  1. ============================================
  2. Django 3.1 release notes - UNDER DEVELOPMENT
  3. ============================================
  4. *Expected August 2020*
  5. Welcome to Django 3.1!
  6. These release notes cover the :ref:`new features <whats-new-3.1>`, as well as
  7. some :ref:`backwards incompatible changes <backwards-incompatible-3.1>` you'll
  8. want to be aware of when upgrading from Django 3.0 or earlier. We've
  9. :ref:`dropped some features<removed-features-3.1>` that have reached the end of
  10. their deprecation cycle, and we've :ref:`begun the deprecation process for
  11. some features <deprecated-features-3.1>`.
  12. See the :doc:`/howto/upgrade-version` guide if you're updating an existing
  13. project.
  14. Python compatibility
  15. ====================
  16. Django 3.1 supports Python 3.6, 3.7, and 3.8. We **highly recommend** and only
  17. officially support the latest release of each series.
  18. .. _whats-new-3.1:
  19. What's new in Django 3.1
  20. ========================
  21. Minor features
  22. --------------
  23. :mod:`django.contrib.admin`
  24. ~~~~~~~~~~~~~~~~~~~~~~~~~~~
  25. * The new ``django.contrib.admin.EmptyFieldListFilter`` for
  26. :attr:`.ModelAdmin.list_filter` allows filtering on empty values (empty
  27. strings and nulls) in the admin changelist view.
  28. * Filters in the right sidebar of the admin changelist view now contains a link
  29. to clear all filters.
  30. :mod:`django.contrib.admindocs`
  31. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  32. * ...
  33. :mod:`django.contrib.auth`
  34. ~~~~~~~~~~~~~~~~~~~~~~~~~~
  35. * The default iteration count for the PBKDF2 password hasher is increased from
  36. 180,000 to 216,000.
  37. * Added the :setting:`PASSWORD_RESET_TIMEOUT` setting to define the minimum
  38. number of seconds a password reset link is valid for. This is encouraged
  39. instead of deprecated ``PASSWORD_RESET_TIMEOUT_DAYS``, which will be removed
  40. in Django 4.0.
  41. * The password reset mechanism now uses the SHA-256 hashing algorithm. Support
  42. for tokens that use the old hashing algorithm remains until Django 4.0.
  43. :mod:`django.contrib.contenttypes`
  44. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  45. * ...
  46. :mod:`django.contrib.gis`
  47. ~~~~~~~~~~~~~~~~~~~~~~~~~
  48. * :lookup:`relate` lookup is now supported on MariaDB.
  49. * Added the :attr:`.LinearRing.is_counterclockwise` property.
  50. * :class:`~django.contrib.gis.db.models.functions.AsGeoJSON` is now supported
  51. on Oracle.
  52. * Added the :class:`~django.contrib.gis.db.models.functions.AsWKB` and
  53. :class:`~django.contrib.gis.db.models.functions.AsWKT` functions.
  54. :mod:`django.contrib.humanize`
  55. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  56. * :tfilter:`intword` template filter now supports negative integers.
  57. :mod:`django.contrib.messages`
  58. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  59. * ...
  60. :mod:`django.contrib.postgres`
  61. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  62. * The new :class:`~django.contrib.postgres.indexes.BloomIndex` class allows
  63. creating ``bloom`` indexes in the database. The new
  64. :class:`~django.contrib.postgres.operations.BloomExtension` migration
  65. operation installs the ``bloom`` extension to add support for this index.
  66. * :meth:`~django.db.models.Model.get_FOO_display` now supports
  67. :class:`~django.contrib.postgres.fields.ArrayField` and
  68. :class:`~django.contrib.postgres.fields.RangeField`.
  69. * The new :lookup:`rangefield.lower_inc`, :lookup:`rangefield.lower_inf`,
  70. :lookup:`rangefield.upper_inc`, and :lookup:`rangefield.upper_inf` allows
  71. querying :class:`~django.contrib.postgres.fields.RangeField` by a bound type.
