2018-08-31 17:01:29 +08:00
|
|
|
==========================
|
|
|
|
Django 2.1.2 release notes
|
|
|
|
==========================
|
|
|
|
|
2018-10-01 16:10:48 +08:00
|
|
|
*October 1, 2018*
|
2018-08-31 17:01:29 +08:00
|
|
|
|
2018-09-13 21:08:41 +08:00
|
|
|
Django 2.1.2 fixes a security issue and several bugs in 2.1.1. Also, the latest
|
|
|
|
string translations from Transifex are incorporated.
|
|
|
|
|
|
|
|
CVE-2018-16984: Password hash disclosure to "view only" admin users
|
|
|
|
===================================================================
|
|
|
|
|
|
|
|
If an admin user has the change permission to the user model, only part of the
|
|
|
|
password hash is displayed in the change form. Admin users with the view (but
|
|
|
|
not change) permission to the user model were displayed the entire hash. While
|
|
|
|
it's typically infeasible to reverse a strong password hash, if your site uses
|
|
|
|
weaker password hashing algorithms such as MD5 or SHA1, it could be a problem.
|
2018-08-31 17:01:29 +08:00
|
|
|
|
|
|
|
Bugfixes
|
|
|
|
========
|
|
|
|
|
2018-09-07 04:10:20 +08:00
|
|
|
* Fixed a regression where nonexistent joins in ``F()`` no longer raised
|
|
|
|
``FieldError`` (:ticket:`29727`).
|
2018-09-12 00:51:11 +08:00
|
|
|
|
|
|
|
* Fixed a regression where files starting with a tilde or underscore weren't
|
|
|
|
ignored by the migrations loader (:ticket:`29749`).
|
2018-09-14 11:33:17 +08:00
|
|
|
|
|
|
|
* Made migrations detect changes to ``Meta.default_related_name``
|
|
|
|
(:ticket:`29755`).
|
2018-09-16 18:45:34 +08:00
|
|
|
|
|
|
|
* Added compatibility for ``cx_Oracle`` 7 (:ticket:`29759`).
|
2018-09-26 04:00:20 +08:00
|
|
|
|
|
|
|
* Fixed a regression in Django 2.0 where unique index names weren't quoted
|
|
|
|
(:ticket:`29778`).
|
2018-09-27 02:18:48 +08:00
|
|
|
|
|
|
|
* Fixed a regression where sliced queries with multiple columns with the same
|
|
|
|
name crashed on Oracle 12.1 (:ticket:`29630`).
|
2018-09-28 07:52:01 +08:00
|
|
|
|
|
|
|
* Fixed a crash when a user with the view (but not change) permission made a
|
|
|
|
POST request to an admin user change form (:ticket:`29809`).
|