

distrib > Mageia > 6 > armv5tl > by-pkgid > 65530c6176058f9b54858c3b4f6385e6 > files > 808


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"

<html xmlns="" lang="">
    <meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
    <title>Django 1.1.3 release notes &#8212; Django 1.8.19 documentation</title>
    <link rel="stylesheet" href="../_static/default.css" type="text/css" />
    <link rel="stylesheet" href="../_static/pygments.css" type="text/css" />
    <script type="text/javascript">
        URL_ROOT:    '../',
        VERSION:     '1.8.19',
        COLLAPSE_INDEX: false,
        FILE_SUFFIX: '.html',
        HAS_SOURCE:  true
    <script type="text/javascript" src="../_static/jquery.js"></script>
    <script type="text/javascript" src="../_static/underscore.js"></script>
    <script type="text/javascript" src="../_static/doctools.js"></script>
    <link rel="index" title="Index" href="../genindex.html" />
    <link rel="search" title="Search" href="../search.html" />
    <link rel="top" title="Django 1.8.19 documentation" href="../contents.html" />
    <link rel="up" title="Release notes" href="index.html" />
    <link rel="next" title="Django 1.1.2 release notes" href="1.1.2.html" />
    <link rel="prev" title="Django 1.1.4 release notes" href="1.1.4.html" />

<script type="text/javascript" src="../templatebuiltins.js"></script>
<script type="text/javascript">
(function($) {
    if (!django_template_builtins) {
       // templatebuiltins.js missing, do nothing.
    $(document).ready(function() {
        // Hyperlink Django template tags and filters
        var base = "../ref/templates/builtins.html";
        if (base == "#") {
            // Special case for builtins.html itself
            base = "";
        // Tags are keywords, class '.k'
        $("div.highlight\\-html\\+django span.k").each(function(i, elem) {
             var tagname = $(elem).text();
             if ($.inArray(tagname, django_template_builtins.ttags) != -1) {
                 var fragment = tagname.replace(/_/, '-');
                 $(elem).html("<a href='" + base + "#" + fragment + "'>" + tagname + "</a>");
        // Filters are functions, class '.nf'
        $("div.highlight\\-html\\+django").each(function(i, elem) {
             var filtername = $(elem).text();
             if ($.inArray(filtername, django_template_builtins.tfilters) != -1) {
                 var fragment = filtername.replace(/_/, '-');
                 $(elem).html("<a href='" + base + "#" + fragment + "'>" + filtername + "</a>");

  <body role="document">

    <div class="document">
  <div id="custom-doc" class="yui-t6">
    <div id="hd">
      <h1><a href="../index.html">Django 1.8.19 documentation</a></h1>
      <div id="global-nav">
        <a title="Home page" href="../index.html">Home</a>  |
        <a title="Table of contents" href="../contents.html">Table of contents</a>  |
        <a title="Global index" href="../genindex.html">Index</a>  |
        <a title="Module index" href="../py-modindex.html">Modules</a>
      <div class="nav">
    &laquo; <a href="1.1.4.html" title="Django 1.1.4 release notes">previous</a>
    <a href="index.html" title="Release notes" accesskey="U">up</a>
    <a href="1.1.2.html" title="Django 1.1.2 release notes">next</a> &raquo;</div>

