3.1.txt 19 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582
  1. ============================================
  2. Django 3.1 release notes - UNDER DEVELOPMENT
  3. ============================================
  4. *Expected August 2020*
  5. Welcome to Django 3.1!
  6. These release notes cover the :ref:`new features <whats-new-3.1>`, as well as
  7. some :ref:`backwards incompatible changes <backwards-incompatible-3.1>` you'll
  8. want to be aware of when upgrading from Django 3.0 or earlier. We've
  9. :ref:`dropped some features<removed-features-3.1>` that have reached the end of
  10. their deprecation cycle, and we've :ref:`begun the deprecation process for
  11. some features <deprecated-features-3.1>`.
  12. See the :doc:`/howto/upgrade-version` guide if you're updating an existing
  13. project.
  14. Python compatibility
  15. ====================
  16. Django 3.1 supports Python 3.6, 3.7, and 3.8. We **highly recommend** and only
  17. officially support the latest release of each series.
  18. .. _whats-new-3.1:
  19. What's new in Django 3.1
  20. ========================
  21. Minor features
  22. --------------
  23. :mod:`django.contrib.admin`
  24. ~~~~~~~~~~~~~~~~~~~~~~~~~~~
  25. * The new ``django.contrib.admin.EmptyFieldListFilter`` for
  26. :attr:`.ModelAdmin.list_filter` allows filtering on empty values (empty
  27. strings and nulls) in the admin changelist view.
  28. * Filters in the right sidebar of the admin changelist view now contains a link
  29. to clear all filters.
  30. :mod:`django.contrib.admindocs`
  31. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  32. * ...
  33. :mod:`django.contrib.auth`
  34. ~~~~~~~~~~~~~~~~~~~~~~~~~~
  35. * The default iteration count for the PBKDF2 password hasher is increased from
  36. 180,000 to 216,000.
  37. * Added the :setting:`PASSWORD_RESET_TIMEOUT` setting to define the minimum
  38. number of seconds a password reset link is valid for. This is encouraged
  39. instead of deprecated ``PASSWORD_RESET_TIMEOUT_DAYS``, which will be removed
  40. in Django 4.0.
  41. * The password reset mechanism now uses the SHA-256 hashing algorithm. Support
  42. for tokens that use the old hashing algorithm remains until Django 4.0.
  43. :mod:`django.contrib.contenttypes`
  44. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  45. * ...
  46. :mod:`django.contrib.gis`
  47. ~~~~~~~~~~~~~~~~~~~~~~~~~
  48. * :lookup:`relate` lookup is now supported on MariaDB.
  49. * Added the :attr:`.LinearRing.is_counterclockwise` property.
  50. * :class:`~django.contrib.gis.db.models.functions.AsGeoJSON` is now supported
  51. on Oracle.
  52. * Added the :class:`~django.contrib.gis.db.models.functions.AsWKB` and
  53. :class:`~django.contrib.gis.db.models.functions.AsWKT` functions.
  54. :mod:`django.contrib.messages`
  55. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  56. * ...
  57. :mod:`django.contrib.postgres`
  58. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  59. * The new :class:`~django.contrib.postgres.indexes.BloomIndex` class allows
  60. creating ``bloom`` indexes in the database. The new
  61. :class:`~django.contrib.postgres.operations.BloomExtension` migration
  62. operation installs the ``bloom`` extension to add support for this index.
  63. * :meth:`~django.db.models.Model.get_FOO_display` now supports
  64. :class:`~django.contrib.postgres.fields.ArrayField` and
  65. :class:`~django.contrib.postgres.fields.RangeField`.
  66. * The new :lookup:`rangefield.lower_inc`, :lookup:`rangefield.lower_inf`,
  67. :lookup:`rangefield.upper_inc`, and :lookup:`rangefield.upper_inf` allows
  68. querying :class:`~django.contrib.postgres.fields.RangeField` by a bound type.
