2.1.txt 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471
  1. ============================================
  2. Django 2.1 release notes - UNDER DEVELOPMENT
  3. ============================================
  4. Welcome to Django 2.1!
  5. These release notes cover the :ref:`new features <whats-new-2.1>`, as well as
  6. some :ref:`backwards incompatible changes <backwards-incompatible-2.1>` you'll
  7. want to be aware of when upgrading from Django 2.0 or earlier. We've
  8. :ref:`dropped some features<removed-features-2.1>` that have reached the end of
  9. their deprecation cycle, and we've :ref:`begun the deprecation process for some
  10. features <deprecated-features-2.1>`.
  11. See the :doc:`/howto/upgrade-version` guide if you're updating an existing
  12. project.
  13. Python compatibility
  14. ====================
  15. Django 2.1 supports Python 3.5, 3.6, and 3.7. Django 2.0 is the last version to
  16. support Python 3.4. We **highly recommend** and only officially support the
  17. latest release of each series.
  18. .. _whats-new-2.1:
  19. What's new in Django 2.1
  20. ========================
  21. Minor features
  22. --------------
  23. :mod:`django.contrib.admin`
  24. ~~~~~~~~~~~~~~~~~~~~~~~~~~~
  25. * :attr:`.ModelAdmin.search_fields` now accepts any lookup such as
  26. ``field__exact``.
  27. * jQuery is upgraded from version 2.2.3 to 3.2.1.
  28. * The new :meth:`.ModelAdmin.delete_queryset` method allows customizing the
  29. deletion process of the "delete selected objects" action.
  30. * You can now :ref:`override the the default admin site
  31. <overriding-default-admin-site>`.
  32. * The new :attr:`.ModelAdmin.sortable_by` attribute and
  33. :meth:`.ModelAdmin.get_sortable_by` method allow limiting the columns that
  34. can be sorted in the change list page.
  35. * The ``admin_order_field`` attribute for elements in
  36. :attr:`.ModelAdmin.list_display` may now be a query expression.
  37. * The new :meth:`.ModelAdmin.get_deleted_objects()` method allows customizing
  38. the deletion process of the delete view and the "delete selected" action.
  39. * The ``actions.html``, ``change_list_results.html``, ``date_hierarchy.html``,
  40. ``pagination.html``, ``prepopulated_fields_js.html``, ``search_form.html``,
  41. and ``submit_line.html`` templates can now be :ref:`overridden per app or
  42. per model <admin-templates-overridden-per-app-or-model>` (besides overridden
  43. globally).
  44. * The admin change list and change form object tools can now be :ref:`overridden
  45. per app, per model, or globally <admin-templates-overridden-per-app-or-model>`
  46. with ``change_list_object_tools.html`` and
  47. ``change_form_object_tools.html`` templates.
  48. * :meth:`.InlineModelAdmin.has_add_permission` is now passed the parent object
  49. as the second positional argument, ``obj``.
  50. :mod:`django.contrib.admindocs`
  51. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  52. * ...
  53. :mod:`django.contrib.auth`
  54. ~~~~~~~~~~~~~~~~~~~~~~~~~~
  55. * :djadmin:`createsuperuser` now gives a prompt to allow bypassing the
  56. :setting:`AUTH_PASSWORD_VALIDATORS` checks.
  57. * :class:`~django.contrib.auth.forms.UserCreationForm` and
  58. :class:`~django.contrib.auth.forms.UserChangeForm` no longer need to be
  59. rewritten for a custom user model.
  60. :mod:`django.contrib.contenttypes`
  61. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  62. * ...
  63. :mod:`django.contrib.gis`
  64. ~~~~~~~~~~~~~~~~~~~~~~~~~
  65. * The new :meth:`.GEOSGeometry.buffer_with_style` method is a version of
  66. :meth:`~.GEOSGeometry.buffer` that allows customizing the style of the
  67. buffer.
  68. :mod:`django.contrib.messages`
  69. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  70. * ...
  71. :mod:`django.contrib.postgres`
  72. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  73. * ...
  74. :mod:`django.contrib.redirects`
  75. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  76. * ...
  77. :mod:`django.contrib.sessions`
  78. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  79. * Added the :setting:`SESSION_COOKIE_SAMESITE` setting to set the ``SameSite``
  80. cookie flag on session cookies.
