Mariusz Felisiak
67a79dcf5b
[4.1.x] Added release date for 4.1.8.
...
Backport of fdf0a367bdd72c70f91fb3aed77dabbe9dcef69f from main
2023-04-05 06:19:38 +02:00
David Wobrock
ba1654cb54
[4.1.x] Fixed #34384 -- Fixed session validation when rotation secret keys.
...
Bug in 0dcd549bbe36c060f536ec270d34d9e7d4b8e6c7.
Thanks Eric Zarowny for the report.
Backport of 2396933ca99c6bfb53bda9e53968760316646e01 from main
2023-03-08 11:33:47 +01:00
Mariusz Felisiak
ff3e3eb2bd
[4.1.x] Added stub release notes for 4.1.8.
...
Backport of 9a07999aef7958c9b5441e368cd90646d0edc5c9 from main
2023-03-06 17:38:07 +01:00
Carlton Gibson
991461a3b3
[4.1.x] Added CVE-2023-24580 to security archive.
...
Backport of ecafcaf634fcef93f9da8cb12795273dd1c3a576 from main
2023-02-14 09:53:25 +01:00
Markus Holtermann
628b33a854
[4.1.x] Fixed CVE-2023-24580 -- Prevented DoS with too many uploaded files.
...
Thanks to Jakob Ackermann for the report.
2023-02-14 08:24:06 +01:00
Sota Tabu
425c75f56f
[4.1.x] Fixed #34318 -- Added release note for 4bfe8c0eec835b8eaffcda7dc1e3b203751a790a.
...
Backport of 3e9d413231edc29768cc7ca0427e63b19233f562 from main
2023-02-13 14:13:36 +01:00
Mariusz Felisiak
590a92e456
[4.1.x] Fixed #34319 -- Fixed Model.validate_constraints() crash on ValidationError with no code.
...
Thanks Mateusz Kurowski for the report.
Regression in 667105877e6723c6985399803a364848891513cc.
Backport of 2fd755b361d3da2cd0440fc9839feb2bb69b027b from main
2023-02-08 16:40:38 +01:00
Carlton Gibson
ae53649b38
[4.1.x] Added stub release notes for 4.0.10 and 3.2.18.
...
Set date for 4.1.7 release.
Backport of 7e003428f96d616c1f77fed84882a95e63bc3644 from main
2023-02-07 10:12:12 +01:00
Mariusz Felisiak
83c88af9f8
[4.1.x] Added stub release notes for 4.1.7.
...
Backport of f3c89744cc801cc7d134bca9958c4a74aa76380f from main
2023-02-01 13:22:50 +01:00
Mariusz Felisiak
9ac634ff26
[4.1.x] Added CVE-2023-23969 to security archive.
...
Backport of 36e3eef7d5a4c88671d20a561788679d0d9c334c from main
2023-02-01 12:10:18 +01:00
Nick Pope
9d7bd5a56b
[4.1.x] Fixed CVE-2023-23969 -- Prevented DoS with pathological values for Accept-Language.
...
The parsed values of Accept-Language headers are cached in order to
avoid repetitive parsing. This leads to a potential denial-of-service
vector via excessive memory usage if the raw value of Accept-Language
headers is very large.
Accept-Language headers are now limited to a maximum length in order
to avoid this issue.
2023-02-01 09:46:23 +01:00
Mariusz Felisiak
26b7a25632
[4.1.x] Fixed #34291 -- Fixed Meta.constraints validation crash on UniqueConstraint with ordered expressions.
...
Thanks Dan F for the report.
Bug in 667105877e6723c6985399803a364848891513cc.
Backport of 2b1242abb3989f5d74e787b09132d01bcbee5b55 from main.
2023-01-26 09:34:15 +01:00
Carlton Gibson
bc48c7dfd6
[4.1.x] Adjusted release notes for 4.1.6, 4.0.9, and 3.2.17.
...
Backport of d8e1442ce2c56282785dd806e5c1147975e8c857 from main
2023-01-25 12:27:07 +01:00
Carlton Gibson
bb59ef749f
[4.1.x] Set date and added stub release notes for 4.1.6, 4.0.9, and 3.2.17.
...
