2023-04-03 11:17:54 +02:00
|
|
|
==========================
|
|
|
|
Django 4.2.1 release notes
|
|
|
|
==========================
|
|
|
|
|
2023-04-20 09:01:59 +02:00
|
|
|
*May 3, 2023*
|
2023-04-03 11:17:54 +02:00
|
|
|
|
2023-04-20 09:01:59 +02:00
|
|
|
Django 4.2.1 fixes a security issue with severity "low" and several bugs in
|
|
|
|
4.2.
|
2023-04-03 11:17:54 +02:00
|
|
|
|
2023-04-13 10:10:56 +02:00
|
|
|
CVE-2023-31047: Potential bypass of validation when uploading multiple files using one form field
|
|
|
|
=================================================================================================
|
|
|
|
|
|
|
|
Uploading multiple files using one form field has never been supported by
|
|
|
|
:class:`.forms.FileField` or :class:`.forms.ImageField` as only the last
|
|
|
|
uploaded file was validated. Unfortunately, :ref:`uploading_multiple_files`
|
|
|
|
topic suggested otherwise.
|
|
|
|
|
|
|
|
In order to avoid the vulnerability, :class:`~django.forms.ClearableFileInput`
|
|
|
|
and :class:`~django.forms.FileInput` form widgets now raise ``ValueError`` when
|
|
|
|
the ``multiple`` HTML attribute is set on them. To prevent the exception and
|
|
|
|
keep the old behavior, set ``allow_multiple_selected`` to ``True``.
|
|
|
|
|
|
|
|
For more details on using the new attribute and handling of multiple files
|
|
|
|
through a single field, see :ref:`uploading_multiple_files`.
|
|
|
|
|
2023-04-03 11:17:54 +02:00
|
|
|
Bugfixes
|
|
|
|
========
|
|
|
|
|
2023-04-04 16:58:15 -04:00
|
|
|
* Fixed a regression in Django 4.2 that caused a crash of ``QuerySet.defer()``
|
|
|
|
when deferring fields by attribute names (:ticket:`34458`).
|
2023-04-05 19:34:16 +02:00
|
|
|
|
|
|
|
* Fixed a regression in Django 4.2 that caused a crash of
|
|
|
|
:class:`~django.contrib.postgres.search.SearchVector` function with ``%``
|
|
|
|
characters (:ticket:`34459`).
|
2023-04-06 08:19:53 -04:00
|
|
|
|
|
|
|
* Fixed a regression in Django 4.2 that caused aggregation over query that
|
|
|
|
uses explicit grouping to group against the wrong columns (:ticket:`34464`).
|
2023-04-06 12:44:37 -07:00
|
|
|
|
|
|
|
* Reallowed, following a regression in Django 4.2, setting the
|
|
|
|
``"cursor_factory"`` option in :setting:`OPTIONS` on PostgreSQL
|
|
|
|
(:ticket:`34466`).
|
2023-04-07 10:11:41 +02:00
|
|
|
|
|
|
|
* Enforced UTF-8 client encoding on PostgreSQL, following a regression in
|
|
|
|
Django 4.2 (:ticket:`34470`).
|
2023-04-06 19:40:14 +02:00
|
|
|
|
|
|
|
* Fixed a regression in Django 4.2 where ``i18n_patterns()`` didn't respect the
|
|
|
|
``prefix_default_language`` argument when a fallback language of the default
|
|
|
|
language was used (:ticket:`34455`).
|
2023-04-12 09:25:45 +02:00
|
|
|
|
2023-04-28 08:05:43 +02:00
|
|
|
* Fixed a regression in Django 4.2 where translated URLs of the default
|
|
|
|
language from ``i18n_patterns()`` with ``prefix_default_language`` set to
|
|
|
|
``False`` raised 404 errors for a request with a different language
|
|
|
|
(:ticket:`34515`).
|
|
|
|
|
2023-04-12 09:25:45 +02:00
|
|
|
* Fixed a regression in Django 4.2 where creating copies and deep copies of
|
2023-04-12 09:46:18 +02:00
|
|
|
``HttpRequest``, ``HttpResponse``, and their subclasses didn't always work
|
|
|
|
correctly (:ticket:`34482`, :ticket:`34484`).
|
2023-04-13 13:16:33 -03:00
|
|
|
|
|
|
|
* Fixed a regression in Django 4.2 where ``timesince`` and ``timeuntil``
|
|
|
|
template filters returned incorrect results for a datetime with a non-UTC
|
|
|
|
timezone when a time difference is less than 1 day (:ticket:`34483`).
|
2023-04-13 21:07:32 +10:00
|
|
|
|
|
|
|
* Fixed a regression in Django 4.2 that caused a crash of
|
|
|
|
:class:`~django.contrib.postgres.search.SearchHeadline` function with
|
|
|
|
``psycopg`` 3 (:ticket:`34486`).
|
2023-04-21 19:49:59 +02:00
|
|
|
|
|
|
|
* Fixed a regression in Django 4.2 that caused incorrect ``ClearableFileInput``
|
|
|
|
margins in the admin (:ticket:`34506`).
|
2023-04-26 08:36:56 +02:00
|
|
|
|
|
|
|
* Fixed a regression in Django 4.2 where breadcrumbs didn't appear on admin
|
|
|
|
site app index views (:ticket:`34512`).
|
2023-05-03 13:06:19 +02:00
|
|
|
|
|
|
|
* Made squashing migrations reduce ``AddIndex``, ``RemoveIndex``,
|
|
|
|
``RenameIndex``, and ``CreateModel`` operations which allows removing a
|
|
|
|
deprecated ``Meta.index_together`` option from historical migrations and use
|
|
|
|
``Meta.indexes`` instead (:ticket:`34525`).
|