Mayank Singhal 
							
						 
					 
					
						
						
							
						
						76b3367035 
					 
					
						
						
							
							Fixed   #29879  -- Added CSRF_COOKIE_HTTPONLY to CSRF AJAX docs.  
						
						
						
						
					 
					
						2018-10-25 11:39:52 -04:00 
						 
				 
			
				
					
						
							
							
								Jon Dufresne 
							
						 
					 
					
						
						
							
						
						0cd465b63a 
					 
					
						
						
							
							Fixed   #29817  -- Deprecated settings.FILE_CHARSET.  
						
						
						
						
					 
					
						2018-10-15 17:15:41 -04:00 
						 
				 
			
				
					
						
							
							
								Kate Berry 
							
						 
					 
					
						
						
							
						
						b8b1d8cad6 
					 
					
						
						
							
							Improved tone in docs/ref/settings.txt.  
						
						
						
						
					 
					
						2018-10-04 11:35:19 -04:00 
						 
				 
			
				
					
						
							
							
								Jon Dufresne 
							
						 
					 
					
						
						
							
						
						82f286cf6f 
					 
					
						
						
							
							Refs  #29784  -- Switched to https:// links where available.  
						
						
						
						
					 
					
						2018-09-26 08:48:47 +02:00 
						 
				 
			
				
					
						
							
							
								Jon Dufresne 
							
						 
					 
					
						
						
							
						
						8c3e0eb1c1 
					 
					
						
						
							
							Normalized spelling of "lowercase" and "lowercased".  
						
						
						
						
					 
					
						2018-09-25 10:30:18 -04:00 
						 
				 
			
				
					
						
							
							
								Claude Paroz 
							
						 
					 
					
						
						
							
						
						e8531cc89c 
					 
					
						
						
							
							Prevented unexpected link in settings docs  
						
						
						
						
					 
					
						2018-06-10 15:11:39 +02:00 
						 
				 
			
				
					
						
							
							
								Tim Graham 
							
						 
					 
					
						
						
							
						
						5cc81cd9eb 
					 
					
						
						
							
							Reverted "Fixed  #29324  -- Made Settings raise ImproperlyConfigured if SECRET_KEY is accessed and not set."  
						
						... 
						
						
						
						This reverts commit b3cffde555 
						
						
					 
					
						2018-05-26 21:06:58 -04:00 
						 
				 
			
				
					
						
							
							
								Tim Graham 
							
						 
					 
					
						
						
							
						
						7543ab1f8d 
					 
					
						
						
							
							Removed versionadded/changed annotations for 2.0.  
						
						
						
						
					 
					
						2018-05-17 11:00:10 -04:00 
						 
				 
			
				
					
						
							
							
								Jon Dufresne 
							
						 
					 
					
						
						
							
						
						b3cffde555 
					 
					
						
						
							
							Fixed   #29324  -- Made Settings raise ImproperlyConfigured if SECRET_KEY is accessed and not set.  
						
						
						
						
					 
					
						2018-04-17 13:02:05 -04:00 
						 
				 
			
				
					
						
							
							
								Alex Gaynor 
							
						 
					 
					
						
						
							
						
						9a56b4b13e 
					 
					
						
						
							
							Fixed   #27863  -- Added support for the SameSite cookie flag.  
						
						... 
						
						
						
						Thanks Alex Gaynor for contributing to the patch. 
						
						
					 
					
						2018-04-13 20:58:31 -04:00 
						 
				 
			
				
					
						
							
							
								Tim Graham 
							
						 
					 
					
						
						
							
						
						5b589a47b9 
					 
					
						
						
							
							Fixed   #29161  -- Removed BCryptPasswordHasher from PASSWORD_HASHERS.  
						
						
						
						
					 
					
						2018-02-26 09:05:18 -05:00 
						 
				 
			
				
					
						
							
							
								Ashaba 
							
						 
					 
					
						
						
							
						
						95fd5cf459 
					 
					
						
						
							
							Fixed   #28403  -- Added missing formats in FORMAT_MODULE_PATH docs.  
						
						
						
						
					 
					
						2018-01-24 13:38:15 -05:00 
						 
				 
			
				
					
						
							
							
								Frédéric Massart 
							
						 
					 
					
						
						
							
						
						a5f1e5809f 
					 
					
						
						
							
							Clarified who the AdminEmailHandler emails.  
						