  72. * :lookup:`rangefield.contained_by` now supports
  73. :class:`~django.db.models.SmallAutoField`,
  74. :class:`~django.db.models.AutoField`,
  75. :class:`~django.db.models.BigAutoField`,
  76. :class:`~django.db.models.SmallIntegerField`, and
  77. :class:`~django.db.models.DecimalField`.
  78. * :class:`~django.contrib.postgres.search.SearchQuery` now supports
  79. ``'websearch'`` search type on PostgreSQL 11+.
  80. * The new :class:`~django.contrib.postgres.search.SearchHeadline` class allows
  81. highlighting search results.
  82. :mod:`django.contrib.redirects`
  83. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  84. * ...
  85. :mod:`django.contrib.sessions`
  86. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  87. * The :setting:`SESSION_COOKIE_SAMESITE` setting now allows ``'None'`` (string)
  88. value to explicitly state that the cookie is sent with all same-site and
  89. cross-site requests.
  90. :mod:`django.contrib.sitemaps`
  91. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  92. * ...
  93. :mod:`django.contrib.sites`
  94. ~~~~~~~~~~~~~~~~~~~~~~~~~~~
  95. * ...
  96. :mod:`django.contrib.staticfiles`
  97. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  98. * The :setting:`STATICFILES_DIRS` setting now supports :class:`pathlib.Path`.
  99. :mod:`django.contrib.syndication`
  100. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  101. * ...
  102. Cache
  103. ~~~~~
  104. * The :func:`~django.views.decorators.cache.cache_control` decorator and
  105. :func:`~django.utils.cache.patch_cache_control` method now support multiple
  106. field names in the ``no-cache`` directive for the ``Cache-Control`` header,
  107. according to :rfc:`7234#section-`.
  108. * :meth:`~django.core.caches.cache.delete` now returns ``True`` if the key was
  109. successfully deleted, ``False`` otherwise.
  110. CSRF
  111. ~~~~
  112. * The :setting:`CSRF_COOKIE_SAMESITE` setting now allows ``'None'`` (string)
  113. value to explicitly state that the cookie is sent with all same-site and
  114. cross-site requests.
  115. Email
  116. ~~~~~
  117. * The :setting:`EMAIL_FILE_PATH` setting, used by the :ref:`file email backend
  118. <topic-email-file-backend>`, now supports :class:`pathlib.Path`.
  119. Error Reporting
  120. ~~~~~~~~~~~~~~~
  121. * :class:`django.views.debug.SafeExceptionReporterFilter` now filters sensitive
  122. values from ``request.META`` in exception reports.
  123. * The new :attr:`.SafeExceptionReporterFilter.cleansed_substitute` and
  124. :attr:`.SafeExceptionReporterFilter.hidden_settings` attributes allow
  125. customization of sensitive settings and ``request.META`` filtering in
  126. exception reports.
  127. * The technical 404 debug view now respects
  128. :setting:`DEFAULT_EXCEPTION_REPORTER_FILTER` when applying settings
  129. filtering.
  130. * The new :setting:`DEFAULT_EXCEPTION_REPORTER` allows providing a
  131. :class:`django.views.debug.ExceptionReporter` subclass to customize exception
  132. report generation. See :ref:`custom-error-reports` for details.
  133. File Storage
  134. ~~~~~~~~~~~~
  135. * ``FileSystemStorage.save()`` method now supports :class:`pathlib.Path`.
  136. File Uploads
  137. ~~~~~~~~~~~~
  138. * ...
  139. Forms
  140. ~~~~~
  141. * :class:`~django.forms.ModelChoiceIterator`, used by
  142. :class:`~django.forms.ModelChoiceField` and
  143. :class:`~django.forms.ModelMultipleChoiceField`, now uses
  144. :class:`~django.forms.ModelChoiceIteratorValue` that can be used by widgets
  145. to access model instances. See :ref:`iterating-relationship-choices` for
  146. details.