Backport of 1df963ad2476726d63be132c0cee47e07b8250d7 from main
2023-01-25 11:58:50 +01:00
Steven
d805010d68
[4.1.x] Fixed "nulls characters" typo in docs.
...
Backport of 4b7016866a80ec8582f55fc7eedfa692039e9648 from main
2023-01-16 08:24:21 +01:00
Mariusz Felisiak
f6d138eeff
[4.1.x] Added stub release notes for 4.1.6.
...
Backport of 75500feecddcb27b6ab65c9057e7317024cef761 from main
2023-01-02 08:51:44 +01:00
Mariusz Felisiak
7bcf84d363
[4.1.x] Added release date for 4.1.5.
...
Backport of 174d8157b5700f6451ac0bdc3eef7e73121bc4a4 from main
2023-01-02 08:11:41 +01:00
Mariusz Felisiak
46b28bbe15
[4.1.x] Updated translations from Transifex.
...
Updated Bulgarian, Esperanto, Hungarian, Japanese, Macedonian, Persian,
Portuguese (Brazil), Russian, Spanish, and Turkmen translations.
2022-12-20 19:33:28 +01:00
James Gillard
af3cfc8630
[4.1.x] Fixed #34205 -- Fixed Meta.constraints validation crash with ArrayField and __len lookup.
...
Regression in 88fc9e2826044110b7b22577a227f122fe9c1fb5 that began
manifesting in Django 4.1.
Backport of c5ed884eabf3b2b67581c55bf6c87e721f69157f from main.
2022-12-10 19:39:00 +01:00
Carlton Gibson
c2dadbcbf0
[4.1.x] Added stub release notes for 4.1.5.
...
Backport of 845a5db38fd3d2695af8cece78951729936a0196 from main
2022-12-06 10:21:44 +01:00
Carlton Gibson
65d31d9e41
[4.1.x] Added release date for 4.1.4.
...
Backport of f4a053a2940c2e5324550cd796724a5837362cba from main
2022-12-06 09:57:26 +01:00
Mariusz Felisiak
423fa4c072
[4.1.x] Updated various links to HTTPS and new locations.
...
Backport of 514884e9a555c51afba3d26d9370a908af4752a6 from main
2022-12-06 06:00:34 +01:00
Mariusz Felisiak
58156f4ed7
[4.1.x] Refs #33397 , Refs #34160 -- Added release note for resolving output_field changes.
...
Backport of e8dcef155c1848ef49e54f787a7d20faf3bf9296 from main
2022-11-30 08:22:29 +01:00
DevilsAutumn
170322451a
[4.1.x] Fixed #34171 -- Fixed QuerySet.bulk_create() on fields with db_column in unique_fields/update_fields.
...
Bug in 0f6946495a8ec955b471ca1baaf408ceb53d4796.
Thanks Joshua Brooks for the report.
Backport of 4035bab56f2862a25cd7bfba41a84e58672cb1cc from main
2022-11-22 20:04:38 +01:00
Mariusz Felisiak
3b0a8ea299
[4.1.x] Fixed #34177 -- Fixed QuerySet.bulk_create() crash on "pk" in unique_fields.
...
Bug in 0f6946495a8ec955b471ca1baaf408ceb53d4796.
Backport of 7d5329852f19c6ae78c6f6f3d3e41835377bf295 from main
2022-11-22 14:26:48 +01:00
Jon Janzen
9fb57fcc70
[4.1.x] Fixed #34139 -- Fixed acreate(), aget_or_create(), and aupdate_or_create() methods for related managers.
...
Bug in 58b27e0dbb3d31ca1438790870b2b51ecdb10500.
Backport of 7b94847e384b1a8c05a7d4c8778958c0290bdf9a from main
2022-11-08 08:13:56 +01:00
Daniel Ivanov
eca526eab0
[4.1.x] Fixed #34088 -- Fixed Sitemap.get_latest_lastmod() crash with empty items.
...
Bug in 480191244d12fefbf95854b2b117c71ffe44749a.
Thanks Michal Čihař for the report.