  69. * :lookup:`rangefield.contained_by` now supports
  70. :class:`~django.db.models.SmallAutoField`,
  71. :class:`~django.db.models.AutoField`,
  72. :class:`~django.db.models.BigAutoField`,
  73. :class:`~django.db.models.SmallIntegerField`, and
  74. :class:`~django.db.models.DecimalField`.
  75. * :class:`~django.contrib.postgres.search.SearchQuery` now supports
  76. ``'websearch'`` search type on PostgreSQL 11+.
  77. * The new :class:`~django.contrib.postgres.search.SearchHeadline` class allows
  78. highlighting search results.
  79. :mod:`django.contrib.redirects`
  80. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  81. * ...
  82. :mod:`django.contrib.sessions`
  83. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  84. * The :setting:`SESSION_COOKIE_SAMESITE` setting now allows ``'None'`` (string)
  85. value to explicitly state that the cookie is sent with all same-site and
  86. cross-site requests.
  87. :mod:`django.contrib.sitemaps`
  88. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  89. * ...
  90. :mod:`django.contrib.sites`
  91. ~~~~~~~~~~~~~~~~~~~~~~~~~~~
  92. * ...
  93. :mod:`django.contrib.staticfiles`
  94. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  95. * The :setting:`STATICFILES_DIRS` setting now supports :class:`pathlib.Path`.
  96. :mod:`django.contrib.syndication`
  97. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  98. * ...
  99. Cache
  100. ~~~~~
  101. * The :func:`~django.views.decorators.cache.cache_control` decorator and
  102. :func:`~django.utils.cache.patch_cache_control` method now support multiple
  103. field names in the ``no-cache`` directive for the ``Cache-Control`` header,
  104. according to :rfc:`7234#section-5.2.2.2`.
  105. * :meth:`~django.core.caches.cache.delete` now returns ``True`` if the key was
  106. successfully deleted, ``False`` otherwise.
  107. CSRF
  108. ~~~~
  109. * The :setting:`CSRF_COOKIE_SAMESITE` setting now allows ``'None'`` (string)
  110. value to explicitly state that the cookie is sent with all same-site and
  111. cross-site requests.
  112. Email
  113. ~~~~~
  114. * The :setting:`EMAIL_FILE_PATH` setting, used by the :ref:`file email backend
  115. <topic-email-file-backend>`, now supports :class:`pathlib.Path`.
  116. Error Reporting
  117. ~~~~~~~~~~~~~~~
  118. * :class:`django.views.debug.SafeExceptionReporterFilter` now filters sensitive
  119. values from ``request.META`` in exception reports.
  120. * The new :attr:`.SafeExceptionReporterFilter.cleansed_substitute` and
  121. :attr:`.SafeExceptionReporterFilter.hidden_settings` attributes allow
  122. customization of sensitive settings and ``request.META`` filtering in
  123. exception reports.
  124. * The technical 404 debug view now respects
  125. :setting:`DEFAULT_EXCEPTION_REPORTER_FILTER` when applying settings
  126. filtering.
  127. * The new :setting:`DEFAULT_EXCEPTION_REPORTER` allows providing a
  128. :class:`django.views.debug.ExceptionReporter` subclass to customize exception
  129. report generation. See :ref:`custom-error-reports` for details.
  130. File Storage
  131. ~~~~~~~~~~~~
  132. * ``FileSystemStorage.save()`` method now supports :class:`pathlib.Path`.
  133. File Uploads
  134. ~~~~~~~~~~~~
  135. * ...
  136. Forms
  137. ~~~~~
  138. * :class:`~django.forms.ModelChoiceIterator`, used by
  139. :class:`~django.forms.ModelChoiceField` and
  140. :class:`~django.forms.ModelMultipleChoiceField`, now uses
  141. :class:`~django.forms.ModelChoiceIteratorValue` that can be used by widgets
  142. to access model instances. See :ref:`iterating-relationship-choices` for
  143. details.