  147. * :class:`django.forms.DateTimeField` now accepts dates in a subset of ISO 8601
  148. datetime formats, including optional timezone (e.g. ``2019-10-10T06:47``,
  149. ``2019-10-10T06:47:23+04:00``, or ``2019-10-10T06:47:23Z``). Additionally, it
  150. now uses ``DATE_INPUT_FORMATS`` in addition to ``DATETIME_INPUT_FORMATS``
  151. when converting a field input to a ``datetime`` value.
  152. Generic Views
  153. ~~~~~~~~~~~~~
  154. * ...
  155. Internationalization
  156. ~~~~~~~~~~~~~~~~~~~~
  157. * The :setting:`LANGUAGE_COOKIE_SAMESITE` setting now allows ``'None'``
  158. (string) value to explicitly state that the cookie is sent with all same-site
  159. and cross-site requests.
  160. * Added support and translations for the Algerian Arabic language.
  161. Logging
  162. ~~~~~~~
  163. * ...
  164. Management Commands
  165. ~~~~~~~~~~~~~~~~~~~
  166. * The new :option:`check --database` option allows specifying database aliases
  167. for running the ``database`` system checks. Previously these checks were
  168. enabled for all configured :setting:`DATABASES` by passing the ``database``
  169. tag to the command.
  170. Migrations
  171. ~~~~~~~~~~
  172. * Migrations are now loaded also from directories without ``__init__.py``
  173. files.
  174. Models
  175. ~~~~~~
  176. * The new :class:`~django.db.models.functions.ExtractIsoWeekDay` function
  177. extracts ISO-8601 week days from :class:`~django.db.models.DateField` and
  178. :class:`~django.db.models.DateTimeField`, and the new :lookup:`iso_week_day`
  179. lookup allows querying by an ISO-8601 day of week.
  180. * :meth:`.QuerySet.explain` now supports:
  181. * ``TREE`` format on MySQL 8.0.16+,
  182. * ``analyze`` option on MySQL 8.0.18+ and MariaDB.
  183. * Added :class:`~django.db.models.PositiveBigIntegerField` which acts much like
  184. a :class:`~django.db.models.PositiveIntegerField` except that it only allows
  185. values under a certain (database-dependent) limit. Values from ``0`` to
  186. ``9223372036854775807`` are safe in all databases supported by Django.
  187. * The new :class:`~django.db.models.RESTRICT` option for
  188. :attr:`~django.db.models.ForeignKey.on_delete` argument of ``ForeignKey`` and
  189. ``OneToOneField`` emulates the behavior of the SQL constraint ``ON DELETE
  190. RESTRICT``.
  191. * :attr:`.CheckConstraint.check` now supports boolean expressions.
  192. * The :meth:`.RelatedManager.add`, :meth:`~.RelatedManager.create`, and
  193. :meth:`~.RelatedManager.set` methods now accept callables as values in the
  194. ``through_defaults`` argument.
  195. Pagination
  196. ~~~~~~~~~~
  197. * :class:`~django.core.paginator.Paginator` can now be iterated over to yield
  198. its pages.
  199. Requests and Responses
  200. ~~~~~~~~~~~~~~~~~~~~~~
  201. * If :setting:`ALLOWED_HOSTS` is empty and ``DEBUG=True``, subdomains of
  202. localhost are now allowed in the ``Host`` header, e.g. ``static.localhost``.
  203. * :meth:`.HttpResponse.set_cookie` and :meth:`.HttpResponse.set_signed_cookie`
  204. now allow using ``samesite='None'`` (string) to explicitly state that the
  205. cookie is sent with all same-site and cross-site requests.
  206. * The new :meth:`.HttpRequest.accepts` method returns whether the request
  207. accepts the given MIME type according to the ``Accept`` HTTP header.