  81. :mod:`django.contrib.sitemaps`
  82. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  83. * ...
  84. :mod:`django.contrib.sites`
  85. ~~~~~~~~~~~~~~~~~~~~~~~~~~~
  86. * ...
  87. :mod:`django.contrib.staticfiles`
  88. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  89. * ...
  90. :mod:`django.contrib.syndication`
  91. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  92. * ...
  93. Cache
  94. ~~~~~
  95. * The :ref:`local-memory cache backend <local-memory-caching>` now uses a
  96. least-recently-used (LRU) culling strategy rather than a pseudo-random one.
  97. CSRF
  98. ~~~~
  99. * Added the :setting:`CSRF_COOKIE_SAMESITE` setting to set the ``SameSite``
  100. cookie flag on CSRF cookies.
  101. Database backends
  102. ~~~~~~~~~~~~~~~~~
  103. * ...
  104. Email
  105. ~~~~~
  106. * ...
  107. File Storage
  108. ~~~~~~~~~~~~
  109. * ...
  110. File Uploads
  111. ~~~~~~~~~~~~
  112. * ...
  113. Forms
  114. ~~~~~
  115. * The widget for ``ImageField`` now renders with the HTML attribute
  116. ``accept="image/*"``.
  117. Generic Views
  118. ~~~~~~~~~~~~~
  119. * ...
  120. Internationalization
  121. ~~~~~~~~~~~~~~~~~~~~
  122. * Added the :meth:`~django.utils.translation.get_supported_language_variant`
  123. function.
  124. * Untranslated strings for territorial language variants now use the
  125. translations of the generic language. For example, untranslated ``pt_BR``
  126. strings use ``pt`` translations.
  127. Management Commands
  128. ~~~~~~~~~~~~~~~~~~~
  129. * The new :option:`inspectdb --include-views` option allows creating models
  130. for database views.
  131. Migrations
  132. ~~~~~~~~~~
  133. * Added support for serialization of ``functools.partialmethod`` objects.
  134. * To support frozen environments, migrations may be loaded from ``.pyc`` files.
  135. Models
  136. ~~~~~~
  137. * Models can now use ``__init_subclass__()`` from :pep:`487`.
  138. * A ``BinaryField`` may now be set to ``editable=True`` if you wish to include
  139. it in model forms.
  140. * A number of new text database functions are added:
  141. :class:`~django.db.models.functions.Chr`,
  142. :class:`~django.db.models.functions.Left`,
  143. :class:`~django.db.models.functions.LPad`,
  144. :class:`~django.db.models.functions.LTrim`,
  145. :class:`~django.db.models.functions.Ord`,
  146. :class:`~django.db.models.functions.Repeat`,
  147. :class:`~django.db.models.functions.Replace`,
  148. :class:`~django.db.models.functions.Right`,
  149. :class:`~django.db.models.functions.RPad`,
  150. :class:`~django.db.models.functions.RTrim`, and
  151. :class:`~django.db.models.functions.Trim`.
  152. * The new :class:`~django.db.models.functions.TruncWeek` function truncates
  153. :class:`~django.db.models.DateField` and
  154. :class:`~django.db.models.DateTimeField` to the Monday of a week.
  155. * Query expressions can now be negated using a minus sign.
  156. * :meth:`.QuerySet.order_by` and :meth:`distinct(*fields) <.QuerySet.distinct>`
  157. now support using field transforms.
  158. * :class:`~django.db.models.BooleanField` can now be ``null=True``. This is
  159. encouraged instead of :class:`~django.db.models.NullBooleanField`, which will
  160. likely be deprecated in the future.
  161. Requests and Responses
  162. ~~~~~~~~~~~~~~~~~~~~~~
  163. * Added :meth:`.HttpRequest.get_full_path_info`.
  164. * Added the ``samesite`` argument to :meth:`.HttpResponse.set_cookie` to allow
  165. setting the ``SameSite`` cookie flag.
  166. Serialization
  167. ~~~~~~~~~~~~~
  168. * ...
  169. Signals
  170. ~~~~~~~
  171. * ...
  172. Templates
  173. ~~~~~~~~~
  174. * The new :tfilter:`json_script` filter safely outputs a Python object as JSON,
  175. wrapped in a ``<script>`` tag, ready for use with JavaScript.
  176. Tests
  177. ~~~~~
  178. * Added test :class:`~django.test.Client` support for 307 and 308 redirects.
