1
0
mirror of https://github.com/django/django.git synced 2025-10-31 09:41:08 +00:00
Commit Graph

14245 Commits

Author SHA1 Message Date
SaJH
ace59cb83b [5.2.x] Fixed #36431 -- Returned tuples for multi-column ForeignObject in values()/values_list().
Thanks Jacob Walls and Simon Charette for tests.

Signed-off-by: SaJH <wogur981208@gmail.com>

Backport of bb7a7701b1 from main
2025-08-29 15:36:09 -04:00
Mustafa Pirbhai
16a12a9799 [5.2.x] Fixed #35831 -- Documented the model form meta API in model form reference docs.
Co-authored-by: Jonathan <3218047+jernwerber@users.noreply.github.com>
Co-authored-by: Mustafa <117516335+mspirbhai@users.noreply.github.com>

Backport of 183fcebf88 from main.
2025-08-29 09:00:37 +02:00
Sarah Boyce
51753bc809 [5.2.x] Added stub release notes and release date for 5.2.6, 5.1.12, and 4.2.24.
Backport of 4c71e33440 from main.
2025-08-27 16:07:46 +02:00
Jacob Walls
a486455125 [5.2.x] Corrected definition of "needsinfo" triage stage in contributing guide.
Backport of 66082a7dac from main
2025-08-27 09:22:26 -04:00
Jacob Walls
f8e572e843 [5.2.x] Removed reference to flake8 file exclusions.
Obsolete since 41384812ef.
(six was removed in 9285926295fbfc86b70e7be8d595d4cfbe7895b8.)
Backport of 165ad74c57 from main
2025-08-23 20:06:54 +02:00
Mariusz Felisiak
9c9ed6fd7a [5.2.x] Refs #35530 -- Corrected deprecation message in auth.alogin().
Follow up to ceecd518b1.

Backport of b3166e1e15 from main.
2025-08-22 16:15:42 +02:00
Mariusz Felisiak
98972b53aa [5.2.x] Corrected release notes of calling format_html() without arguments.
Backport of bcddf641ae from main
2025-08-20 07:35:30 +02:00
mengxun
38844c348b [5.2.x] Fixed spelling of "logged-in" when used as an adjective in docs.
Backport of f5c944b314 from main.
2025-08-19 12:43:52 -03:00
David Sanders
4926591343 [5.2.x] Aligned format of constraint examples in docs/ref/models/constraints.txt.
Backport of fda3c1712a from main.
2025-08-13 09:16:06 +02:00
Rohit
1d9f6c3270 [5.2.x] Corrected code examples in topics docs.
Backport of fa804d0d14 from main.
2025-08-11 10:14:43 +02:00
Sarah Boyce
ad836aa0c5 [5.2.x] Added stub release notes for 5.2.6.
Backport of 0bff53b413 from main.
2025-08-06 10:36:46 +02:00
Sarah Boyce
0489f54e8b [5.2.x] Added release date for 5.2.5.
Backport of 8999b0e2bf from main.
2025-08-06 09:59:50 +02:00
David Smith
a9c7d4b703 [5.2.x] Refs #36485 -- Grouped docs checks under a unified make check target.
Added a new 'check' rule to the docs Makefile which runs both the black
and spelling checks.

Backport of 7f9bf357fe from main.
2025-08-05 12:20:13 -03:00
David Smith
5ad6d43cd9 [5.2.x] Refs #34140 -- Added dedicated code block formatting section in docs/internals/contributing/writing-documentation.txt.
Backport of cba7328196 from main.
2025-08-05 12:20:04 -03:00
jkhall81
bdc3f9e350 [5.2.x] Fixed #36530 -- Extended fields.E347 to check for ManyToManyField involving CompositePrimaryKey on either side.
Thanks to Jacob Walls for the report.

Backport of 2013092b69 from main.
2025-08-05 08:46:56 -03:00
Natalia
f01ceae477 [5.2.x] Fixed #36535 -- Ensured compatibility with docutils 0.19 through 0.22.
Regression in 65ab92f6a8.

Backport of 9cec8d9f55 from main.
2025-08-04 21:53:33 -03:00
Adam Zapletal
5ca58ce3d0 [5.2.x] Corrected assertNumQueries() example in docs/topics/testing/tools.txt.
Backport of dca8284a37 from main.
2025-08-04 15:08:53 +02:00
Simon Charette
b3bb7230e1 [5.2.x] Fixed #34871, #36518 -- Implemented unresolved lookups expression replacement.
This allows the proper resolving of lookups when performing constraint
validation involving Q and Case objects.

Thanks Andrew Roberts for the report and Sarah for the tests and review.

Backport of 079d31e698 from main.
2025-08-04 09:42:32 +02:00
Simon Charette
3031c512f0 [5.2.x] Fixed #36522 -- Added support for filtering composite pks using a tuple of expressions.
Thanks Jacob Walls for the report, and Sarah Boyce and Mariusz Felisiak
for reviews.