  208. .. _whats-new-security-3.1:
  209. Security
  210. ~~~~~~~~
  211. * The :setting:`SECURE_REFERRER_POLICY` setting now defaults to
  212. ``'same-origin'``. With this configured,
  213. :class:`~django.middleware.security.SecurityMiddleware` sets the
  214. :ref:`referrer-policy` header to ``same-origin`` on all responses that do not
  215. already have it. This prevents the ``Referer`` header being sent to other
  216. origins. If you need the previous behavior, explicitly set
  217. :setting:`SECURE_REFERRER_POLICY` to ``None``.
  218. Serialization
  219. ~~~~~~~~~~~~~
  220. * ...
  221. Signals
  222. ~~~~~~~
  223. * ...
  224. Templates
  225. ~~~~~~~~~
  226. * The renamed :ttag:`translate` and :ttag:`blocktranslate` template tags are
  227. introduced for internationalization in template code. The older :ttag:`trans`
  228. and :ttag:`blocktrans` template tags aliases continue to work, and will be
  229. retained for the foreseeable future.
  230. * The :ttag:`include` template tag now accepts iterables of template names.
  231. Tests
  232. ~~~~~
  233. * :class:`~django.test.SimpleTestCase` now implements the ``debug()`` method to
  234. allow running a test without collecting the result and catching exceptions.
  235. This can be used to support running tests under a debugger.
  236. * The new :setting:`MIGRATE <TEST_MIGRATE>` test database setting allows
  237. disabling of migrations during a test database creation.
  238. * Django test runner now supports a :option:`test --buffer` option to discard
  239. output for passing tests.
  240. * :class:`~django.test.runner.DiscoverRunner` now skips running the system
  241. checks on databases not :ref:`referenced by tests<testing-multi-db>`.
  242. URLs
  243. ~~~~
  244. * :ref:`Path converters <registering-custom-path-converters>` can now raise
  245. ``ValueError`` in ``to_url()`` to indicate no match when reversing URLs.
  246. Utilities
  247. ~~~~~~~~~
  248. * :func:`~django.utils.encoding.filepath_to_uri` now supports
  249. :class:`pathlib.Path`.
  250. * :func:`~django.utils.dateparse.parse_duration` now supports comma separators
  251. for decimal fractions in the ISO 8601 format.
  252. * :func:`~django.utils.dateparse.parse_datetime`,
  253. :func:`~django.utils.dateparse.parse_duration`, and
  254. :func:`~django.utils.dateparse.parse_time` now support comma separators for
  255. milliseconds.
  256. Validators
  257. ~~~~~~~~~~
  258. * ...
  259. Miscellaneous
  260. ~~~~~~~~~~~~~
  261. * The SQLite backend now supports :class:`pathlib.Path` for the ``NAME``
  262. setting.
  263. * The ``settings.py`` generated by the :djadmin:`startproject` command now uses
  264. :class:`pathlib.Path` instead of :mod:`os.path` for building filesystem
  265. paths.
  266. * The :setting:`TIME_ZONE <DATABASE-TIME_ZONE>` setting is now allowed on
  267. databases that support time zones.
  268. .. _backwards-incompatible-3.1:
  269. Backwards incompatible changes in 3.1
  270. =====================================
  271. Database backend API
  272. --------------------
  273. This section describes changes that may be needed in third-party database
  274. backends.
  275. * ``DatabaseOperations.fetch_returned_insert_columns()`` now requires an
  276. additional ``returning_params`` argument.
  277. * ``connection.timezone`` property is now ``'UTC'`` by default, or the
  278. :setting:`TIME_ZONE <DATABASE-TIME_ZONE>` when :setting:`USE_TZ` is ``True``
  279. on databases that support time zones. Previously, it was ``None`` on
  280. databases that support time zones.
  281. * ``connection._nodb_connection`` property is changed to the
  282. ``connection._nodb_cursor()`` method and now returns a context manager that
  283. yields a cursor and automatically closes the cursor and connection upon
  284. exiting the ``with`` statement.
  285. Dropped support for MariaDB 10.1
  286. --------------------------------
  287. Upstream support for MariaDB 10.1 ends in October 2020. Django 3.1 supports
  288. MariaDB 10.2 and higher.
  289. ``contrib.admin`` browser support
  290. ---------------------------------
  291. The admin no longer supports the legacy Internet Explorer browser. See
  292. :ref:`the admin FAQ <admin-browser-support>` for details on supported browsers.
