1
0
mirror of https://github.com/django/django.git synced 2025-01-15 12:52:31 +00:00

13609 Commits

Author SHA1 Message Date
Shai Berger
3394fc6132 [5.0.x] Fixed CVE-2024-27351 -- Prevented potential ReDoS in Truncator.words().
Thanks Seokchan Yoon for the report.

Co-Authored-By: Mariusz Felisiak <felisiak.mariusz@gmail.com>
2024-03-04 08:22:40 +01:00
Shafiya Adzhani
80761c3b01 [5.0.x] Fixed #35198 -- Fixed facet filters crash on querysets with no primary key.
Thanks Simon Alef for the report.

Regression in 868e2fcddae6720d5713924a785339d1665f1bb9.

Backport of a738281265bba5d00711ab62d4d37923764a27eb from main
2024-02-29 10:37:26 +01:00
kbehlers
24de8113a8 [5.0.x] Fixed typo in docs/ref/contrib/admin/index.txt.
Backport of 3cb1ba50ccde5b33d6bc5b7cc1ea22c8af3c2aa3 from main
2024-02-29 08:31:46 +01:00
Mariusz Felisiak
bf7fedc446 [5.0.x] Removed #django-geo IRC channel in docs.
It's been inactive for several years.
Backport of 11695b8fdd002362be8d5dc48bc78db09ddf33d8 from main
2024-02-28 19:06:32 +01:00
David Sanders
a8de04f8db [5.0.x] Refs #34964 -- Doc'd that Q expression order is preserved.
Backport of 7714ccfeae969aca52ad46c1d69a13fac4086c08 from main
2024-02-28 13:06:30 +01:00
Mariusz Felisiak
b1f2833bc4 [5.0.x] Added release date for 5.0.3, 4.2.11, and 3.2.25.
Backport of 977d25416954a72ad100b01762078bf1ceb89a63 from main
2024-02-26 08:27:34 +01:00
Carlton Gibson
5d9be66c98 [5.0.x] Removed distracting note from tutorial 4.
The note on a possible race condition is inappropriate in this
tutorial setting. To quote Diátaxis:

> Your job is to guide the learner to a successful conclusion. There
> may be many interesting diversions along the way … - ignore them.

Co-Authored-By: Ryan Hiebert <ryan@ryanhiebert.com>

Backport of 0a646c8e08605ba6896ef8f2938231d23c2181cc from main
2024-02-21 08:15:19 +01:00
AlexCLeduc
69e5b13c75 [5.0.x] Fixed #35238 -- Fixed database serialization crash when base managers use prefetch_related().
Regression in 139135627650ed6aaaf4c755b82c3bd43f2b8f51
following deprecation in eedbf930287cb72e9afab1f7208c24b1146b0c4ec.

Backport of a084c5d35a6d00abd261338a374a4424764b4aee from main
2024-02-21 05:17:36 +01:00
sandjio
e72fdc850a [5.0.x] Fixed #35153 -- Added note about locale name notation to FORMAT_MODULE_PATH docs.
Co-authored-by: Paul Hermans <paul.hermans@benemtech.com>

Backport of 9bd849c8d5c587209a231af643a17ec2db802ab2 from main
2024-02-20 06:11:51 +01:00
Adam Johnson
23c7cbfd24 [5.0.x] Fixed #28011 -- Corrected Field.hidden docs.
Backport of 7ba6c9edc50dc989fc5c306b541636249b952f93 from main
2024-02-17 19:22:20 +01:00
Mariusz Felisiak
41a4bba817 [5.0.x] Fixed #35187 -- Fixed @sensitive_variables/sensitive_post_parameters decorators crash with .pyc-only builds.
Thanks Jon Janzen for the implementation idea.

Thanks Marcus Hoffmann for the report.

Regression in 38e391e95fe5258bc6d2467332dc9cd44ce6ba52.
Backport of d1be05b3e9209fd0787841c71a95819d81061187 from main
2024-02-17 08:16:36 +01:00
Hisham Mahmood
3a54e64ef7 [5.0.x] Fixed #35173 -- Fixed ModelAdmin.lookup_allowed() for lookups on foreign keys when not included in ModelAdmin.list_filter.
Regression in f80669d2f5a5f1db9e9b73ca893fefba34f955e7.