Backport of 0a4999b422 from main.
2025-07-28 16:40:08 -03:00
Jordan Bae
28f33f50b2 [5.2.x] Moved manual testing instructions from intro to submitting patches docs.
The section on manual testing, including how to use a local checkout of
Django, is moved from the contribution intro to the submitting patches
docs. This makes it easier for reviewers and authors to follow best
practices.

Backport of fdeca38072 from main.
2025-07-28 09:02:15 -03:00
Mike Edmunds
c1356333b6 [5.2.x] Fixed typo in docs/topics/email.txt.
Backport of f551aeb003 from main.
2025-07-25 13:32:23 +02:00
Thibaud Colas
6e71386118 [5.2.x] Added accessibility guidelines for contributors.
Backport of 5527df9192 from main.
2025-07-23 16:42:23 +02:00
Mike Edmunds
6966adc519 [5.2.x] Fixed get_connection() signature in docs/topics/email.txt.
django.core.mail.get_connection() has always supported only variable
keyword arguments (never variable positional arguments).

Backport of 5289ce65b9 from main.
2025-07-17 14:02:01 -03:00
Clifford Gama
1c2e11c7f4 [5.2.x] Fixed typo in docs/ref/utils.txt.
Backport of ac2d907f45 from main
2025-07-13 19:38:44 +02:00
Tim Schilling
e5080fc5e9 [5.2.x] Added Django ecosystem page to the documentation.
Backport of 395e498553 from main
2025-07-13 15:06:58 +02:00
Simon Charette
3df1ad57bf [5.2.x] Fixed #36502 -- Restored UNNEST strategy for foreign key bulk inserts on PostgreSQL.
Regression in 764af7a3d6.

Backport of 0fe218842e from main.
2025-07-10 18:36:01 +02:00
Natalia
abc10ab7f9 [5.2.x] Added release date for 5.2.4.
Backport of 94ebcf8366 from main.
2025-07-02 15:56:47 -03:00
Natalia
4da3446c92 [5.2.x] Added stub release notes for 5.2.5.
Backport of 7ab6b863da from main.
2025-07-02 15:51:38 -03:00
Simon Charette
a150160c9f [5.2.x] Fixed #36464 -- Fixed "__in" tuple lookup on backends lacking native support.
When native support for tuple lookups is missing in a DB backend, it can
be emulated with an EXISTS clause. This is controlled by the backend
feature flag "supports_tuple_lookups".

The mishandling of subquery right-hand side in `TupleIn` (added to
support `CompositePrimaryKey` in Refs #373) was likely missed because
the only core backend we test with the feature flag disabled
(Oracle < 23.4) supports it natively.

Thanks to Nandana Raol for the report, and to Sarah Boyce, Jacob Walls,
and Natalia Bidart for reviews.

Backport of 192bc7a7be from main.
2025-06-30 20:16:08 -03:00
Jake Howard
db5da3c91c [5.2.x] Clarified that only latest dependency versions are valid for security reports.
Backport of bc1bfe12b6 from main.
2025-06-18 11:05:15 -03:00
nessita
359af3779a [5.2.x] Added guidance on AI-assisted security reports to docs/internals/security.txt.
Co-authored-by: Shai Berger <shai@platonix.com>
Co-authored-by: Mike Edmunds <medmunds@gmail.com>

Backport of 0f60102444 from main.
2025-06-17 11:45:48 -03:00
Clifford Gama
1d89691c74 [5.2.x] Fixed #36453 -- Made When.condition resolve with for_save=False.
Value(None, JSONField()) when used in When.condition incorrectly resolved with
for_save=True, resulting in the value being serialized as SQL NULL instead of
JSON null.

Regression in c1fa3fdd04.

Thanks to Thomas McKay for the report, and to David Sanders and Simon Charettes
for the review.

Co-authored-by: Sarah Boyce <42296566+sarahboyce@users.noreply.github.com>

Backport of 104cbfd44b from main.
2025-06-16 10:41:24 +02:00
Jake Howard
4de4edf2c0 [5.2.x] Fixed #36447 -- Selected preferred media type based on quality.
When matching which entry in the `Accept` header should be used for
a given media type, the specificity matters. However once those are
resolved, only the quality matters when selecting preference.

Regression in c075508b4d.

Thank you to Anders Kaseorg for the report.