  293. Miscellaneous
  294. -------------
  295. * The cache keys used by :ttag:`cache` and generated by
  296. :func:`~django.core.cache.utils.make_template_fragment_key` are different
  297. from the keys generated by older versions of Django. After upgrading to
  298. Django 3.1, the first request to any previously cached template fragment will
  299. be a cache miss.
  300. * The logic behind the decision to return a redirection fallback or a 204 HTTP
  301. response from the :func:`~django.views.i18n.set_language` view is now based
  302. on the ``Accept`` HTTP header instead of the ``X-Requested-With`` HTTP header
  303. presence.
  304. * The compatibility imports of ``django.core.exceptions.EmptyResultSet`` in
  305. ``django.db.models.query``, ``django.db.models.sql``, and
  306. ``django.db.models.sql.datastructures`` are removed.
  307. * The compatibility import of ``django.core.exceptions.FieldDoesNotExist`` in
  308. ``django.db.models.fields`` is removed.
  309. * The compatibility imports of ``django.forms.utils.pretty_name()`` and
  310. ``django.forms.boundfield.BoundField`` in ``django.forms.forms`` are removed.
  311. * The compatibility imports of ``Context``, ``ContextPopException``, and
  312. ``RequestContext`` in ``django.template.base`` are removed.
  313. * The compatibility import of
  314. ``django.contrib.admin.helpers.ACTION_CHECKBOX_NAME`` in
  315. ``django.contrib.admin`` is removed.
  316. * The :setting:`STATIC_URL` and :setting:`MEDIA_URL` settings set to relative
  317. paths are now prefixed by the server-provided value of ``SCRIPT_NAME`` (or
  318. ``/`` if not set). This change should not affect settings set to valid URLs
  319. or absolute paths.
  320. * :class:`~django.middleware.http.ConditionalGetMiddleware` no longer adds the
  321. ``ETag`` header to responses with an empty
  322. :attr:`~django.http.HttpResponse.content`.
  323. * ``django.utils.decorators.classproperty()`` decorator is moved to
  324. ``django.utils.functional.classproperty()``.
  325. * :tfilter:`floatformat` template filter now outputs (positive) ``0`` for
  326. negative numbers which round to zero.
  327. * :attr:`Meta.ordering <django.db.models.Options.ordering>` and
  328. :attr:`Meta.unique_together <django.db.models.Options.unique_together>`
  329. options on models in ``django.contrib`` modules that were formerly tuples are
  330. now lists.
  331. * The admin calendar widget now handles two-digit years according to the Open
  332. Group Specification, i.e. values between 69 and 99 are mapped to the previous
  333. century, and values between 0 and 68 are mapped to the current century.
  334. * Date-only formats are removed from the default list for
  335. :setting:`DATETIME_INPUT_FORMATS`.
  336. * The :class:`~django.forms.FileInput` widget no longer renders with the
  337. ``required`` HTML attribute when initial data exists.
  338. * The undocumented ``django.views.debug.ExceptionReporterFilter`` class is
  339. removed. As per the :ref:`custom-error-reports` documentation, classes to be
  340. used with :setting:`DEFAULT_EXCEPTION_REPORTER_FILTER` needs to inherit from
  341. :class:`django.views.debug.SafeExceptionReporterFilter`.
  342. * The cache timeout set by :func:`~django.views.decorators.cache.cache_page`
  343. decorator now takes precedence over the ``max-age`` directive from the
  344. ``Cache-Control`` header.
  345. * Providing a non-local remote field in the :attr:`.ForeignKey.to_field`
  346. argument now raises :class:`~django.core.exceptions.FieldError`.
  347. * :setting:`SECURE_REFERRER_POLICY` now defaults to ``'same-origin'``. See the
  348. *What's New* :ref:`Security section <whats-new-security-3.1>` above for more
  349. details.