						
						
						
					 
					
						2017-11-21 11:49:15 -05:00 
						 
				 
			
				
					
						
							
							
								Дилян Палаузов 
							
						 
					 
					
						
						
							
						
						6c0042430e 
					 
					
						
						
							
							Fixed   #28776  -- Fixed a/an/and typos in docs and comments.  
						
						
						
						
					 
					
						2017-11-06 22:41:03 -05:00 
						 
				 
			
				
					
						
							
							
								Tim Graham 
							
						 
					 
					
						
						
							
						
						afd375fc34 
					 
					
						
						
							
							Fixed   #28741  -- Removed unnecessary leading dot from cross-domain cookie examples.  
						
						
						
						
					 
					
						2017-11-01 10:57:59 -04:00 
						 
				 
			
				
					
						
							
							
								Tim Graham 
							
						 
					 
					
						
						
							
						
						0edff2107f 
					 
					
						
						
							
							Refs  #28248  -- Clarified the precision of PASSWORD_RESET_TIMEOUT_DAYS.  
						
						
						
						
					 
					
						2017-10-12 14:58:18 -04:00 
						 
				 
			
				
					
						
							
							
								Jon Ribbens 
							
						 
					 
					
						
						
							
						
						44f08422c8 
					 
					
						
						
							
							Fixed   #28625  -- Distinguished DATABASES['TIME_ZONE'] from settings.TIME_ZONE.  
						
						
						
						
					 
					
						2017-09-28 09:42:08 -04:00 
						 
				 
			
				
					
						
							
							
								Tim Graham 
							
						 
					 
					
						
						
							
						
						5446b72003 
					 
					
						
						
							
							Removed versionadded/changed annotations for 1.11.  
						
						
						
						
					 
					
						2017-09-22 12:51:18 -04:00 
						 
				 
			
				
					
						
							
							
								Tim Graham 
							
						 
					 
					
						
						
							
						
						48d57788ee 
					 
					
						
						
							
							Refs  #26447  -- Removed the USE_ETAGS setting per deprecation timeline.  
						
						
						
						
					 
					
						2017-09-22 12:51:18 -04:00 
						 
				 
			
				
					
						
							
							
								Tim Graham 
							
						 
					 
					
						
						
							
						
						c7d58c6f43 
					 
					
						
						
							
							Fixed   #28435  -- Removed inaccurate warning about SECURE_HSTS_PRELOAD.  
						
						
						
						
					 
					
						2017-07-25 15:12:50 -04:00 
						 
				 
			
				
					
						
							
							
								Laura 
							
						 
					 
					
						
						
							
						
						e58c87cb70 
					 
					
						
						
							
							Fixed   #28336  -- Fixed typo in docs/ref/settings.txt.  
						
						
						
						
					 
					
						2017-06-27 21:41:10 -04:00 
						 
				 
			
				
					
						
							
							
								Mariusz Felisiak 
							
						 
					 
					
						
						
							
						
						516b7664dc 
					 
					
						
						
							
							Fixed   #28260  -- Allowed customizing the test tablespace initial and autoextend size on Oracle.  
						
						... 
						
						
						
						Thanks Tim Graham for the review. 
						
						
					 
					
						2017-06-02 18:35:56 +02:00 
						 
				 
			
				
					
						
							
							
								François Freitag 
							
						 
					 
					
						
						
							
						
						88336fdbb5 
					 
					
						
						
							
							Fixed   #28062  -- Added a setting to disable server-side cursors on PostgreSQL.  
						
						... 
						
						
						
						When a connection pooler is set up in transaction pooling mode, queries
relying on server-side cursors fail. The DISABLE_SERVER_SIDE_CURSORS
setting in DATABASES disables server-side cursors for this use case. 
						
						
					 
					
						2017-05-06 06:59:04 -04:00 
						 
				 
			
				
					
						
							
							
								Mariusz Felisiak 
							
						 
					 
					
						
						
							
						
						a3af8c99d9 
					 
					
						
						
							
							Removed extra characters in docs header underlines.  
						
						
						
						
					 
					
						2017-03-20 18:30:32 -04:00 
						 
				 
			
				
					
						
							
							
								Tim Graham 
							
						 
					 
					
						
						
							
						
						c577d8a498 
					 
					
						
						
							
							Described DEBUG_PROPAGATE_EXCEPTIONS behavior in more detail.  
						