  144. * :class:`django.forms.DateTimeField` now accepts dates in a subset of ISO 8601
  145. datetime formats, including optional timezone (e.g. ``2019-10-10T06:47``,
  146. ``2019-10-10T06:47:23+04:00``, or ``2019-10-10T06:47:23Z``). Additionally, it
  147. now uses ``DATE_INPUT_FORMATS`` in addition to ``DATETIME_INPUT_FORMATS``
  148. when converting a field input to a ``datetime`` value.
  149. Generic Views
  150. ~~~~~~~~~~~~~
  151. * ...
  152. Internationalization
  153. ~~~~~~~~~~~~~~~~~~~~
  154. * The :setting:`LANGUAGE_COOKIE_SAMESITE` setting now allows ``'None'``
  155. (string) value to explicitly state that the cookie is sent with all same-site
  156. and cross-site requests.
  157. * Added support and translations for the Algerian Arabic language.
  158. Logging
  159. ~~~~~~~
  160. * ...
  161. Management Commands
  162. ~~~~~~~~~~~~~~~~~~~
  163. * The new :option:`check --database` option allows specifying database aliases
  164. for running the ``database`` system checks. Previously these checks were
  165. enabled for all configured :setting:`DATABASES` by passing the ``database``
  166. tag to the command.
  167. Migrations
  168. ~~~~~~~~~~
  169. * Migrations are now loaded also from directories without ``__init__.py``
  170. files.
  171. Models
  172. ~~~~~~
  173. * The new :class:`~django.db.models.functions.ExtractIsoWeekDay` function
  174. extracts ISO-8601 week days from :class:`~django.db.models.DateField` and
  175. :class:`~django.db.models.DateTimeField`, and the new :lookup:`iso_week_day`
  176. lookup allows querying by an ISO-8601 day of week.
  177. * :meth:`.QuerySet.explain` now supports:
  178. * ``TREE`` format on MySQL 8.0.16+,
  179. * ``analyze`` option on MySQL 8.0.18+ and MariaDB.
  180. * Added :class:`~django.db.models.PositiveBigIntegerField` which acts much like
  181. a :class:`~django.db.models.PositiveIntegerField` except that it only allows
  182. values under a certain (database-dependent) limit. Values from ``0`` to
  183. ``9223372036854775807`` are safe in all databases supported by Django.
  184. * The new :class:`~django.db.models.RESTRICT` option for
  185. :attr:`~django.db.models.ForeignKey.on_delete` argument of ``ForeignKey`` and
  186. ``OneToOneField`` emulates the behavior of the SQL constraint ``ON DELETE
  187. RESTRICT``.
  188. * :attr:`.CheckConstraint.check` now supports boolean expressions.
  189. * The :meth:`.RelatedManager.add`, :meth:`~.RelatedManager.create`, and
  190. :meth:`~.RelatedManager.set` methods now accept callables as values in the
  191. ``through_defaults`` argument.
  192. Pagination
  193. ~~~~~~~~~~
  194. * :class:`~django.core.paginator.Paginator` can now be iterated over to yield
  195. its pages.
  196. Requests and Responses
  197. ~~~~~~~~~~~~~~~~~~~~~~
  198. * If :setting:`ALLOWED_HOSTS` is empty and ``DEBUG=True``, subdomains of
  199. localhost are now allowed in the ``Host`` header, e.g. ``static.localhost``.
  200. * :meth:`.HttpResponse.set_cookie` and :meth:`.HttpResponse.set_signed_cookie`
  201. now allow using ``samesite='None'`` (string) to explicitly state that the
  202. cookie is sent with all same-site and cross-site requests.
  203. * The new :meth:`.HttpRequest.accepts` method returns whether the request
  204. accepts the given MIME type according to the ``Accept`` HTTP header.