  350. * :djadmin:`check` management command now runs the ``database`` system checks
  351. only for database aliases specified using :option:`check --database` option.
  352. * :djadmin:`migrate` management command now runs the ``database`` system checks
  353. only for a database to migrate.
  354. * The admin CSS classes ``row1`` and ``row2`` are removed in favor of
  355. ``:nth-child(odd)`` and ``:nth-child(even)`` pseudo-classes.
  356. .. _deprecated-features-3.1:
  357. Features deprecated in 3.1
  358. ==========================
  359. Miscellaneous
  360. -------------
  361. * ``PASSWORD_RESET_TIMEOUT_DAYS`` setting is deprecated in favor of
  362. :setting:`PASSWORD_RESET_TIMEOUT`.
  363. * The undocumented usage of the :lookup:`isnull` lookup with non-boolean values
  364. as the right-hand side is deprecated, use ``True`` or ``False`` instead.
  365. * The barely documented ``django.db.models.query_utils.InvalidQuery`` exception
  366. class is deprecated in favor of
  367. :class:`~django.core.exceptions.FieldDoesNotExist` and
  368. :class:`~django.core.exceptions.FieldError`.
  369. * The ``django-admin.py`` entry point is deprecated in favor of
  370. ``django-admin``.
  371. * The ``HttpRequest.is_ajax()`` method is deprecated as it relied on a
  372. jQuery-specific way of signifying AJAX calls, while current usage tends to
  373. use the JavaScript `Fetch API
  374. <https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API>`_. Depending on
  375. your use case, you can either write your own AJAX detection method, or use
  376. the new :meth:`.HttpRequest.accepts` method if your code depends on the
  377. client ``Accept`` HTTP header.
  378. If you are writing your own AJAX detection method, ``request.is_ajax()`` can
  379. be reproduced exactly as
  380. ``request.headers.get('x-requested-with') == 'XMLHttpRequest'``.
  381. * Passing ``None`` as the first argument to
  382. ``django.utils.deprecation.MiddlewareMixin.__init__()`` is deprecated.
  383. * The encoding format of cookies values used by
  384. :class:`~django.contrib.messages.storage.cookie.CookieStorage` is different
  385. from the format generated by older versions of Django. Support for the old
  386. format remains until Django 4.0.
  387. * The encoding format of sessions is different from the format generated by
  388. older versions of Django. Support for the old format remains until Django
  389. 4.0.
  390. * The purely documentational ``providing_args`` argument for
  391. :class:`~django.dispatch.Signal` is deprecated. If you rely on this
  392. argument as documentation, you can move the text to a code comment or
  393. docstring.
  394. * Calling ``django.utils.crypto.get_random_string()`` without a ``length``
  395. argument is deprecated.
  396. * The ``list`` message for :class:`~django.forms.ModelMultipleChoiceField` is
  397. deprecated in favor of ``invalid_list``.
  398. .. _removed-features-3.1:
  399. Features removed in 3.1
  400. =======================
  401. These features have reached the end of their deprecation cycle and are removed
  402. in Django 3.1.
  403. See :ref:`deprecated-features-2.2` for details on these changes, including how
  404. to remove usage of these features.
  405. * ``django.utils.timezone.FixedOffset`` is removed.
  406. * ``django.core.paginator.QuerySetPaginator`` is removed.
  407. * A model's ``Meta.ordering`` doesn't affect ``GROUP BY`` queries.
  408. * ``django.contrib.postgres.fields.FloatRangeField`` and
  409. ``django.contrib.postgres.forms.FloatRangeField`` are removed.
  410. * The ``FILE_CHARSET`` setting is removed.
  411. * ``django.contrib.staticfiles.storage.CachedStaticFilesStorage`` is removed.
  412. * The ``RemoteUserBackend.configure_user()`` method requires ``request`` as the
  413. first positional argument.
  414. * Support for ``SimpleTestCase.allow_database_queries`` and
  415. ``TransactionTestCase.multi_db`` is removed.