						
						
						
					 
					
						2017-03-09 12:18:17 -05:00 
						 
				 
			
				
					
						
							
							
								Tim Graham 
							
						 
					 
					
						
						
							
						
						80493b0871 
					 
					
						
						
							
							Fixed   #27829  -- Deprecated settings.DEFAULT_CONTENT_TYPE.  
						
						
						
						
					 
					
						2017-02-16 07:59:44 -05:00 
						 
				 
			
				
					
						
							
							
								Claude Paroz 
							
						 
					 
					
						
						
							
						
						c651331b34 
					 
					
						
						
							
							Converted usage of ugettext* functions to their gettext* aliases  
						
						... 
						
						
						
						Thanks Tim Graham for the review. 
						
						
					 
					
						2017-02-07 09:04:04 +01:00 
						 
				 
			
				
					
						
							
							
								Tim Graham 
							
						 
					 
					
						
						
							
						
						e27e4c0339 
					 
					
						
						
							
							Removed versionadded/changed annotations for 1.10.  
						
						
						
						
					 
					
						2017-01-17 20:52:05 -05:00 
						 
				 
			
				
					
						
							
							
								Tim Graham 
							
						 
					 
					
						
						
							
						
						d334f46b7a 
					 
					
						
						
							
							Refs  #26601  -- Removed support for old-style middleware using settings.MIDDLEWARE_CLASSES.  
						
						
						
						
					 
					
						2017-01-17 20:52:04 -05:00 
						 
				 
			
				
					
						
							
							
								Tim Graham 
							
						 
					 
					
						
						
							
						
						9e734875fe 
					 
					
						
						
							
							Fixed   #24994  -- Documented the expected type of settings.SECRET_KEY.  
						
						
						
						
					 
					
						2016-12-28 07:36:37 -05:00 
						 
				 
			
				
					
						
							
							
								Preston Timmons 
							
						 
					 
					
						
						
							
						
						b52c73008a 
					 
					
						
						
							
							Fixed   #15667  -- Added template-based widget rendering.  
						
						... 
						
						
						
						Thanks Carl Meyer and Tim Graham for contributing to the patch. 
						
						
					 
					
						2016-12-27 17:50:10 -05:00 
						 
				 
			
				
					
						
							
							
								Tim Graham 
							
						 
					 
					
						
						
							
						
						c27104a9c7 
					 
					
						
						
							
							Fixed   #27611  -- Doc'd that CSRF_COOKIE_HTTPONLY setting offers no security.  
						
						
						
						
					 
					
						2016-12-19 17:56:58 -05:00 
						 
				 
			
				
					
						
							
							
								Raphael Michel 
							
						 
					 
					
						
						
							
						
						ddf169cdac 
					 
					
						
						
							
							Refs  #16859  -- Allowed storing CSRF tokens in sessions.  
						
						... 
						
						
						
						Major thanks to Shai for helping to refactor the tests, and to
Shai, Tim, Florian, and others for extensive and helpful review. 
						
						
					 
					
						2016-11-30 08:57:27 -05:00 
						 
				 
			
				
					
						
							
							
								Ian Lee 
							
						 
					 
					
						
						
							
						
						501c993010 
					 
					
						
						
							
							Fixed typo in docs/ref/settings.txt.  
						
						
						
						
					 
					
						2016-11-11 07:01:48 -05:00 
						 
				 
			
				
					
						
							
							
								Tim Graham 
							
						 
					 
					
						
						
							
						
						7fe2d8d940 
					 
					
						
						
							
							Fixed CVE-2016-9014 -- Validated Host header when DEBUG=True.  
						
						... 
						
						
						
						This is a security fix. 
						
						
					 
					
						2016-11-01 09:30:57 -04:00 
						 
				 
			
				
					
						
							
							
								Marti Raudsepp 
							
						 
					 
					
						
						
							
						
						da7910d483 
					 
					
						
						
							
							Fixed CVE-2016-9013 -- Generated a random database user password when running tests on Oracle.  
						
						... 
						
						
						
						This is a security fix. 
						
						
					 
					
						2016-11-01 09:30:57 -04:00 
						 
				 
			
				
					
						
							
							
								Tim Graham 
							
						 
					 
					
						
						
							
						
						de91c172cf 
					 
					
						
						
							
							Fixed   #27410  -- Clarified when static files is enabled in STATIC_ROOT docs.  
						
						
						
						
					 
					
						2016-10-31 15:17:40 -04:00 
						 
				 
			
				
					
						
							
							
								Tim Graham 
							
						 
					 
					
						
						
							
						
						414ad25b09 
					 
					
						
						
							
							Fixed   #27327  -- Simplified time zone handling by requiring pytz.  
						