Backport of 5eab4d1924613a5506e517f157054b4852ae7dc2 from main
2022-11-07 07:57:11 +01:00
Mariusz Felisiak
84a2b2e7a7
[4.1.x] Fixed #34138 -- Avoided table rebuild when adding inline m2m fields on SQLite.
...
Regression in 2f73e5406d54cb8945e187eff302a3a3373350be.
Thanks David Wobrock for the report.
Backport of 7b0e9ea53ca99de2f485ec582f3a79be34b531d4 from main
2022-11-04 09:31:30 +01:00
Mariusz Felisiak
e8ea852f07
[4.1.x] Added stub release notes for 4.1.4.
...
Backport of c765b62e3258de4dce9935ab7aed430346dfbc10 from main
2022-11-01 07:31:24 +01:00
Mariusz Felisiak
cf69b9f7ef
[4.1.x] Added release date for 4.1.3.
...
Backport of 635e5643b3921e278dbddf8f13ecb66f17cd6aee from main
2022-11-01 06:59:26 +01:00
Mariusz Felisiak
ddf3ee6f9e
[4.1.x] Refs #33173 -- Doc'd Python 3.11 compatibility in Django 4.1.x.
...
Backport of eb6cc01d0f62c73441a3610193ba210176d0935f from main.
2022-10-26 20:13:41 +02:00
Carlton Gibson
84814412a0
[4.1.x] Fixed #34085 -- Made management commands don't use black for non-Python files.
...
Bug in d113b5a837f726d1c638d76c4e88445e6cd59fd5.
Co-authored-by: programmylife <acmshar@gmail.com>
Co-authored-by: Carlton Gibson <carlton.gibson@noumenal.es>
Backport of 5c2c7277d4554db34c585477b269bb1acfcbbe56 from main.
2022-10-20 14:38:40 -07:00
Carlton Gibson
e9a24a15f2
[4.1.x] Added CVE-2022-36359 to security archive.
...
Backport of 93d4c9ea1de24eb391cb2b3561b6703fd46374df from main
2022-10-04 10:12:35 +02:00
Carlton Gibson
324d4fcbe1
[4.1.x] Added stub release notes for 4.1.3 release.
...
Backport of 7a089273236cf79a6c8a3db7a622fb89872ebe37 from main
2022-10-04 09:49:47 +02:00
Adam Johnson
9d656ea51d
[4.1.x] Fixed CVE-2022-41323 -- Prevented locales being interpreted as regular expressions.
...
Thanks to Benjamin Balder Bach for the report.
2022-10-04 09:12:42 +02:00
Mariusz Felisiak
7843c43c49
[4.1.x] Refs #32987 -- Relaxed system check for template tag modules with the same name by turning into a warning.
...
Thanks Claude Paroz for the report.
Regression in 004b4620f6f4ad87261e149898940f2dcd5757ef.
Backport of f71b0cf769d9ac582ee3d1a8c33d73dad3a770da from main
2022-10-03 10:52:47 +02:00
Mariusz Felisiak
7a1675806a
[4.1.x] Fixed #33984 -- Reverted "Fixed #32980 -- Made models cache related managers."
...
This reverts 4f8c7fd9d91b35e2c2922de4bb50c8c8066cbbc6 and adds
two regression tests:
- test_related_manager_refresh(), and
- test_create_copy_with_m2m().
Thanks joeli for the report.
Backport of 5e0aa362d91d000984995ce374c2d7547d8d107f from main
2022-09-30 18:19:36 +02:00
Antoine Lorence
ecf6506f44
[4.1.x] Fixed #34062 -- Updated View.http_method_not_allowed() to support async.
...
As with the options() methods, wrap the response in a coroutine if
the view is async.
Co-authored-by: Carlton Gibson <carlton.gibson@noumenal.es>
Backport of 9b0c9821ed4dd9920cc7c5e7b657720d91a89bdc from main
2022-09-29 16:29:34 +02:00
Mariusz Felisiak
97353bc64b
[4.1.x] Fixed #34058 -- Changed sequence types when altering pre-Django 4.1 auto fields on PostgreSQL.
...
Thanks Anders Kaseorg for the report.
Thanks Florian Apolloner for pair programming.
Regression in 2eea361eff58dd98c409c5227064b901f41bd0d6.