  205. .. _whats-new-security-3.1:
  206. Security
  207. ~~~~~~~~
  208. * The :setting:`SECURE_REFERRER_POLICY` setting now defaults to
  209. ``'same-origin'``. With this configured,
  210. :class:`~django.middleware.security.SecurityMiddleware` sets the
  211. :ref:`referrer-policy` header to ``same-origin`` on all responses that do not
  212. already have it. This prevents the ``Referer`` header being sent to other
  213. origins. If you need the previous behavior, explicitly set
  214. :setting:`SECURE_REFERRER_POLICY` to ``None``.
  215. Serialization
  216. ~~~~~~~~~~~~~
  217. * ...
  218. Signals
  219. ~~~~~~~
  220. * ...
  221. Templates
  222. ~~~~~~~~~
  223. * The renamed :ttag:`translate` and :ttag:`blocktranslate` template tags are
  224. introduced for internationalization in template code. The older :ttag:`trans`
  225. and :ttag:`blocktrans` template tags aliases continue to work, and will be
  226. retained for the foreseeable future.
  227. * The :ttag:`include` template tag now accepts iterables of template names.
  228. Tests
  229. ~~~~~
  230. * :class:`~django.test.SimpleTestCase` now implements the ``debug()`` method to
  231. allow running a test without collecting the result and catching exceptions.
  232. This can be used to support running tests under a debugger.
  233. * The new :setting:`MIGRATE <TEST_MIGRATE>` test database setting allows
  234. disabling of migrations during a test database creation.
  235. * Django test runner now supports a :option:`test --buffer` option to discard
  236. output for passing tests.
  237. * :class:`~django.test.runner.DiscoverRunner` now skips running the system
  238. checks on databases not :ref:`referenced by tests<testing-multi-db>`.
  239. URLs
  240. ~~~~
  241. * :ref:`Path converters <registering-custom-path-converters>` can now raise
  242. ``ValueError`` in ``to_url()`` to indicate no match when reversing URLs.
  243. Utilities
  244. ~~~~~~~~~
  245. * :func:`~django.utils.encoding.filepath_to_uri` now supports
  246. :class:`pathlib.Path`.
  247. * :func:`~django.utils.dateparse.parse_duration` now supports comma separators
  248. for decimal fractions in the ISO 8601 format.
  249. * :func:`~django.utils.dateparse.parse_datetime`,
  250. :func:`~django.utils.dateparse.parse_duration`, and
  251. :func:`~django.utils.dateparse.parse_time` now support comma separators for
  252. milliseconds.
  253. Validators
  254. ~~~~~~~~~~
  255. * ...
  256. Miscellaneous
  257. ~~~~~~~~~~~~~
  258. * The SQLite backend now supports :class:`pathlib.Path` for the ``NAME``
  259. setting.
  260. * The ``settings.py`` generated by the :djadmin:`startproject` command now uses
  261. :class:`pathlib.Path` instead of :mod:`os.path` for building filesystem
  262. paths.
  263. * The :setting:`TIME_ZONE <DATABASE-TIME_ZONE>` setting is now allowed on
  264. databases that support time zones.
  265. .. _backwards-incompatible-3.1:
  266. Backwards incompatible changes in 3.1
  267. =====================================
  268. Database backend API
  269. --------------------
  270. This section describes changes that may be needed in third-party database
  271. backends.
  272. * ``DatabaseOperations.fetch_returned_insert_columns()`` now requires an
  273. additional ``returning_params`` argument.
  274. * ``connection.timezone`` property is now ``'UTC'`` by default, or the
  275. :setting:`TIME_ZONE <DATABASE-TIME_ZONE>` when :setting:`USE_TZ` is ``True``
  276. on databases that support time zones. Previously, it was ``None`` on
  277. databases that support time zones.
  278. * ``connection._nodb_connection`` property is changed to the
  279. ``connection._nodb_cursor()`` method and now returns a context manager that
  280. yields a cursor and automatically closes the cursor and connection upon
  281. exiting the ``with`` statement.
