin get_form() and get_formsets()
Backport of eed4faf16f from master
2012-10-20 08:42:24 -04:00
Tim Graham 700717db1f [1.4.X] Fixed #17388 - Noted in the custom model field docs that field methods need to handle None if the field may be null.
Backport of 4cef9a09f9 from master
2012-10-19 17:54:38 -04:00
Tim Graham fd90a90633 [1.4.X] Fixed #18046 - Documented that an index is created by default for ForeignKeys; thanks jbauer for the suggestion.
Backport of db598dd8a0 from master
2012-10-18 16:59:23 -04:00
Preston Holmes 773a29295a Added missed poisoned host header test changes 2012-10-18 11:18:25 -07:00
James Bennett 8c46ead92b [1.4.x] Bump ALL the version numbers. 2012-10-17 17:17:37 -05:00
James Bennett 0f54fed0b6 [1.4.x] Bump version numbers for security release. 2012-10-17 17:15:49 -05:00
Preston Holmes 58806ce153 Fixed an error in the set cookie documentation 2012-10-17 14:57:58 -07:00