Backport of 19e6efa50b603af325e7f62058364f278596758f from main
2022-09-29 13:20:55 +02:00
Adam Johnson
b826b38847
[4.1.x] Refs #34010 -- Made --debug-mode work for parallel tests using spawn.
...
Bug in 3b3f38b3b09b0f2373e51406ecb8c9c45d36aebc.
Thanks Kevin Renskers for the report.
Backport of 0f5b11eca0ba199501941fa244b276aaa10353c8 from main
2022-09-28 20:40:23 +02:00
Adam Johnson
5630a6ca29
[4.1.x] Fixed #34010 -- Made parallel tests using spawn set up Django.
...
Bug in 3b3f38b3b09b0f2373e51406ecb8c9c45d36aebc.
Thanks Kevin Renskers for the report.
Backport of 4a910f3de35338df7d4fcd8b7729fd1e31edaad0 from main
2022-09-28 20:40:12 +02:00
David Sanders
33d9247c8b
[4.1.x] Fixed #34025 -- Fixed selecting ModelAdmin.autocomplete_fields after adding/changing related instances via popups.
...
Regression in c72f6f36c13a21f6db3d4f85d2d3cec87bad45e6.
Thanks Alexandre da Silva for the report.
Backport of 9976f3d4b80cfb2e6f4c998438622b78eb1ac53e from main
2022-09-28 12:54:48 +02:00
Carlton Gibson
fba7962bac
[4.1.x] Set date and added stub notes for 4.1.2, 4.0.8, and 3.2.16 releases.
...
Backport of c2bc71b635e3ca637b6920f30fb3dcc92037cee2 and
f08651c06cb5fe5a6181354e053bf82fe8d68f16 from main.
2022-09-27 10:11:25 +02:00
Jacob Walls
e151df24ae
[4.1.x] Fixed typo in docs/releases/3.2.1.txt.
...
Backport of cfe3008123ed7c9e3f3a4d51d4a22f9d96634e33 from main
2022-09-19 05:19:45 +02:00
Alexander Kerkum
2d20386b41
[4.1.x] Fixed #34016 -- Fixed QuerySet.values()/values_list() crash on ArrayAgg() and JSONBAgg().
...
Regression in e06dc4571ea9fd5723c8029959b95808be9f8812.
Backport of f88fc72da4eb76f2d464edb4874ef6046f8a8658 from main
2022-09-18 07:39:47 +02:00
David Sanders
be5e3b46f7
[4.1.x] Fixed #33996 -- Fixed CheckConstraint validation on NULL values.
...
Bug in 667105877e6723c6985399803a364848891513cc.
Thanks James Beith for the report.
Backport of e14d08cd894e9d91cb5d9f44ba7532c1a223f458 from main
2022-09-13 14:06:46 +02:00
Simon Charette
e0f14d8389
[4.1.x] Fixed #33992 -- Fixed queryset crash when aggregating over a group containing Exists.
...
A more in-depth solution is likely to make sure that we always GROUP BY
selected annotations or revisit how we use Query.exists() in the Exists
expression but that requires extra work that isn't suitable for a
backport.
Regression in e5a92d400acb4ca6a8e1375d1ab8121f2c7220be.
Thanks Fernando Flores Villaça for the report.
Backport of 32536b1324e98768dd892980408a8c6b26c23fd9 from main
2022-09-08 08:13:15 +02:00
James Beith
7ba9a44831
[4.1.x] Fixed #33982 -- Fixed migrations crash when adding model with ExclusionConstraint.
...
Regression in 0e656c02fe945389246f0c08f51c6db4a0849bd2.
Backport of 19e838daa8872ee29fbea0bc471c2a6443f26835 from main
2022-09-07 09:17:23 +02:00
Mariusz Felisiak
4987ce3350
[4.1.x] Added stub release notes for 4.1.2.
...
Backport of 604fadde11966c5fdfe5a236a7a3963ee868f764 from main
2022-09-05 06:09:35 +02:00
Mariusz Felisiak
95c5557032
[4.1.x] Added release date for 4.1.1.
...
Backport of aed92f686d362b731c74a7840085d2e6714e5ef5 from main
2022-09-05 05:22:07 +02:00