  282. Dropped support for MariaDB 10.1
  283. --------------------------------
  284. Upstream support for MariaDB 10.1 ends in October 2020. Django 3.1 supports
  285. MariaDB 10.2 and higher.
  286. ``contrib.admin`` browser support
  287. ---------------------------------
  288. The admin no longer supports the legacy Internet Explorer browser. See
  289. :ref:`the admin FAQ <admin-browser-support>` for details on supported browsers.
  290. Miscellaneous
  291. -------------
  292. * The cache keys used by :ttag:`cache` and generated by
  293. :func:`~django.core.cache.utils.make_template_fragment_key` are different
  294. from the keys generated by older versions of Django. After upgrading to
  295. Django 3.1, the first request to any previously cached template fragment will
  296. be a cache miss.
  297. * The logic behind the decision to return a redirection fallback or a 204 HTTP
  298. response from the :func:`~django.views.i18n.set_language` view is now based
  299. on the ``Accept`` HTTP header instead of the ``X-Requested-With`` HTTP header
  300. presence.
  301. * The compatibility imports of ``django.core.exceptions.EmptyResultSet`` in
  302. ``django.db.models.query``, ``django.db.models.sql``, and
  303. ``django.db.models.sql.datastructures`` are removed.
  304. * The compatibility import of ``django.core.exceptions.FieldDoesNotExist`` in
  305. ``django.db.models.fields`` is removed.
  306. * The compatibility imports of ``django.forms.utils.pretty_name()`` and
  307. ``django.forms.boundfield.BoundField`` in ``django.forms.forms`` are removed.
  308. * The compatibility imports of ``Context``, ``ContextPopException``, and
  309. ``RequestContext`` in ``django.template.base`` are removed.
  310. * The compatibility import of
  311. ``django.contrib.admin.helpers.ACTION_CHECKBOX_NAME`` in
  312. ``django.contrib.admin`` is removed.
  313. * The :setting:`STATIC_URL` and :setting:`MEDIA_URL` settings set to relative
  314. paths are now prefixed by the server-provided value of ``SCRIPT_NAME`` (or
  315. ``/`` if not set). This change should not affect settings set to valid URLs
  316. or absolute paths.
  317. * :class:`~django.middleware.http.ConditionalGetMiddleware` no longer adds the
  318. ``ETag`` header to responses with an empty
  319. :attr:`~django.http.HttpResponse.content`.
  320. * ``django.utils.decorators.classproperty()`` decorator is moved to
  321. ``django.utils.functional.classproperty()``.
  322. * :tfilter:`floatformat` template filter now outputs (positive) ``0`` for
  323. negative numbers which round to zero.
  324. * :attr:`Meta.ordering <django.db.models.Options.ordering>` and
  325. :attr:`Meta.unique_together <django.db.models.Options.unique_together>`
  326. options on models in ``django.contrib`` modules that were formerly tuples are
  327. now lists.
  328. * The admin calendar widget now handles two-digit years according to the Open
  329. Group Specification, i.e. values between 69 and 99 are mapped to the previous
  330. century, and values between 0 and 68 are mapped to the current century.
  331. * Date-only formats are removed from the default list for
  332. :setting:`DATETIME_INPUT_FORMATS`.
  333. * The :class:`~django.forms.FileInput` widget no longer renders with the
  334. ``required`` HTML attribute when initial data exists.
  335. * The undocumented ``django.views.debug.ExceptionReporterFilter`` class is
  336. removed. As per the :ref:`custom-error-reports` documentation, classes to be
  337. used with :setting:`DEFAULT_EXCEPTION_REPORTER_FILTER` needs to inherit from
  338. :class:`django.views.debug.SafeExceptionReporterFilter`.
  339. * The cache timeout set by :func:`~django.views.decorators.cache.cache_page`
  340. decorator now takes precedence over the ``max-age`` directive from the
  341. ``Cache-Control`` header.
