diff --git a/docs/releases/1.4.txt b/docs/releases/1.4.txt index 585e7ff591..1e3c6032b2 100644 --- a/docs/releases/1.4.txt +++ b/docs/releases/1.4.txt @@ -777,6 +777,17 @@ instance: * Time period: The amount of time you expect user to take filling out such forms. +* ``contrib.auth`` user password hash-upgrade sequence + + * Consequences: Each user's password will be updated to a stronger password + hash when it's written to the database in 1.4. This means that if you + upgrade to 1.4 and then need to downgrade to 1.3, version 1.3 won't be able + to read the updated passwords. + + * Remedy: Set :setting:`PASSWORD_HASHERS` to use your original password + hashing when you initially upgrade to 1.4. After you confirm your app works + well with Django 1.4 and you won't have to roll back to 1.3, enable the new + password hashes. django.contrib.flatpages ~~~~~~~~~~~~~~~~~~~~~~~~