Thanks Sarah Boyce for the review.
Backport of 8db593de05c3516c939b7d4b9eb91e8791f4c79a from main
2024-02-15 08:18:27 -03:00
Vašek Dohnal
761e913191 [5.0.x] Fixed #35174 -- Fixed Signal.asend()/asend_robust() crash when all receivers are asynchronous.
Regression in e83a88566a71a2353cebc35992c110be0f8628af.

Backport of 1b5338d03ecc962af8ab4678426bc60b0672b8dd from main
2024-02-08 12:56:41 +01:00
Mariusz Felisiak
c22075af80 [5.0.x] Fixed #35172 -- Fixed intcomma for string floats.
Thanks Warwick Brown for the report.

Regression in 55519d6cf8998fe4c8f5c8abffc2b10a7c3d14e9.
Backport of 2f14c2cedc9c92373471c1f98a80c81ba299584a from main
2024-02-08 10:59:43 +01:00
Koo
540b28ff9f [5.0.x] Fixed typo in docs/internals/contributing/writing-code/coding-style.txt.
Backport of aaffbabd58c8f3c9bf82cd4eb98b8c5cb9e7aa6a from main
2024-02-08 05:58:49 +01:00
Natalia
fec087a45f [5.0.x] Added CVE-2024-24680 to security archive.
Backport of c650c1412d1933e339cc93f9b6745c3eedb1c25b from main
2024-02-06 12:16:27 -03:00
Natalia
d6f14b2209 [5.0.x] Added stub release notes for 5.0.3.
Backport of f61bc0319748876763e98be1c2933a03d59b7c34 from main
2024-02-06 12:09:54 -03:00
Adam Johnson
16a8fe18a3 [5.0.x] Fixed CVE-2024-24680 -- Mitigated potential DoS in intcomma template filter.
Thanks Seokchan Yoon for the report.

Co-authored-by: Mariusz Felisiak <felisiak.mariusz@gmail.com>
Co-authored-by: Natalia <124304+nessita@users.noreply.github.com>
Co-authored-by: Shai Berger <shai@platonix.com>
2024-02-06 09:13:21 -03:00
shivaramkumar
2cfa3fba0c [5.0.x] Changed severity levels to list in security policy docs.
Backport of a47de0d6cd440d4515ede48df8335d91d7ac7793 from main
2024-02-05 05:37:35 +01:00
Simon Charette
761946f8e1 [5.0.x] Fixed #35149 -- Fixed crashes of db_default with unresolvable output field.
Field.db_default accepts either literal Python values or compilables
(as_sql) and wrap the former ones in Value internally.

While 1e38f11 added support for automatic resolving of output fields for
types such as str, int, float, and other unambigous ones it's cannot do
so for all types such as dict or even contrib.postgres and contrib.gis
primitives.

When a literal, non-compilable, value is provided it likely make the
most sense to bind its output field to the field its attached to avoid
forcing the user to provide an explicit `Value(output_field)`.

Thanks David Sanders for the report.

Backport of e67d7d70fa10c06aca36b9057f82054eda45269d from main
2024-02-04 14:48:44 +01:00
Simon Charette
3e7a30fb3a [5.0.x] Fixed #35162 -- Fixed crash when adding fields with db_default on MySQL.
MySQL doesn't allow literal DEFAULT values to be used for BLOB, TEXT,
GEOMETRY or JSON columns and requires expression to be used instead.

Regression in 7414704e88d73dafbcfbb85f9bc54cb6111439d3.