Backport of 12c1557060 from main.
2025-06-16 09:27:46 +02:00
Sarah Boyce
f5cc6a888b [5.2.x] Corrected jsonfield fieldlookup references.
Backport of 8e2249bc79 from main.
2025-06-13 09:53:30 +02:00
Sulove Bista
538616136b [5.2.x] Fixed #36463 -- Fixed grammar in docs/intro/contributing.txt.
Backport of e80b33ae4d from main.
2025-06-12 15:14:52 -03:00
ruvilonix
e3b2370795 [5.2.x] Fixed #36454 -- Fixed typo in docs/intro/tutorial08.txt.
Backport of 87a5ae6c5b from main.
2025-06-12 09:56:39 +02:00
junghwan16
91569cffec [5.2.x] Fixed #36425 -- Standardized integer fields descriptions.
Backport of 091f66e51a from main.
2025-06-11 10:00:21 +02:00
Sarah Boyce
329a5c9228 [5.2.x] Added follow-up to CVE-2025-48432 to security archive.
Backport of 2714bc3f2c from main.
2025-06-10 15:11:54 +02:00
Sarah Boyce
69fe089f00 [5.2.x] Added stub release notes for 5.2.4.
Backport of 7fcc7b1a0c from main.
2025-06-10 12:31:19 +02:00
Jacob Walls
264003146f [5.2.x] Refs #373 -- Doc'd that on_delete is ignored for ForeignObject.
Backport of 76e1ca77bc from main.
2025-06-10 09:48:25 +02:00
Jacob Walls
6f99c8856d [5.2.x] Fixed #36449 -- Fixed field types in example model using ForeignObject.
Backport of 5942754769 from main.
2025-06-10 09:47:37 +02:00
Natalia
cc5079730a [5.2.x] Fixed #36446 -- Restored "q" in internal MediaType.params property.
The "q" key was removed while addressing ticket #36411. Despite
`MediaType.params` is undocumented and considered internal, it was used
in third-party projects (Zulip reported breakage), so this work restored
the `q` key in `params`.

Thanks Anders Kaseorg for the report.

Regression in c075508b4d.

Backport of cf5f36bf90 from main.
2025-06-09 17:39:25 -03:00
Clifford Gama
6fc620b4a8 [5.2.x] Fixed #36419 -- Ensured for_save was propagated when resolving expressions.
The for_save flag wasn't properly propagated when resolving expressions, which
prevented get_db_prep_save() from being called in some cases. This affected
fields like JSONField where None would be saved as JSON null instead of SQL NULL.

Regression in 00c690efbc.

Thanks to David Sanders and Simon Charette for reviews.

Co-authored-by: Adam Johnson <me@adamj.eu>

Backport of c1fa3fdd04 from main.
2025-06-06 17:41:51 +02:00
Jake Howard
8fcc83953c [5.2.x] Refs CVE-2025-48432 -- Prevented log injection in remaining response logging.
Migrated remaining response-related logging to use the `log_response()`
helper to avoid potential log injection, to ensure untrusted values like
request paths are safely escaped.

Co-authored-by: Natalia <124304+nessita@users.noreply.github.com>

Backport of 9579517552 from main.
2025-06-06 09:07:12 -03:00
Sarah Boyce
5901cfe591 [5.2.x] Updated translations from Transifex. 2025-06-06 13:55:05 +02:00
Natalia
48a82d44d8 [5.2.x] Added CVE-2025-48432 to security archive.
Backport of 51923c576a from main.
2025-06-04 10:58:40 -03:00
Natalia
3bc3ce8e64 [5.2.x] Added stub release notes for 5.2.3.
Backport of 1f19c36e2d from main.
2025-06-04 10:56:00 -03:00
Natalia
7456aa23da [5.2.x] Fixed CVE-2025-48432 -- Escaped formatting arguments in log_response().
Suitably crafted requests containing a CRLF sequence in the request
path may have allowed log injection, potentially corrupting log files,
obscuring other attacks, misleading log post-processing tools, or
forging log entries.

To mitigate this, all positional formatting arguments passed to the
logger are now escaped using "unicode_escape" encoding.

Thanks to Seokchan Yoon (https://ch4n3.kr/) for the report.

Co-authored-by: Carlton Gibson <carlton@noumenal.es>
Co-authored-by: Jake Howard <git@theorangeone.net>

Backport of a07ebec559 from main.
2025-06-04 08:34:51 -03:00
Simon Charette
3340d41446 [5.2.x] Fixed #36432 -- Fixed a prefetch_related crash on related target subclass queryset.
Regression in 626d77e52a.

Refs #36116.

Thanks Cornelis Poppema for the excellent report.

Backport of 08187c94ed from main.
2025-06-04 10:48:13 +02:00
Jake Howard
0c548e62d0 [5.2.x] Fixed #36411 -- Made HttpRequest.get_preferred_type() consider media type parameters.
HttpRequest.get_preferred_type() did not account for parameters in
Accept header media types (e.g., "text/vcard; version=3.0"). This caused
incorrect content negotiation when multiple types differed only by
parameters, reducing specificity as per RFC 7231 section 5.3.2
(https://datatracker.ietf.org/doc/html/rfc7231.html#section-5.3.2).

This fix updates get_preferred_type() to treat media types with
parameters as distinct, allowing more precise and standards-compliant
matching.

Thanks to magicfelix for the report, and to David Sanders and Sarah
Boyce for the reviews.

Backport of c075508b4d from main.
2025-06-03 16:11:38 -03:00