  179. * The test :class:`~django.test.Client` now serializes a request data
  180. dictionary as JSON if ``content_type='application/json'``. You can customize
  181. the JSON encoder with test client's ``json_encoder`` parameter.
  182. URLs
  183. ~~~~
  184. * ...
  185. Validators
  186. ~~~~~~~~~~
  187. * ...
  188. .. _backwards-incompatible-2.1:
  189. Backwards incompatible changes in 2.1
  190. =====================================
  191. Database backend API
  192. --------------------
  193. * To adhere to :pep:`249`, exceptions where a database doesn't support a
  194. feature are changed from :exc:`NotImplementedError` to
  195. :exc:`django.db.NotSupportedError`.
  196. * Renamed the ``allow_sliced_subqueries`` database feature flag to
  197. ``allow_sliced_subqueries_with_in``.
  198. * ``DatabaseOperations.distinct_sql()`` now requires an additional ``params``
  199. argument and returns a tuple of SQL and parameters instead of a SQL string.
  200. * ``DatabaseFeatures.introspected_boolean_field_type`` is changed from a method
  201. to a property.
  202. :mod:`django.contrib.gis`
  203. -------------------------
  204. * Support for SpatiaLite 4.0 is removed.
  205. Dropped support for MySQL 5.5
  206. -----------------------------
  207. The end of upstream support for MySQL 5.5 is December 2018. Django 2.1 supports
  208. MySQL 5.6 and higher.
  209. Dropped support for PostgreSQL 9.3
  210. ----------------------------------
  211. The end of upstream support for PostgreSQL 9.3 is September 2018. Django 2.1
  212. supports PostgreSQL 9.4 and higher.
  213. Removed ``BCryptPasswordHasher`` from the default ``PASSWORD_HASHERS`` setting
  214. ------------------------------------------------------------------------------
  215. If you used bcrypt with Django 1.4 or 1.5 (before ``BCryptSHA256PasswordHasher``
  216. was added in Django 1.6), you might have some passwords that use the
  217. ``BCryptPasswordHasher`` hasher.
  218. You can check if that's the case like this::
  219. from django.contrib.auth import get_user_model
  220. User = get_user_model()
  221. User.objects.filter(password__startswith='bcrypt$$')
  222. If you want to continue to allow those passwords to be used, you'll
  223. have to define the :setting:`PASSWORD_HASHERS` setting (if you don't already)
  224. and include ``'django.contrib.auth.hashers.BCryptPasswordHasher'``.
  225. Moved ``wrap_label`` widget template context variable
  226. -----------------------------------------------------
  227. To fix the lack of ``<label>`` when using ``RadioSelect`` and
  228. ``CheckboxSelectMultiple`` with ``MultiWidget``, the ``wrap_label`` context
  229. variable now appears as an attribute of each option. For example, in a custom
  230. ``input_option.html`` template, change ``{% if wrap_label %}`` to
  231. ``{% if widget.wrap_label %}``.
  232. ``SameSite`` cookies
  233. --------------------
  234. The cookies used for ``django.contrib.sessions``, ``django.contrib.messages``,
  235. and Django's CSRF protection now set the ``SameSite`` flag to ``Lax`` by
  236. default. Browsers that respect this flag won't send these cookies on
  237. cross-origin requests. If you rely on the old behavior, set the
  238. :setting:`SESSION_COOKIE_SAMESITE` and/or :setting:`CSRF_COOKIE_SAMESITE`
  239. setting to ``None``.
  240. Miscellaneous
  241. -------------
  242. * The minimum supported version of ``mysqlclient`` is increased from 1.3.3 to
  243. 1.3.7.
  244. * The date format of ``Set-Cookie``'s ``Expires`` directive is changed to
  245. follow :rfc:`7231#section-7.1.1.1` instead of Netscape's cookie standard.
  246. Hyphens present in dates like ``Tue, 25-Dec-2018 22:26:13 GMT`` are removed.
  247. This change should be merely cosmetic except perhaps for antiquated browsers
  248. that don't parse the new format.
  249. * ``allowed_hosts`` is now a required argument of private API
  250. ``django.utils.http.is_safe_url()``.
  251. * The ``multiple`` attribute rendered by the
  252. :class:`~django.forms.SelectMultiple` widget now uses HTML5 boolean syntax
  253. rather than XHTML's ``multiple="multiple"``.