Backport of dfc77637ea5c1aa81caa72b1cf900e6931d61b54 from main
2024-02-04 09:24:38 +01:00
Petar Netev
741f080ab5 [5.0.x] Fixed #35147 -- Added backward incompatibility note about filtering against overflowing integers.
Backport of 0630ca5725ba5b17c61cd1f6a05dce2660c4724e from main
2024-02-01 20:36:50 +01:00
Ebram Shehata
58d5e5779c [5.0.x] Fixed typo in docs/topics/db/managers.txt.
Backport of 2152246c0a4408df7716c84b20bd0fa79a31179b from main
2024-02-01 09:26:24 +01:00
Priya
a8f9c29d4b [5.0.x] Removed mention of designers in DTL design philosophy.
Signed-off-by: Priya Pahwa <pahwa.priya19@gmail.com>
Backport of 6f2c7cf6b41f9346feff0098319c302c15cef9a3 from main
2024-02-01 09:20:53 +01:00
James Thorniley
f1fbd061ac [5.0.x] Fixed #35059 -- Ensured that ASGIHandler always sends the request_finished signal.
Prior to this work, when async tasks that process the request are cancelled due
to receiving an early "http.disconnect" ASGI message, the request_finished
signal was not being sent, potentially leading to resource leaks (such as
database connections).

This branch ensures that the request_finished signal is sent even in the case
of early termination of the response.

Regression in 64cea1e48f285ea2162c669208d95188b32bbc82.

Co-authored-by: Natalia <124304+nessita@users.noreply.github.com>
Co-authored-by: Carlton Gibson <carlton.gibson@noumenal.es>

Backport of 11393ab1316f973c5fbb534305750740d909b4e4 from main
2024-01-31 14:45:44 -03:00
Ben Cail
d28c61b777 [5.0.x] Fixed #35156 -- Removed outdated note about not supporting foreign keys by SQLite.
Backport of b3dc80682e678b20c89fb2a430c0bc77960a29ac from main
2024-01-31 18:35:30 +01:00
Mariusz Felisiak
7453d6a807 [5.0.x] Fixed #35159 -- Fixed dumpdata crash when base querysets use prefetch_related().
Regression in 139135627650ed6aaaf4c755b82c3bd43f2b8f51
following deprecation in edbf930287cb72e9afab1f7208c24b1146b0c4ec.

Thanks Andrea F for the report.
Backport of 38eaf2f21a2398a8dd8444f6df3723898cb5fe2a from main
2024-01-31 16:10:50 +01:00
evananyonga
2822cafa3c [5.0.x] Corrected BaseCommand.check() signature in docs.
Backport of ae8baaee9d717cb48d59514b7130e35ae921d265 from main
2024-01-30 11:41:26 +01:00
Nicolas Delaby
a5440054d2 [5.0.x] Fixed #35135 -- Made FilteredRelation raise ValueError on querysets as rhs.
Regression in 59f475470494ce5b8cbff816b1e5dafcbd10a3a3.

Backport of 820c5f1bacd41713bd30d8b5fefb66752ff15c4c from main
2024-01-30 05:54:39 +01:00
Alexander Lazarević
28d6db26a2 [5.0.x] Fixed #35141 -- Clarified the expected type of CACHE_MIDDLEWARE_SECONDS setting.
Backport of a5365339eaee043895a79dbbdd7462f1399136e5 from main
2024-01-29 19:24:10 +01:00
Natalia
f588c444fd [5.0.x] Added stub release notes and release date for 5.0.2, 4.2.10, and 3.2.24.
Backport of 06d0a1bd56a9899c351ca047a05813e8dd6a4e17 from main
2024-01-29 11:47:13 -03:00
Claude Paroz
3cc35aafab [5.0.x] Updated translations from Transifex. 2024-01-29 05:22:31 +01:00
Mariusz Felisiak
0379e7532f [5.0.x] Applied Black's 2024 stable style.
https://github.com/psf/black/releases/tag/24.1.0

Backport of 305757aec19c9d5111e4d76095ae0acd66163e4b from main
2024-01-26 12:55:56 +01:00
duranbe
b2601a77f9 [5.0.x] Fixed #34971 -- Doc'd additional loggers.
Co-authored-by: duranbe <benoit.durand.mail@gmail.com>
Co-authored-by: Natalia <124304+nessita@users.noreply.github.com>