    <div id="bd">
      <div id="yui-main">
        <div class="yui-b">
          <div class="yui-g" id="releases-1.1.3">
  <div class="section" id="s-django-1-1-3-release-notes">
<span id="django-1-1-3-release-notes"></span><h1>Django 1.1.3 release notes<a class="headerlink" href="#django-1-1-3-release-notes" title="Permalink to this headline">¶</a></h1>
<p>Welcome to Django 1.1.3!</p>
<p>This is the third &#8220;bugfix&#8221; release in the Django 1.1 series,
improving the stability and performance of the Django 1.1 codebase.</p>
<p>With one exception, Django 1.1.3 maintains backwards compatibility
with Django 1.1.2. It also contains a number of fixes and other
improvements. Django 1.1.2 is a recommended upgrade for any
development or deployment currently using or targeting Django 1.1.</p>
<p>For full details on the new features, backwards incompatibilities, and
deprecated features in the 1.1 branch, see the <a class="reference internal" href="1.1.html"><span class="doc">Django 1.1 release notes</span></a>.</p>
<div class="section" id="s-backwards-incompatible-changes">
<span id="backwards-incompatible-changes"></span><h2>Backwards incompatible changes<a class="headerlink" href="#backwards-incompatible-changes" title="Permalink to this headline">¶</a></h2>
<div class="section" id="s-restricted-filters-in-admin-interface">
<span id="restricted-filters-in-admin-interface"></span><h3>Restricted filters in admin interface<a class="headerlink" href="#restricted-filters-in-admin-interface" title="Permalink to this headline">¶</a></h3>
<p>The Django administrative interface, django.contrib.admin, supports
filtering of displayed lists of objects by fields on the corresponding
models, including across database-level relationships. This is
implemented by passing lookup arguments in the querystring portion of
the URL, and options on the ModelAdmin class allow developers to
specify particular fields or relationships which will generate
automatic links for filtering.</p>
<p>One historically-undocumented and -unofficially-supported feature has
been the ability for a user with sufficient knowledge of a model&#8217;s
structure and the format of these lookup arguments to invent useful
new filters on the fly by manipulating the querystring.</p>
<p>However, it has been demonstrated that this can be abused to gain
access to information outside of an admin user&#8217;s permissions; for
example, an attacker with access to the admin and sufficient knowledge
of model structure and relations could construct query strings which &#8211;
with repeated use of regular-expression lookups supported by the
Django database API &#8211; expose sensitive information such as users&#8217;
password hashes.</p>
<p>To remedy this, django.contrib.admin will now validate that
querystring lookup arguments either specify only fields on the model
being viewed, or cross relations which have been explicitly
whitelisted by the application developer using the pre-existing
mechanism mentioned above. This is backwards-incompatible for any
users relying on the prior ability to insert arbitrary lookups.</p>

          <div class="yui-b" id="sidebar">
      <div class="sphinxsidebar" role="navigation" aria-label="main navigation">
        <div class="sphinxsidebarwrapper">
  <h3><a href="../contents.html">Table Of Contents</a></h3>
<li><a class="reference internal" href="#">Django 1.1.3 release notes</a><ul>
<li><a class="reference internal" href="#backwards-incompatible-changes">Backwards incompatible changes</a><ul>
<li><a class="reference internal" href="#restricted-filters-in-admin-interface">Restricted filters in admin interface</a></li>

      <li>Prev: <a href="1.1.4.html">Django 1.1.4 release notes</a></li>
      <li>Next: <a href="1.1.2.html">Django 1.1.2 release notes</a></li>
  <h3>You are here:</h3>
        <a href="../index.html">Django 1.8.19 documentation</a>
          <ul><li><a href="index.html">Release notes</a>
        <ul><li>Django 1.1.3 release notes</li></ul>

  <div role="note" aria-label="source link">
    <h3>This Page</h3>
    <ul class="this-page-menu">
      <li><a href="../_sources/releases/1.1.3.txt"
            rel="nofollow">Show Source</a></li>
<div id="searchbox" style="display: none" role="search">
  <h3>Quick search</h3>
    <form class="search" action="../search.html" method="get">
      <div><input type="text" name="q" /></div>
      <div><input type="submit" value="Go" /></div>
      <input type="hidden" name="check_keywords" value="yes" />
      <input type="hidden" name="area" value="default" />
<script type="text/javascript">$('#searchbox').show(0);</script>
              <h3>Last update:</h3>
              <p class="topless">Mar 10, 2018</p>

    <div id="ft">
      <div class="nav">
    &laquo; <a href="1.1.4.html" title="Django 1.1.4 release notes">previous</a>
    <a href="index.html" title="Release notes" accesskey="U">up</a>
    <a href="1.1.2.html" title="Django 1.1.2 release notes">next</a> &raquo;</div>

      <div class="clearer"></div>