  342. * Providing a non-local remote field in the :attr:`.ForeignKey.to_field`
  343. argument now raises :class:`~django.core.exceptions.FieldError`.
  344. * :setting:`SECURE_REFERRER_POLICY` now defaults to ``'same-origin'``. See the
  345. *What's New* :ref:`Security section <whats-new-security-3.1>` above for more
  346. details.
  347. * :djadmin:`check` management command now runs the ``database`` system checks
  348. only for database aliases specified using :option:`check --database` option.
  349. * :djadmin:`migrate` management command now runs the ``database`` system checks
  350. only for a database to migrate.
  351. .. _deprecated-features-3.1:
  352. Features deprecated in 3.1
  353. ==========================
  354. Miscellaneous
  355. -------------
  356. * ``PASSWORD_RESET_TIMEOUT_DAYS`` setting is deprecated in favor of
  357. :setting:`PASSWORD_RESET_TIMEOUT`.
  358. * The undocumented usage of the :lookup:`isnull` lookup with non-boolean values
  359. as the right-hand side is deprecated, use ``True`` or ``False`` instead.
  360. * The barely documented ``django.db.models.query_utils.InvalidQuery`` exception
  361. class is deprecated in favor of
  362. :class:`~django.core.exceptions.FieldDoesNotExist` and
  363. :class:`~django.core.exceptions.FieldError`.
  364. * The ``django-admin.py`` entry point is deprecated in favor of
  365. ``django-admin``.
  366. * The ``HttpRequest.is_ajax()`` method is deprecated as it relied on a
  367. jQuery-specific way of signifying AJAX calls, while current usage tends to
  368. use the JavaScript `Fetch API
  369. <https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API>`_. Depending on
  370. your use case, you can either write your own AJAX detection method, or use
  371. the new :meth:`.HttpRequest.accepts` method if your code depends on the
  372. client ``Accept`` HTTP header.
  373. If you are writing your own AJAX detection method, ``request.is_ajax()`` can
  374. be reproduced exactly as
  375. ``request.headers.get('x-requested-with') == 'XMLHttpRequest'``.
  376. * Passing ``None`` as the first argument to
  377. ``django.utils.deprecation.MiddlewareMixin.__init__()`` is deprecated.
  378. * The encoding format of cookies values used by
  379. :class:`~django.contrib.messages.storage.cookie.CookieStorage` is different
  380. from the format generated by older versions of Django. Support for the old
  381. format remains until Django 4.0.
  382. * The encoding format of sessions is different from the format generated by
  383. older versions of Django. Support for the old format remains until Django
  384. 4.0.
  385. * The purely documentational ``providing_args`` argument for
  386. :class:`~django.dispatch.Signal` is deprecated. If you rely on this
  387. argument as documentation, you can move the text to a code comment or
  388. docstring.
  389. .. _removed-features-3.1:
  390. Features removed in 3.1
  391. =======================
  392. These features have reached the end of their deprecation cycle and are removed
  393. in Django 3.1.
  394. See :ref:`deprecated-features-2.2` for details on these changes, including how
  395. to remove usage of these features.
  396. * ``django.utils.timezone.FixedOffset`` is removed.
  397. * ``django.core.paginator.QuerySetPaginator`` is removed.
  398. * A model's ``Meta.ordering`` doesn't affect ``GROUP BY`` queries.
  399. * ``django.contrib.postgres.fields.FloatRangeField`` and
  400. ``django.contrib.postgres.forms.FloatRangeField`` are removed.
  401. * The ``FILE_CHARSET`` setting is removed.
  402. * ``django.contrib.staticfiles.storage.CachedStaticFilesStorage`` is removed.
  403. * The ``RemoteUserBackend.configure_user()`` method requires ``request`` as the
  404. first positional argument.
  405. * Support for ``SimpleTestCase.allow_database_queries`` and
  406. ``TransactionTestCase.multi_db`` is removed.