Backport of 0450c9bdf1773297c61b4e36850ab997ffd5dde2 from main
2024-01-24 08:48:17 -03:00
Adrienne Franke
d490d009a3 [5.0.x] Fixed typo in docs/topics/auth/default.txt.
Backport of 8570e091d025c4aacc6b76597a3322030c2f8162 from main
2024-01-22 17:43:46 +01:00
Adam Johnson
60bc65eb80 [5.0.x] Fixed tutorial 'background.gif' reference.
Missed in 76fda7729e4cdfec715cd92b2c80d851797b05f7.
Backport of a5622f84ab0ba0ebb30c2b85f2b85d8aef75f337 from main
2024-01-22 05:26:15 +01:00
Emmanuel Katchy
c4a6a8d815 [5.0.x] Updated "Dive Into Python" links.
Backport of 12ffcfc350a19bbfbc203126a9b6c84b5e0d0ba2 from main
2024-01-20 22:22:49 +01:00
Mariusz Felisiak
ee78fe390d [5.0.x] Fixed #35127 -- Made Model.full_clean() ignore GeneratedFields.
Thanks Claude Paroz for the report.

Regression in f333e3513e8bdf5ffeb6eeb63021c230082e6f95.
Backport of 4879907223d70ee1a82474d9286ccfa5dae96971 from main
2024-01-19 08:56:14 +01:00
Salvo Polizzi
4ed1423de4 [5.0.x] Fixed #35121 -- Corrected color for links in the admin.
Thanks Collin Anderson for the report.

Regression in 6ad2738a8f32b94cbae742f212080fadf2dee421.

Backport of 10c7c7320baf1c655fcb91202169d77725c9c4bd from main
2024-01-18 14:07:23 +01:00
Baptiste Mispelon
a7b35aa7c9 [5.0.x] Used more specific link to email backends in EMAIL_BACKEND docs.
Backport of 1592f0ac220c1fd37779f6d33efb28ebd60e2e66 from main
2024-01-16 20:10:39 +01:00
jordanbae
dd2d76803c [5.0.x] Fixed #34949 -- Clarified when UniqueConstraints with include/nulls_distinct are not created.
Backport of 4fec1d2ce37241fb8fa001971c441d360ed2a196 from main
2024-01-15 14:16:12 +01:00
evananyonga
d56b2105b6 [5.0.x] Made management command examples more consistent in docs.
Backport of ec7651586d2d94e1ccd8f905c6a3776ad936b62d from main
2024-01-09 20:56:46 +01:00
Sarah Boyce
4cba6748a6 [5.0.x] Fixed #35087 -- Reallowed filtering against foreign keys not listed in ModelAdmin.list_filters.
Regression in f80669d2f5a5f1db9e9b73ca893fefba34f955e7.

Backport of a9094ec1f43dca7f2a649327afcd5e6226b4959c from main
2024-01-08 14:25:32 +01:00
Adam Johnson
4818a139f7 [5.0.x] Fixed #35084 -- Recommended 'django_' prefix for reusable app modules.
Backport of 05f124348e72c1dcf1f6e5de72ffc1f67ad9aa77 from main
2024-01-04 11:58:33 +01:00
Adam Johnson
ef8234aef8 [5.0.x] Refs #33690 -- Updated tutorial for admin dark mode toggle.
Backport of c65f49d3cb8709f2f694f78b4849bc7693e90416 from main
2024-01-03 22:18:45 +01:00
Mariusz Felisiak
abb2448f17 [5.0.x] Added stub release notes for 5.0.2.
Backport of f412add786dfc18424eee6281ec8cc97220b04fc from main
2024-01-02 10:35:04 +01:00
Mariusz Felisiak
01d2f94cfd [5.0.x] Added release date for 5.0.1 and 4.2.9.
Backport of f82a2c3b3d553f36661cfdce5261bffb669d68a9 from main
2024-01-02 09:58:37 +01:00
Zowie Beha
031bc47101 [5.0.x] Fixed #35072 -- Corrected Field.choices description in models topic.
Backport of 8fcd7b01eec85a509762dd8dbb3a27b7ab521e94 from main
2024-01-02 05:24:24 +01:00
Salvo Polizzi
c69dbc7c10 [5.0.x] Fixed #35069 -- Fixed typo in docs/ref/forms/api.txt.
Backport of dc26a3d563b1e1d98d40f5d351a6a61c34f12d98 from main
2023-12-30 15:00:33 +01:00
Mohammad Yameen
c8274ecfe2 [5.0.x] Corrected method/function wording in tutorial 3.
Backport of bb560651c489879c22878cba5003a09b6a9f930a from main
2023-12-29 06:01:47 +01:00