  254. * HTML rendered by form widgets no longer includes a closing slash on void
  255. elements, e.g. ``<br>``. This is incompatible within XHTML, although some
  256. widgets already used aspects of HTML5 such as boolean attributes.
  257. * The value of :class:`~django.forms.SelectDateWidget`'s empty options is
  258. changed from 0 to an empty string, which mainly may require some adjustments
  259. in tests that compare HTML.
  260. * :meth:`.User.has_usable_password` and the
  261. :func:`~django.contrib.auth.hashers.is_password_usable` function no longer
  262. return ``False`` if the password is ``None`` or an empty string, or if the
  263. password uses a hasher that's not in the :setting:`PASSWORD_HASHERS` setting.
  264. This undocumented behavior was a regression in Django 1.6 and prevented users
  265. with such passwords from requesting a password reset. Audit your code to
  266. confirm that your usage of these APIs don't rely on the old behavior.
  267. * Since migrations are now loaded from ``.pyc`` files, you might need to delete
  268. them if you're working in a mixed Python 2 and Python 3 environment.
  269. * Using ``None`` as a :class:`~django.contrib.postgres.fields.JSONField` lookup
  270. value now matches objects that have the specified key and a null value rather
  271. than objects that don't have the key.
  272. * The admin CSS class ``field-box`` is renamed to ``fieldBox`` to prevent
  273. conflicts with the class given to model fields named "box".
  274. .. _deprecated-features-2.1:
  275. Features deprecated in 2.1
  276. ==========================
  277. Miscellaneous
  278. -------------
  279. * The ``ForceRHR`` GIS function is deprecated in favor of the new
  280. :class:`~django.contrib.gis.db.models.functions.ForcePolygonCW` function.
  281. * ``django.utils.http.cookie_date()`` is deprecated in favor of
  282. :func:`~django.utils.http.http_date`, which follows the format of the latest
  283. RFC.
  284. * ``{% load staticfiles %}`` and ``{% load admin_static %}`` are deprecated
  285. in favor of ``{% load static %}``, which works the same.
  286. * ``django.contrib.staticfiles.templatetags.static()`` is deprecated in favor
  287. of ``django.templatetags.static.static()``.
  288. * Support for :meth:`.InlineModelAdmin.has_add_permission` methods that don't
  289. accept ``obj`` as the second positional argument will be removed in Django
  290. 3.0.
  291. .. _removed-features-2.1:
  292. Features removed in 2.1
  293. =======================
  294. These features have reached the end of their deprecation cycle and are removed
  295. in Django 2.1. See :ref:`deprecated-features-1.11` for details, including how
  296. to remove usage of these features.
  297. in Django 2.1. See :ref:`deprecated-features-1.11` and for details, including
  298. how to remove usage of these features.
  299. * ``contrib.auth.views.login()``, ``logout()``, ``password_change()``,
  300. ``password_change_done()``, ``password_reset()``, ``password_reset_done()``,
  301. ``password_reset_confirm()``, and ``password_reset_complete()`` are removed.
  302. * The ``extra_context`` parameter of ``contrib.auth.views.logout_then_login()``
  303. is removed.
  304. * ``django.test.runner.setup_databases()`` is removed.
  305. * ``django.utils.translation.string_concat()`` is removed.
  306. * ``django.core.cache.backends.memcached.PyLibMCCache`` no longer supports
  307. passing ``pylibmc`` behavior settings as top-level attributes of ``OPTIONS``.
  308. * The ``host`` parameter of ``django.utils.http.is_safe_url()`` is removed.
  309. * Silencing of exceptions raised while rendering the ``{% include %}`` template
  310. tag is removed.
  311. * ``DatabaseIntrospection.get_indexes()`` is removed.
  312. * The ``authenticate()`` method of authentication backends requires ``request``
  313. as the first positional argument.
  314. * The ``django.db.models.permalink()`` decorator is removed.
  315. * The ``USE_ETAGS`` setting is removed. ``CommonMiddleware`` and
  316. ``django.utils.cache.patch_response_headers()`` no longer set ETags.
  317. * The ``Model._meta.has_auto_field`` attribute is removed.
  318. * Support for regular expression groups with ``iLmsu#`` in ``url()`` is removed.
  319. * Support for ``Widget.render()`` methods without the ``renderer`` argument
  320. is removed.