						
						
						
					 
					
						2016-10-27 08:53:20 -04:00 
						 
				 
			
				
					
						
							
							
								Marti Raudsepp 
							
						 
					 
					
						
						
							
						
						51fbe2a60d 
					 
					
						
						
							
							Updated postgresql.org links to https and made them canonical.  
						
						
						
						
					 
					
						2016-10-25 11:43:32 -04:00 
						 
				 
			
				
					
						
							
							
								Denis Cornehl 
							
						 
					 
					
						
						
							
						
						a840710e1e 
					 
					
						
						
							
							Fixed   #26447  -- Deprecated settings.USE_ETAGS in favor of ConditionalGetMiddleware.  
						
						
						
						
					 
					
						2016-10-10 14:55:59 -04:00 
						 
				 
			
				
					
						
							
							
								Tim Graham 
							
						 
					 
					
						
						
							
						
						9819676676 
					 
					
						
						
							
							Updated links to the current version of MySQL docs.  
						
						
						
						
					 
					
						2016-09-30 09:14:17 -04:00 
						 
				 
			
				
					
						
							
							
								Tim Graham 
							
						 
					 
					
						
						
							
						
						43c471e81c 
					 
					
						
						
							
							Fixed typo in docs/ref/settings.txt.  
						
						
						
						
					 
					
						2016-09-15 19:52:49 -04:00 
						 
				 
			
				
					
						
							
							
								Tim Graham 
							
						 
					 
					
						
						
							
						
						ef021412d5 
					 
					
						
						
							
							Normalized spelling of ETag.  
						
						
						
						
					 
					
						2016-09-09 11:00:21 -04:00 
						 
				 
			
				
					
						
							
							
								Ed Morley 
							
						 
					 
					
						
						
							
						
						1d54fb4483 
					 
					
						
						
							
							Made settings docs link to cache parameters more specific.  
						
						
						
						
					 
					
						2016-08-31 12:31:30 -04:00 
						 
				 
			
				
					
						
							
							
								Chris Jerdonek 
							
						 
					 
					
						
						
							
						
						a3db480393 
					 
					
						
						
							
							Fixed   #27061  -- Added a TEST['TEMPLATE'] setting for PostgreSQL.  
						
						
						
						
					 
					
						2016-08-23 15:08:20 -04:00 
						 
				 
			
				
					
						
							
							
								Ed Morley 
							
						 
					 
					
						
						
							
						
						3c2447dd13 
					 
					
						
						
							
							Fixed   #26947  -- Added an option to enable the HSTS header preload directive.  
						
						
						
						
					 
					
						2016-08-10 20:23:54 -04:00 
						 
				 
			
				
					
						
							
							
								Ed Morley 
							
						 
					 
					
						
						
							
						
						8c3bc5cd78 
					 
					
						
						
							
							Fixed docs to refer to HSTS includeSubdomains as a directive.  
						
						... 
						
						
						
						The spec refers to it as a 'directive' rather than a 'tag':
https://tools.ietf.org/html/rfc6797#section-6.1.2  
						
						
					 
					
						2016-08-08 20:20:49 -04:00 
						 
				 
			
				
					
						
							
							
								Claude Paroz 
							
						 
					 
					
						
						
							
						
						255fb99284 
					 
					
						
						
							
							Fixed   #17209  -- Added password reset/change class-based views  
						
						... 
						
						
						
						Thanks Tim Graham for the review. 
						
						
					 
					
						2016-07-16 10:36:12 +02:00 
						 
				 
			
				
					
						
							
							
								Tim Graham 
							
						 
					 
					
						
						
							
						
						944e66cb1d 
					 
					
						
						
							
							Reverted "Fixed  #25388  -- Added an option to allow disabling of migrations during test database creation"  
						
						... 
						
						
						
						This reverts commit 157d7f1f1d 
						
						
					 
					
						2016-07-14 09:21:28 -04:00 
						 
				 
			
				
					
						
							
							
								Claude Paroz 
							
						 
					 
					
						
						
							
						
						78963495d0 
					 
					
						
						
							
							Refs  #17209  -- Added LoginView and LogoutView class-based views  
						
						... 
						
						
						
						Thanks Tim Graham for the review. 
						
						
					 
					
						2016-06-24 10:45:13 +02:00